PLC Reprogramming Detection via TAP and Time Deception in SCADA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SCADA systems are vulnerable to malicious reprogramming of PLCs due to lack of security measures, outdated architecture, and connectivity issues, which can lead to unauthorized control and manipulation of physical devices, compromising system integrity and availability.

Innovation Solution

A dedicated system using a Test Access Point (TAP) and Intrusion Detection System (IDS) is installed between the Engineering Workstation and PLC to passively monitor and detect unauthorized reprogramming attempts, alerting the Security Information and Event Management System (SIEM) and allowing for controlled programming windows to prevent malicious changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures such as IDS and TAP are installed to detect malicious reprogramming, then system security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Test Access Point (TAP) as an intermediary device that passively monitors communication between the Engineering Workstation and PLC. The TAP captures traffic without interrupting normal operations, allowing security monitoring while maintaining system simplicity. This intermediary approach enables security enhancement without directly modifying the core control system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security measures (such as locked control rooms or restricted access) with electronic monitoring through IDS and TAP. Instead of mechanically preventing access, the system uses digital surveillance of communication traffic to detect and prevent malicious reprogramming, reducing physical complexity while enhancing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If continuous monitoring is implemented to detect unauthorized changes, then detection capability is improved, but loss of time for legitimate programming operations increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprogramming time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and authorization checks before allowing programming operations. By pre-establishing security credentials and authorization levels, the system can quickly validate legitimate programming requests without time-consuming monitoring delays, while still maintaining continuous detection capability for unauthorized attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system operates periodically rather than continuously blocking operations. It samples communication traffic at intervals and triggers detailed analysis only when suspicious patterns are detected, allowing legitimate programming to proceed uninterrupted while maintaining detection capability. This periodic approach reduces time loss for authorized operations.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3190769B1A system and method for detecting malicious re-programming of a PLC in scada systems using time deception
Publication Date: 2020.10.28 DEUTSCHE TELEKOM AG
  • EP3190769B1 patent drawingFigure 1
  • EP3190769B1 patent drawingFigure 2

AI summary

A method for detecting malicious reprogramming of a Programmable Logic Controller (PLC) in a Superiority Control And Data Acquisition (SCADA) system, according to which a dedicated device is located on the communication network between the PLC and an engineering Workstation and the traffic between the PLC and the engineering Workstation is passively collected and checked using a TAP. An alert is generated upon detecting an unauthorized reprogramming in the checked traffic.