Security analysis of 11 industrial protocols used in SCADA, PLCs, RTUs, and field devices — vulnerabilities, CVEs, authentication mechanisms, and IEC 62443 defences.
The most widely deployed ICS protocol — no authentication, no encryption. Every device on the network can read or write registers.
SCADASCADA backbone for electric and water utilities. Secure Authentication v5 adds HMAC-SHA-256 but adoption remains limited.
Data AccessOPC UA replaced DCOM-based Classic with TLS and X.509 certificates. Classic's RPC attack surface remains in legacy deployments.
Power SystemsSubstation automation standard. GOOSE messages trip breakers in <4ms with no authentication in Edition 1/2.
FieldbusDominant fieldbus in European manufacturing. No security in base protocol — relies entirely on physical and network isolation.
Industrial EthernetRockwell/Allen-Bradley standard over standard Ethernet. CIP Security (2018) adds TLS — but most deployed devices predate it.
Field InstrumentDigital overlay on 4-20mA analog loops. HART-IP extends it over TCP. Optional challenge-response auth rarely deployed.
SCADATelecontrol over TCP/IP for power grid SCADA. Used in the 2016 Ukraine grid attacks. IEC 62351-5 adds TLS.
Building AutomationASHRAE standard for HVAC, lighting, and fire safety. Unauthenticated object access in base protocol. BACnet/SC (2020) adds TLS.
Industrial EthernetReal-time Industrial Ethernet replacing PROFIBUS in new installations. No authentication in RT — relies on network isolation.
Field InstrumentHART protocol multiplexed over TCP/UDP networks. Extends HART device access to IP infrastructure with optional authentication.