A Demilitarised Zone to Protect Oslo Metro’s Signalling System from Cyber Attacks
Zircon collaborated with longstanding partner Siemens to create a demilitarised zone to protect Oslo Metro’s signal control systems from cyber-attacks. The project saw us design the network architecture, manage multiple parties’ needs, and develop a deployment plan that could be implemented over several night shifts without passengers noticing.
Oslo Metro's signalling control system ensures trains move through its rail network safely and efficiently. In response to the growing threat of cyber-attacks on critical infrastructure – such as the 2023 attack on Polish State railways that brought 20 trains to a standstill – Oslo’s railway and Metro operator wanted to ensure its critical control systems were secure.
There was a specific risk identified in which several servers were connected to both the safety-critical signal control network, and the wider corporate network. The latter was increasingly accessed by remote workers on unsecured personal devices, creating a potential backdoor for malicious actors to infiltrate the signal control network.
The Project: Build A Demilitarised Zone in Oslo Metro’s IT Network
The solution was to create a security cordon around these shared servers – known as a demilitarised zone (DMZ) – with access controls and firewalls. Siemens, who held the network maintenance contract, took responsibility and made the decision to bring in Zircon – with whom it regularly partners on rail software and technology projects – to handle the project.
As Vince Dade of Siemens explains, “the idea was to draw a boundary around these parts of the IT network, and set strict limits on what the less-secure corporate network could access. That ensured authorised users could still view important signalling data when needed, but it prevented unauthorised personnel from making changes or uploading malicious software that could compromise the signal control software.”
“The team has a really good understanding of control systems and legacy interfaces, which was a serious advantage in being able to deal with the technical challenges of this project”
The Solution: Defining and Deploying a Secure Network Architecture
Zircon took on the entire project on a turnkey basis, handling everything from the initial information gathering to define the requirements, through to the final deployment plan. Our work spanned five parts:
1. Defining the requirements: We ran a series of workshops with Siemens and the Metro operator to understand and document their requirements in detail. "This was a complex and collaborative process” says Dade. “The client knew what they wanted but not how to get there. And they also needed to satisfy themselves that this would do the job and not have any adverse effects on their network. So there were a lot of meetings to get to a solution everyone was happy with."
2. Network Design: Once the requirements were documented, Zircon designed the network architecture, defined the firewall rules, and resolved networking issues related to communication between new and legacy systems.
To hold everything together, Zircon developed the TIS (Traffic Information Server) Proxy, a piece of software that acts as a gatekeeper to the DMZ, monitoring the network and allowing valid messages to pass from the signalling network to the corporate network. This enables real-time tracking and analysis of the flow of data across the DMZ, providing vital insights into network performance, and the detection of any suspicious behaviour.
A critical element of getting this project to the finish line was our team’s agile approach and ability to continuously adapt to changing requirements , such as a decision by the Metro’s IT team to end a contract with a network equipment vendor, which had major knock-on effects for the DMZ’s firewall design.
3. Network equipment sourcing: Once the final design was agreed, Zircon sourced the networking equipment for the upgrade on the Metro operators behalf.
4. Factory Acceptance Testing: Before deployment, Zircon conducted a Factory Acceptance Test (FAT) with the client present. This involved setting up the entire system at our offices and testing it over a three-day period to demonstrate reliability before it went live.
5. Deployment Plan: Zircon created a detailed deployment plan, outlining every stage of the deployment process into the wider IT and signalling networks, over a four day commissioning period. Given the huge consequences of a signal failure on a metropolitan transport system, this plan had to be carefully designed to ensure no disruption to the Metro's operations, and to be deployable within their short maintenance window of a few hours each night.
The Outcome
As of July 2024, the network design and deployment plan has been accepted by the Metro operator and is awaiting an appropriate window for deployment by their own network engineers – though Zircon is committed to being on hand throughout to ensure all goes to plan.
Why Zircon was the Ideal Partner
“Zircon's combination of both technical and project management skills, as well as its extensive experience in rail projects and understanding of control systems made it an ideal partner for this project”, says Dade.
"The team has a really good understanding of control systems and legacy interfaces, which was a serious advantage in being able to deal with the technical challenges of this project”, he adds. “But perhaps the biggest benefit was that they are not just software experts, but problem solvers. We knew we could trust them to take on the whole thing, navigating the many different parties’ needs, and constantly adapting to the changes that inevitably arise in such a project.”
Similar Projects
Lets Talk Software
Looking for a team to support your next Rail software venture? Zircon is there to help you ensure project success, contact the team today.