Investigation of Secure Communication of Modbus TCP/IP Protocol: Siemens S7 PLC Series Case Study

Industrial Control Systems (ICS) have become increasingly vulnerable to cyber threats due to the growing interconnectivity with enterprise networks and the Industrial Internet of Things (IIoT). Among these threats, Address Resolution Protocol (ARP) spoofing presents a critical risk to the integrity...

Full description

Saved in:
Bibliographic Details
Main Authors: Quy-Thinh Dao, Le-Trung Nguyen, Trung-Kien Ha, Viet-Hoang Nguyen, Tuan-Anh Nguyen
Format: Article
Language:English
Published: MDPI AG 2025-05-01
Series:Applied System Innovation
Subjects:
Online Access:https://www.mdpi.com/2571-5577/8/3/65
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Industrial Control Systems (ICS) have become increasingly vulnerable to cyber threats due to the growing interconnectivity with enterprise networks and the Industrial Internet of Things (IIoT). Among these threats, Address Resolution Protocol (ARP) spoofing presents a critical risk to the integrity and reliability of Modbus TCP/IP communications, particularly in environments utilizing Siemens S7 programmable logic controllers (PLCs). Traditional defense methods often rely on host-based software solutions or cryptographic techniques that may not be practical for legacy or resource-constrained industrial environments. This paper proposes a novel, lightweight hardware device designed to detect and mitigate ARP spoofing attacks in Modbus TCP/IP networks without relying on conventional computer-based infrastructure. An experimental testbed using Siemens S7-1500 and S7-1200 PLCs (Siemens, Munich, Germany) was established to validate the proposed approach. The results demonstrate that the toolkit can effectively detect malicious activity and maintain stable industrial communication under normal and adversarial conditions.
ISSN:2571-5577