Stopping Lateral OT Network Attacks at the Cellular Edge

Defend critical infrastructure and water utilities against cellular edge cyber attacks using VeilNet's quantum-resistant Conflux and Aether architectures.
Stopping Lateral OT Network Attacks at the Cellular Edge

The Vulnerability of Cellular Entry Points in Water Systems

Recent cyber operations targeting public water systems across multiple states have exposed a severe and systemic vulnerability in operational technology (OT) environments. State-sponsored adversaries are actively exploiting remote access interfaces, specifically targeting cellular modems, Programmable Logic Controllers (PLCs), and Human-Machine Interfaces (HMIs) managing drinking water systems. These networks rely heavily on cellular connections to link remote booster pumps and chemical feed systems to centralized control centers. Because these remote sites are unstaffed, operators deploy cellular modems to avoid the cost of laying physical fiber lines.

However, this cellular convenience creates an unmanaged attack surface. Traditional cellular modems operate with public or static IP addresses exposed to the public internet. Attackers use automated scanning tools to discover these endpoints, searching for open management ports or unpatched firmware vulnerabilities. Once compromised, a single modem grants direct access to the local network of the water utility, allowing an adversary to move laterally to critical physical PLCs and modify water chemical dosing or pressure levels.

The severity of this threat is compounded because most legacy OT environments were designed under the assumption of complete physical isolation. They lack internal segmentation or access controls, meaning any device on the network is implicitly trusted. A compromised cellular modem at a remote booster station serves as a direct launchpad to traverse the utility's entire operational footprint, threatening public safety.

Why Private APNs and Software Defined WANs Fall Short

In response, federal guidelines recommend deploying private Access Point Names (APNs) or cellular Software-Defined Wide Area Networks (SD-WANs) to isolate OT traffic. However, these recommendations fail to address the core architectural flaws of legacy remote access. A private APN merely shifts the boundary of exposure. It still relies on carrier infrastructure and leaves modems with listening ports that become vulnerable if an adversary gains access to the private APN through another compromised endpoint on the carrier's network.

Similarly, cellular SD-WANs and traditional Virtual Private Networks (VPNs) present severe operational risks. A legacy VPN gateway must listen for incoming connections from the internet to authenticate remote endpoints. This listening port is a beacon for adversaries who routinely exploit zero-day vulnerabilities in VPN software to gain entry. Once an attacker compromises the VPN appliance, they obtain broad network-layer access, enabling unrestricted lateral movement across the entire OT segment.

Compounding this network exposure is a silent, long-term threat: quantum computing. State-sponsored adversaries are actively executing 'harvest now, decrypt later' campaigns, capturing encrypted cellular traffic to decrypt once cryptanalytically relevant quantum computers emerge. For critical water infrastructure, where physical machinery operates for decades, today’s encrypted communications are already vulnerable to future exposure.

Conflux Replaces Exposed Ports with a Meta Air Gap

VeilNet directly addresses these vulnerabilities through Conflux, its post-quantum zero-trust mesh networking engine. Conflux replaces exposed listening ports on cellular modems and PLCs with a complete meta air gap. Instead of leaving ports open to accept incoming connections, Conflux-enabled edge nodes initiate outbound-only connections to the overlay mesh. Because there are no open inbound ports, cellular modems running Conflux become entirely dark and invisible to internet scanning tools, leaving adversaries with nothing to scan or exploit.

Conflux operates on a model of identity-authenticated mesh networking. Traditional networks trust IP addresses, which are easily spoofed once a perimeter device is breached. In contrast, Conflux requires every node—whether a cellular router, HMI, or remote PLC gateway—to cryptographically prove its identity before routing any packets. If a remote physical site is compromised, its cryptographic identity is instantly revoked, immediately halting lateral spread.

To defend against 'harvest now, decrypt later' operations, Conflux implements quantum-resistant packet routing. It secures all mesh communications using post-quantum cryptographic algorithms, specifically ML-KEM for key encapsulation and ML-DSA for digital signatures. This quantum-resistant foundation ensures that utility data moving over cellular networks remains secure today and throughout its long service life, neutralizing future quantum decryption threats.

Aether Secures the Industrial Data Plane Above the Network

Securing the network layer is only half the battle. If an adversary compromises a remote physical terminal or clones a device configuration, network-level security cannot stop them from sending malicious control commands. This is where Aether, VeilNet’s industrial data plane engine, secures the application layer above Conflux. Aether integrates directly with critical OT protocols, specifically OPC UA, RESTful APIs, and Model Context Protocol (MCP), acting as an intelligent, protocol-aware security broker.

When deployed at a water treatment facility, Aether intercepts and validates all industrial data streams. Rather than blindly forwarding traffic, Aether performs deep protocol translation and granular command filtering on OPC UA streams. For instance, Aether can be configured to allow remote HMIs to read sensor data like water pH, while strictly blocking unauthorized write commands like altering chemical dosing pumps or opening valves. This validation ensures that even if an attacker compromises a remote HMI, they cannot send destructive commands to PLCs.

Furthermore, Aether provides secure RESTful API and MCP integrations, facilitating safe connectivity between OT systems, enterprise IT, and AI-driven monitoring systems without exposing control loops. By decoupling the industrial data plane from the network layer, Aether prevents lateral movement at the protocol level. An adversary cannot leverage a compromised remote API or database connection to execute commands on a PLC, because Aether enforces strict, least-privilege control over every transaction.

Implementing Post Quantum Zero Trust for Water Infrastructure

Migrating critical infrastructure to a post-quantum zero-trust architecture does not require a disruptive, costly forklift upgrade of legacy PLCs. VeilNet Conflux and Aether deploy seamlessly as an overlay on existing municipal networks. By installing lightweight Conflux gateways at cellular edge sites and deploying Aether brokers at control centers, water utilities immediately secure legacy, unencrypted OT protocols within a dark, quantum-safe mesh.

This deployment model protects municipal capital investments while elevating security to combat targeted attacks. The combination of Conflux's meta air gap and Aether's protocol-aware validation provides a robust, defense-in-depth shield. Municipalities no longer have to rely on the fragile security of private APNs or vulnerable legacy VPN appliances. With VeilNet, critical water services become completely invisible to the public internet, immune to lateral movement, and fully protected against the quantum threats of tomorrow.