Industrial Protocol Analysis & Zeek Plugin Development
Protocol-aware security monitoring for industrial networks.
Role
Software developer / cybersecurity
Domain
OT security
Timeline
2024–2026
Type
Professional R&D
STACKZeek · C++ · OPC UA · Wireshark · UAExpert · PLCs
01
Overview
Industrial communication carries context that a generic packet view cannot explain. This work extended Zeek-based monitoring with an OPC UA analyzer, connecting low-level traffic to security-relevant behavior inside SINEC Security Monitor.
My contribution
I researched OPC UA traffic, developed the C++ Zeek plugin, mapped protocol behavior to events, and defined test scenarios for monitoring and detection validation.
02
The problem
Capturing traffic was only the starting point. Useful monitoring needed to identify the service being used, the target of an operation, its response, and the conditions that made it relevant to security. The analyzer also had to interpret communication from real PLCs rather than assume every message matched a simplified example.
03
Protocol analysis
I used Wireshark, UAExpert, and generated PLC traffic to study message boundaries, secure-channel setup, service identifiers, request handles, node targets, and response status codes.
01Ethernet / TCP→
02OPC UA message→
03Parsed fields→
04Zeek event→
05Security log
Message structure
Transport framing and service fields establish what a message represents.
Request / response behavior
Handles and status conditions link an observed action to its result.
Security context
Certificate handling, access levels, and write responses shape the monitoring questions.
04
Analyzer architecture
The C++ plugin parses OPC UA traffic within Zeek, maintains the context needed to associate protocol activity, and emits events that monitoring logic can turn into useful logs.
01Network traffic→
02Protocol parser→
03Analyzer state→
04Zeek events→
05Monitoring logic
Technical decisions
Extend the existing monitoring stack
A Zeek plugin places protocol understanding inside the existing SINEC workflow rather than creating a separate packet-review tool.
Log behavior, not just fields
Event-specific output answers monitoring questions about services, targets, access, and response conditions.
05
Testing environment
The R&D environment combined real PLC communication with an engineering workstation, UAExpert, Wireshark, Zeek, and SINEC Security Monitor. I defined attack procedures and generated test data to compare protocol behavior with the events and logs produced by the plugin.
01UAExpert workstation→
02Industrial network / PLC→
03Wireshark captures→
04Zeek + SINEC validation
06
Technical challenges
01
Understanding real protocol behavior
Problem
Specification-level fields need to be understood in actual device conversations.
Approach
Compare generated PLC traffic with packet inspection and UAExpert sessions.
Result
Ground the parser and event mappings in observed industrial communication.
02
Preserving conversation context
Problem
A response alone does not explain the earlier operation it belongs to.
Approach
Track requests, service mappings, and response conditions in analyzer state.
Result
Associate protocol actions with outcomes in the emitted events.
03
Making telemetry useful
Problem
A dump of decoded fields is difficult to use for targeted monitoring.
Approach
Shape logs around certificate handling, access validation, and write behavior.
Result
Produce event-specific output for SINEC monitoring and detection logic.
07
Result
The resulting plugin interprets OPC UA activity and produces structured telemetry for SINEC Security Monitor. It connects packet-level protocol analysis with higher-level OT security visibility.
08
Lessons learned
Real device traffic is essential for validating protocol assumptions.
State and event design matter as much as decoding individual fields.
Security telemetry is useful when it preserves the context behind an action.