Skip to project
← Projects

PROJECT_01 / Industrial cybersecurity

Industrial Protocol Analysis & Zeek Plugin Development

Protocol-aware security monitoring for industrial networks.

STACKZeek · C++ · OPC UA · Wireshark · UAExpert · PLCs

01

Overview

Industrial communication carries context that a generic packet view cannot explain. This work extended Zeek-based monitoring with an OPC UA analyzer, connecting low-level traffic to security-relevant behavior inside SINEC Security Monitor.

My contribution

I researched OPC UA traffic, developed the C++ Zeek plugin, mapped protocol behavior to events, and defined test scenarios for monitoring and detection validation.

02

The problem

Capturing traffic was only the starting point. Useful monitoring needed to identify the service being used, the target of an operation, its response, and the conditions that made it relevant to security. The analyzer also had to interpret communication from real PLCs rather than assume every message matched a simplified example.

03

Protocol analysis

I used Wireshark, UAExpert, and generated PLC traffic to study message boundaries, secure-channel setup, service identifiers, request handles, node targets, and response status codes.

  1. 01Ethernet / TCP
  2. 02OPC UA message
  3. 03Parsed fields
  4. 04Zeek event
  5. 05Security log

Message structure

Transport framing and service fields establish what a message represents.

Request / response behavior

Handles and status conditions link an observed action to its result.

Security context

Certificate handling, access levels, and write responses shape the monitoring questions.

04

Analyzer architecture

The C++ plugin parses OPC UA traffic within Zeek, maintains the context needed to associate protocol activity, and emits events that monitoring logic can turn into useful logs.

  1. 01Network traffic
  2. 02Protocol parser
  3. 03Analyzer state
  4. 04Zeek events
  5. 05Monitoring logic

Technical decisions

Extend the existing monitoring stack

A Zeek plugin places protocol understanding inside the existing SINEC workflow rather than creating a separate packet-review tool.

Log behavior, not just fields

Event-specific output answers monitoring questions about services, targets, access, and response conditions.

05

Testing environment

The R&D environment combined real PLC communication with an engineering workstation, UAExpert, Wireshark, Zeek, and SINEC Security Monitor. I defined attack procedures and generated test data to compare protocol behavior with the events and logs produced by the plugin.

  1. 01UAExpert workstation
  2. 02Industrial network / PLC
  3. 03Wireshark captures
  4. 04Zeek + SINEC validation
06

Technical challenges

01

Understanding real protocol behavior

Problem
Specification-level fields need to be understood in actual device conversations.
Approach
Compare generated PLC traffic with packet inspection and UAExpert sessions.
Result
Ground the parser and event mappings in observed industrial communication.
02

Preserving conversation context

Problem
A response alone does not explain the earlier operation it belongs to.
Approach
Track requests, service mappings, and response conditions in analyzer state.
Result
Associate protocol actions with outcomes in the emitted events.
03

Making telemetry useful

Problem
A dump of decoded fields is difficult to use for targeted monitoring.
Approach
Shape logs around certificate handling, access validation, and write behavior.
Result
Produce event-specific output for SINEC monitoring and detection logic.
07

Result

The resulting plugin interprets OPC UA activity and produces structured telemetry for SINEC Security Monitor. It connects packet-level protocol analysis with higher-level OT security visibility.

08

Lessons learned

  • Real device traffic is essential for validating protocol assumptions.
  • State and event design matter as much as decoding individual fields.
  • Security telemetry is useful when it preserves the context behind an action.