Energy & Utilities
Detecting a controller that changed, without signatures
Control-network traffic is unusually regular, which makes it unusually easy to baseline. We used similarity-preserving hashes to fingerprint the steady state across a multi-vendor PLC bench and public labeled captures, then measured what it actually caught.
- Client
- A federally funded research program, with a university SCADA testbed
- Duration
- 12 months of research, through peer review
- Team
- 4, with a national-laboratory review cycle
- Year
- 2024–2025
The situation
What we walked into.
The detection tooling available for industrial environments largely inherits an assumption from enterprise security: that you know in advance what the bad thing looks like. In operational technology you frequently do not, because the attack that matters is often a legitimate protocol command issued at an illegitimate time by an unexpected party.
Endpoint agents were not an option. You cannot install software on a programmable logic controller, and the engineering workstation is frequently vendor-managed and out of scope for change.
Any active testing was off the table on the production process, which meant the research had to be conducted on a bench that faithfully represented several controller families rather than on a single convenient one.
There was also an honest scientific risk that the whole approach would not work. Similarity hashing is a technique from malware research, and the assumption that it would transfer usefully to process traffic was an assumption, not a result. It very nearly did not: industrial protocol frames are far smaller than the inputs these hash functions are designed for, and the first three approaches we tried failed outright.
Approach
How we sequenced it.
Each step had to be independently valuable. That constraint is what let the client stop at any point without being stranded.
- Step 01
Build a bench that resembles a plant
Controllers from four vendors, real ladder logic, and a process simulation that generated the traffic patterns a running line generates. Everything measured afterward depends on this being representative, so it got a disproportionate share of the effort.
- Step 02
Characterize normal, in detail
Passive capture over extended periods to establish what steady state actually looks like per device and per protocol, including the variation introduced by ordinary process changes, shift patterns and maintenance activity.
- Step 03
Fingerprint with similarity hashes
Similarity-preserving hashes over windows of clustered process traffic, so a small change produces a small distance rather than a completely different value. Clustering is what made it work at all: a single frame is too short for these functions to behave, and the cluster is the smallest unit that carries a stable signature. The output is a continuous deviation measure rather than a match or no-match verdict.
- Step 04
Attack it deliberately, then measure
Denial of service, man in the middle, packet injection and command manipulation, executed against the bench, plus evaluation against public capture sets carrying labeled attack windows. Results were presented for review at two national laboratories and written up for publication, which is a considerably harsher review than an internal report gets.
What was built
The parts that mattered.
- Multi-vendor bench: Allen-Bradley, Siemens, Beckhoff and Click controllers with real ladder logic
- Entirely passive detection: no agent on a controller, no scanning of the process network
- Continuous deviation scoring rather than binary signature matching
- Sliding window baseline that follows normal operational drift, so a maintenance window does not poison it
- Attack classes validated by execution on the bench, not by literature review
- Findings peer-reviewed and presented at national laboratories
Results
What changed, and how we know.
3 of the 5 below are measurements, each against a stated baseline. The rest are states of the delivered system rather than numbers, and are written as such rather than dressed up as figures.
- Controller families on the bench
- 4 vendors
- Installed on control equipment
- 0 agents
- Network flows analyzed
- 100k+
- Method and results
- Published
- A primary signal, not a verdict
- Indicator
Built with
Services involved
More work
Related engagements.
- 2023–202520 months, four phases
One codebase for the public site and the platform behind it
A public-facing site and an internal student-tracking platform, built years apart on stacks nobody still owned. We consolidated them into one application with one design system and one authorization model, and shipped it without a production regression.
Read the case study- Production regressions across the release window
- 0
- Unit and integration tests at handover
- 600+
- 2024About four weeks
The scanner read every barcode except theirs
They had no way to say who was holding what, and a barcode scanner that would not decode their own label format; the capability was licensed separately and they had declined to buy it. Writing the decoder in C cost less than the license and made the rest of the system possible.
Read the case study- Trackable, in and out, by holder
- Every item
- Bought to read their own labels
- No license
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether the thing you’re worried about is actually your biggest risk.
- Phone
- (214) 723-2510
- Reply
- A person replies, not a sequence: within one business day, from someone who would be on the engagement.