A parser for deep packet inspection of IEC-104: A practical solution for industrial applications

Justyna Joanna Chromik, Anne Katharina Ingrid Remke, Boudewijn Haverkort, Gerard Geist

    Research output: Contribution to conferencePaperScientificpeer-review

    Abstract

    We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the future. To illustrate the feasibility of the proposed solution, the throughput obtained when using the parser in combination with the monitoring tool Zeek has been evaluated for traces of different lengths. The traces have been captured in an operating electrical distribution field station with a single RTU.
    Original languageEnglish
    Number of pages6
    DOIs
    Publication statusPublished - 2019
    EventAnnual IEEE/IFIP International Conference on Dependable Systems and Networks 2019: Industry Track - The Benson Hotel, Portland, United States
    Duration: 24 Jun 201927 Jun 2019
    Conference number: 49
    http://2019.dsn.org/

    Conference

    ConferenceAnnual IEEE/IFIP International Conference on Dependable Systems and Networks 2019
    Abbreviated titleDSN 2019 Industry Track
    CountryUnited States
    CityPortland
    Period24/06/1927/06/19
    Internet address

    Fingerprint

    Industrial applications
    Inspection
    Monitoring
    Throughput

    Cite this

    Chromik, J. J., Remke, A. K. I., Haverkort, B., & Geist, G. (2019). A parser for deep packet inspection of IEC-104: A practical solution for industrial applications. Paper presented at Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019, Portland, United States. https://doi.org/10.1109/DSN-Industry.2019.00008
    Chromik, Justyna Joanna ; Remke, Anne Katharina Ingrid ; Haverkort, Boudewijn ; Geist, Gerard. / A parser for deep packet inspection of IEC-104 : A practical solution for industrial applications. Paper presented at Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019, Portland, United States.6 p.
    @conference{830c92de60494785a7cd63f289ffa219,
    title = "A parser for deep packet inspection of IEC-104: A practical solution for industrial applications",
    abstract = "We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the future. To illustrate the feasibility of the proposed solution, the throughput obtained when using the parser in combination with the monitoring tool Zeek has been evaluated for traces of different lengths. The traces have been captured in an operating electrical distribution field station with a single RTU.",
    author = "Chromik, {Justyna Joanna} and Remke, {Anne Katharina Ingrid} and Boudewijn Haverkort and Gerard Geist",
    year = "2019",
    doi = "10.1109/DSN-Industry.2019.00008",
    language = "English",
    note = "Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019 : Industry Track, DSN 2019 Industry Track ; Conference date: 24-06-2019 Through 27-06-2019",
    url = "http://2019.dsn.org/",

    }

    Chromik, JJ, Remke, AKI, Haverkort, B & Geist, G 2019, 'A parser for deep packet inspection of IEC-104: A practical solution for industrial applications', Paper presented at Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019, Portland, United States, 24/06/19 - 27/06/19. https://doi.org/10.1109/DSN-Industry.2019.00008

    A parser for deep packet inspection of IEC-104 : A practical solution for industrial applications. / Chromik, Justyna Joanna; Remke, Anne Katharina Ingrid; Haverkort, Boudewijn; Geist, Gerard.

    2019. Paper presented at Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019, Portland, United States.

    Research output: Contribution to conferencePaperScientificpeer-review

    TY - CONF

    T1 - A parser for deep packet inspection of IEC-104

    T2 - A practical solution for industrial applications

    AU - Chromik, Justyna Joanna

    AU - Remke, Anne Katharina Ingrid

    AU - Haverkort, Boudewijn

    AU - Geist, Gerard

    PY - 2019

    Y1 - 2019

    N2 - We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the future. To illustrate the feasibility of the proposed solution, the throughput obtained when using the parser in combination with the monitoring tool Zeek has been evaluated for traces of different lengths. The traces have been captured in an operating electrical distribution field station with a single RTU.

    AB - We present a practical solution for deep packet inspection for IEC-104 SCADA traffic, which can be used in monitoring approaches to ensure the dependable operation of critical systems. We re-implement an outdated parser and extend it to also parse the content of individual IEC-104 packets and to extract information relevant for monitoring and securing the physical processes being controlled. The deep packet inspection framework Spicy was used for the implementation, which allows for easy extensibility in the future. To illustrate the feasibility of the proposed solution, the throughput obtained when using the parser in combination with the monitoring tool Zeek has been evaluated for traces of different lengths. The traces have been captured in an operating electrical distribution field station with a single RTU.

    U2 - 10.1109/DSN-Industry.2019.00008

    DO - 10.1109/DSN-Industry.2019.00008

    M3 - Paper

    ER -

    Chromik JJ, Remke AKI, Haverkort B, Geist G. A parser for deep packet inspection of IEC-104: A practical solution for industrial applications. 2019. Paper presented at Annual IEEE/IFIP International Conference on Dependable Systems and Networks 2019, Portland, United States. https://doi.org/10.1109/DSN-Industry.2019.00008