A parser for deep packet inspection of IEC-104: A practical solution for industrial applications

Justyna Joanna Chromik, Anne Katharina Ingrid Remke, Boudewijn Haverkort, Gerard Geist

    Research output: Chapter in Book/Report/Conference proceedingConference contributionScientificpeer-review

    Abstract

    We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the future. To illustrate the feasibility of the proposed solution, the throughput obtained when using the parser in combination with the monitoring tool Zeek has been evaluated for traces of different lengths. The traces have been captured in an operating electrical distribution field station with a single RTU.
    Original languageEnglish
    Title of host publicationProceedings - 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - DSN 2019 Industry Track
    PublisherInstitute of Electrical and Electronics Engineers Inc.
    Pages5-8
    Number of pages4
    ISBN (Electronic)9781728130323
    DOIs
    Publication statusPublished - 2019
    Event49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Industry Track, DSN-Industry Track 2019 - Portland, United States
    Duration: 24 Jun 201927 Jun 2019

    Publication series

    NameProceedings - 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - DSN 2019 Industry Track

    Conference

    Conference49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks - Industry Track, DSN-Industry Track 2019
    Country/TerritoryUnited States
    CityPortland
    Period24/06/1927/06/19

    Keywords

    • IDS
    • IEC-104
    • parser
    • SCADA
    • Zeek

    Fingerprint

    Dive into the research topics of 'A parser for deep packet inspection of IEC-104: A practical solution for industrial applications'. Together they form a unique fingerprint.

    Cite this