Sie sind auf Seite 1von 7

Microsoft Visual Studio .

NET
Customer Solution Case Study

Honeywell Builds Secure Process


Knowledge Systems with Microsoft

Overview “When we talk with customers, one of the


Country or Region: United States
Industry: Industrial Automation things that differentiates us is that we make
security part of the infrastructure of the
Customer Profile
Honeywell Process Solutions (HPS) system. It’s pervasive: it’s at every level, it’s
provides products and services to in everything.”
the process automation industry,
including cyber security for the Kevin Staggs, Control System Solution Planner, Honeywell Process Solutions
company’s large industrial and
Honeywell Process Solutions (HPS) builds and delivers
petrochemical customers. automation products and services to support a wide
Business Situation
range of heavy industries, including refining, chemicals,
HPS realizes the benefits of open pharmaceuticals, mining, and energy. The reliability and
technology and recognizes the need
to secure automation systems
security of control systems in these industries is critical
against abnormal situations and not only to efficient plant operation and business
nontraditional threats.
success, but also to the avoidance of failures and risk
Solution mitigation. Honeywell’s flagship product Experion®
HPS committed to continual
improvement in the security of its
Process Knowledge System (PKS) is a process
flagship Experion® Process knowledge system with key components based on
Knowledge System (PKS) product
and deepened its partnership
advanced Microsoft® Windows® operating systems
commitment with Microsoft to joint, and .NET connection software. Working in close
trustworthy computing.
collaboration with Microsoft, HPS has pioneered
Benefits groundbreaking methods of securing Windows-based
 Improved plant operations
 Outstanding collaborative support
solutions that improve the decision-making
for security effectiveness of plant operators under normal and
 Easy migration and integration
abnormal conditions.
Situation flagship system is the Experion®
Honeywell Process Solutions (HPS), a Process Knowledge System (PKS).
business unit within Honeywell’s Experion PKS is designed for
Automation and Control business operators to monitor and control
segment, serves a U.S.$15 billion complex processes. It gathers data
installed-customer base and supplies from a range of diverse sources,
them with process automation including field sensors, control
products. Clients depend on HPS for equipment, and other supervisory
the infrastructure that controls systems, then presents this data to
complex production processes the operator through graphical
involving high temperatures and displays. A single point of access to all
pressures typically found in process information helps improve
production industries such as energy, operator performance and ensure
chemical, and pharmaceutical. safety.

In recent years, threats against open Experion PKS comprises a Control


systems have escalated the need for Execution Environment (CEE) at the
securing computing infrastructures industrial controller level that controls
within production facilities. In 2004, plant processes, using Experion
the U.S. Department of Homeland servers and databases to gather and
Security advised that refineries and organize information, and Experion
petrochemical plants are to be stations to provide the human-
considered potential terrorism machine interface (HMI) with the
targets. This heightened reality has operator. At the industrial controller
given momentum to industry and level, HPS manufactures equipment
government initiatives aimed at integrating proprietary, real-time
enhancing the security of industrial operating systems. Starting in 1996,
facilities in ways that meet the server-level software has run on
nontraditional threat scenarios. Microsoft® Windows® operating
system platforms. Operator stations
Says Kevin Staggs, Control System run on Windows-based PCs and use
Solution Planner at HPS, “Our clients Microsoft Internet Explorer technology
are operating some very sensitive as a basis for the HMI display. A
processes. A significant failure can medium-size implementation might
cause a plant to shut down or worse, include 15 operator stations and two
so everything we do is built around Experion servers.
safety and availability. When we talk
with customers, one of the things that The entire Experion PKS architecture
differentiates us is that we make includes many products that securely
security part of the infrastructure of integrate into a complete
the system. It’s pervasive: it’s at performance solution, as shown in
every level, it’s in everything.” Figure 1.

Honeywell has long had a reputation Honeywell Process Solutions wanted


for delivering process automation to introduce new features and
products that exceed the highest capabilities into Experion PKS. The
standards for safety and security. Its goal was to increase the level of
Figure 1. Experion PKS servers
and stations in the Experion information visibility between higher- leave anybody behind, which creates
platform architecture. level business applications and lower- some very significant challenges.”
level process control systems to
create a truly enterprise-wide 2. Safety and security must remain
knowledge system for manufacturing priority one. Increased levels of
organizations. Any changes to the integration between the realm of
HPS process automation software, business applications and the world of
however, would have to meet two industrial controls might run the risk
stringent requirements. of creating new susceptibilities and
possibilities for failure. Understanding
1. All changes must accommodate and eliminating such risk remains the
legacy technology. The industries utmost concern of HPS when
served by HPS depend on complex considering any changes to Experion
systems with life spans of 15 years PKS.
and longer. “We need to be able to
integrate today’s technology with Solution
controllers that we shipped in 1974,” The most recent release of Experion
points out Staggs. “We will never PKS, R300, represents the latest step
in Honeywell’s carefully considered
plan to provide greater value to its change the visualization of the display
customers through the inclusion of when changes occur. This
advanced Microsoft technologies. The customization of Internet Explorer–
Experion server, which first migrated based display can be accomplished by
from UNIX to a Windows platform in using .NET-connected technologies
1996, now runs on Microsoft Windows like Windows Forms.
Server™ 2003 operating system and
uses Microsoft SQL Server™ 2000. HPS has a Premier Independent
Some of the Experion applications are Software Vendor (ISV) agreement
built with Microsoft Visual Studio® with Microsoft and works closely with
.NET 2003 on the Microsoft .NET Microsoft Partner Services on security
Framework version 1.1. Technologies, topics. In order to deploy secure
such as Windows Forms, provide Windows-based server and
information from both the plant floor workstation products, Experion PKS
and the business enterprise to human R300 uses a number of special
operators on Windows XP operating techniques that include:
system–based client stations.  A series of scripts lock down the file
system and registry during the
HPS developers use .NET-connected installation of the operating system.
technologies extensively in carefully A series of local groups are created
selected parts of Experion PKS, and the system is locked down
particularly in its user interface based on those groups before any
elements and offline configuration HPS application is even installed on
tools. “Applications, such as the machine.
movement automation, blending  Experion Server is installed onto a
applications, and business Windows Server 2003 Service Pack
applications, are utilizing .NET,” says 1 (SP1) platform, and the Experion
Andrew Duca, System Architect at Server firewall feature is—by
HPS. “All our integrated tools used for default—on.
configuring and engineering a system  A strict separation is enforced
within our Configuration Studio are between the process control side of
“The new based on smart client technology the system and the business
technologies coming and .NET.” application side. A client on one
side never crosses the boundary to
down the road in The user interface provided by the access a server on the other side.
Windows and .NET company’s own HMIWeb technology is
a particularly important component of
Server-to-server interactions across
that boundary are carefully limited
will help us the Experion PKS system because it is through protocols that require, for
accomplish [our] directly tied to the ability of the
operator to control processes
example, special shadow servers.
 Increasingly, Experion products are
goal through efficiently. During system moving toward a domain model in
constantly implementation, the HMIWeb Display
Builder is used to create custom
which an application must be
deployed into a Windows domain—
improving displays showing graphical either the business domain or the
collaborative representations of processes (such as
pumps, valves, tanks, and pipes).
control domain. Eliminating trust
relationships between the domains
decision-support Animation and scripts can be used to will compartmentalize risk.
tools and better
“Our collaboration
 Group policy objects are used in
Experion deployments. HPS
life-cycle costs for its customers. Not
only are the Windows-based servers
onprovides
security
its groupwas a
policy templates and workstations securely locked
two-way street. The
(based on provided group policy
objects) for its customers to
down, but also their advanced ability
to gather, store, analyze, and present
HPS engineers
integrate into organizational units. information to plant operators can
learned about our
In some cases, HPS scripts the
whole process of creating a domain
actually improve the safety and
security of the plant under abnormal
approach
and setting up to threat
security. conditions. Better information
modeling, and they
Honeywell will continually place an
delivered more quickly to the
operator can prevent or mitigate
gave
emphasisus goodPKS security.
on Experion catastrophic failures.
feedback that we
Future versions will likely be built on
an even more compartmentalized “Windows platforms will enable us to
incorporated
model that will eliminateinto
all trust build next-generation operator
our own
relationships between domains and
synchronization between machines.
environments that use best guidance
from the Abnormal Situation
methodology.”
To test the effectiveness of its Management Consortium,” remarks
security measures, Honeywell’s Duca. “We are working toward an
“white hat” teams stage network- integrated cockpit that brings exactly
based attacks against the Experion the right information to the operators
servers and stations. at the exactly the right time, without
overloading them with too much non-
Benefits critical information. The new
Safety and environmental protection technologies coming down the road in
go beyond regulatory compliance, Windows and .NET will help us
with constant pressure to safeguard accomplish that goal through
people, assets, and profitability while constantly improving collaborative
increasing efficiency. Honeywell decision-support tools and better
Process Solutions uses the power of display technology.”
Windows to extend the role and scope
of automation for its customers. Using Outstanding Collaborative Support for
Microsoft .NET software, Honeywell Security
continues to improve the ability of Honeywell Process Solutions has
plant operators to view and introduced the latest Windows and
comprehend processes in real time, .NET technologies into an
especially under abnormal conditions. environment tightly constrained by
extreme safety and security
Improved Plant Operations requirements. In collaboration with
Experion PKS uses Windows operating Microsoft, Honeywell’s years of
systems and .NET connection experience and Six Sigma
software to help integrate process methodology have enabled it to
control information with business pioneer some of the safest and most
information in manufacturing plants. secure methods in the world for
Better visibility into enterprise-wide implementing Windows-based
information increases efficiencies, systems.
improves uptime, and reduces plant
The Microsoft Partner Services team Solutions, therefore, takes
provides both proactive and reactive tremendous advantage of Microsoft’s
support for development and extended product life-cycle policies to
deployment projects by HPS. support HPS customers over the long
According to Duca, “The Partner term. HPS helps its customers
Services team is a virtual extension of maintain older systems and augments
our development team.” those systems with new features and
capabilities that take advantage of
The benefits of close collaboration for the latest Windows technologies.
trustworthy computing are When it is time to upgrade, the
exemplified by the Threat Modeling continuity of the Windows platform
Workshop Microsoft delivered for the enables HPS to offer its customers a
developers and architects at HPS. clear upgrade path from any previous
Microsoft experts shared their internal point to the current product.
methodology used to test business
application security, then the
Microsoft and HPS engineers worked
together to determine how threat
modeling could best be applied to the
HPS systems. “Our collaboration on
security was a two-way street,”
according to Ned Curic, Strategic
Security Advisor at Microsoft. “The
HPS engineers learned about our
approach to threat modeling, and
they gave us good feedback that we
incorporated into our own
methodology.”

Easy Migration and Integration


Honeywell’s customers deploy the
latest Experion PKS servers and
stations, which are based on Windows
Server 2003 and Windows XP, right
alongside other systems that have
typically been in place for 10 years or
more. Everything about these
Experion products has been designed
to be safe, secure, and compatible
with the proven technologies of
Honeywell’s legacy process control
systems.

Customers in the automation industry


do not typically upgrade their
systems as often as do other
enterprises. Honeywell Process
For More Information Microsoft Visual Studio Microsoft .NET Framework
For more information about .NET The Microsoft .NET Framework is an
Microsoft products and services, call Microsoft Visual Studio .NET is the integral Windows component for
the Microsoft Sales Information rapid application development (RAD) building and running the next
Center at (800) 426-9400. In tool for building next-generation Web generation of applications and XML-
Canada, call the Microsoft Canada applications and XML-based Web based Web services.
Information Centre at (877) 568- services. Visual Studio .NET empowers
2495. Customers who are deaf or developers to rapidly design broad- For more information about the .NET
hard-of-hearing can reach Microsoft reach Web applications for any device Framework, go to:
text telephone (TTY/TDD) services and any platform. In addition, Visual msdn.microsoft.com/netframework
at (800) 892-5234 in the United Studio .NET is fully integrated with the
States or (905) 568-9641 in Canada. Microsoft .NET Framework, providing
Outside the 50 United States and support for multiple programming
Canada, please contact your local languages and automatically handling
Microsoft subsidiary. To access many common programming tasks,
information using the World Wide freeing developers to rapidly create
Web, go to: www.microsoft.com Web applications using their language
of choice.
For more information about
Honeywell Process Solutions For more information about Visual
products and services, call 1-877- Studio .NET, go to:
466-3993 or visit the Web site at: msdn.microsoft.com/vstudio
www.honeywell.com/ps
Acquire Visual Studio .NET:
msdn.microsoft.com/vstudio/howtobuy

MSDN® Subscriptions:
msdn.microsoft.com/subscriptions

Software and Services  Technologies


 Microsoft Windows Server − Microsoft .NET Framework
System™ version 1.1
− Microsoft Windows Server 2003 − Microsoft Windows Forms
− Microsoft SQL Server 2000  Partner Solutions
 Microsoft Internet Explorer − Abnormal Situation
 Microsoft Visual Studio .NET 2003 Management® Consortium
 Microsoft Windows XP − Experion Process Knowledge
© 2006 Microsoft Corporation. All rights reserved.  Services System
This case study is for informational purposes only.
MICROSOFT MAKES NO WARRANTIES, EXPRESS OR − Microsoft Partner Services
IMPLIED, IN THIS SUMMARY.
Microsoft, MSDN, the .NET logo, Visual Studio, the
Visual Studio logo, Windows, the Windows logo,
Windows Server, and Windows Server System are
either registered trademarks or trademarks of
Microsoft Corporation in the United States and/or
other countries. All other trademarks are property of
their respective owners.

Document published December 2005

Das könnte Ihnen auch gefallen