Leveraging Data Plane Programmability Towards a Policy-driven In-Network Security Framework for Industrial Control Systems
Reuben Samson Raj, Dong Jin · 2025
Industrial Control Systems (ICS) for power utilities often rely on legacy protocols like Modbus and DNP3 to transport control events and measurement data.These systems, however, are highly vulnerable to cyber-attacks due to the absence of basic security mechanisms in these legacy protocols and their increased integration with corporate networks and the Internet.Traditional approaches to securing ICS networks, such as using middle-boxes for IDS/IPS or securing protocols with authentication and encryption, often introduce significant overhead.In this paper, we propose an in-network security framework using programmable P4 data planes.Our framework performs detection and mitigation entirely in the data plane, addressing cross-domain security concerns such as traffic flow, packet structure, protocol violations, request message rates, and delayed or unsolicited responses.Additionally, to simplify management, we introduce a graph-based automated rule management module that streamlines table entry management on the P4 switch.Our evaluation on a Modbus TCP network using Intel's Tofino P4 switch demonstrates that programmable data planes can be effective in securing legacy ICS networks against a range of attacks, with minimal impact on forwarding delay and throughput. CCS Concepts• Security and privacy → Network security.