OT Intrusion Detection: 6 Smart Steps to Stop Hidden Threats

Share:
Cybersecurity
OT Intrusion Detection: 6 Smart Steps to Stop Hidden Threats

Attackers inside a control network can move quietly for months, because PLC protocols accept commands from almost anyone. Listening passively to that traffic reveals unusual behaviour without touching the process or adding any delay at all.

Passive Capture SPAN and TAP Anomaly Baseline NISTIR 8219

Control networks carry a small, repetitive set of messages, which makes unusual traffic easier to spot than on an office network. Passive monitoring tools learn that normal pattern and raise alerts when something changes.

Hello everyone, today we are going to learn how OT intrusion detection works, why passive packet capture suits control networks, how baselines are built and how much storage packet retention needs.
OT intrusion detection

What Is OT Intrusion Detection?

OT intrusion detection is the passive monitoring of industrial network traffic to find attacks, misuse and abnormal behaviour in SCADA, DCS and PLC networks. It complements the preventive controls described in SCADA network security.

SentryWire notes that Modbus, DNP3 and S7comm lack authentication, so a valid looking command from the wrong host is accepted. It also notes that industrial intrusions have persisted for months before detection.

According to SentryWire, passive capture adds no latency because the sensor sits outside the data path. A failure of the sensor therefore cannot stop the process.

How Passive Monitoring Works

Mirror TrafficSPAN port or network TAP copies packets
SensorReceives copies, never sends to the process
Protocol ParsingDecodes Modbus, DNP3, S7comm and others
BaselineLearns normal hosts, commands and timing
AlertsFlags new devices, writes and anomalies

SPAN ports on managed switches are cheap but can drop packets under load, while hardware TAPs copy every frame. Switch features are covered in network switches for SCADA and DCS.

Place sensors at the key boundaries of the Purdue model, especially between levels 2 and 3 and inside critical cells. Monitor the conduits defined in IEC 62443 zones and conduits.

Detection Methods Compared

Signature

Matches known attack patterns and malware.

Best for: known threats
Rules
Anomaly

Compares traffic with a learned baseline.

Best for: unknown and insider threats
Baseline
Protocol Rules

Checks commands against allowed function codes.

Best for: unauthorised writes
Policy

NIST studied behavioural anomaly detection tools on a manufacturing test bed in NISTIR 8219. The report shows how such tools detect unusual commands, new hosts and changed traffic patterns.

A baseline period of 30 to 90 days is common guidance, so that shift changes, batches and maintenance activities are all captured. Too short a baseline creates many false alerts.

6 Smart OT Intrusion Detection Steps

1
Map Assets
Build an inventory of hosts and protocols.
2
Choose Tap Points
Pick SPAN or TAP locations per zone.
3
Deploy Sensors
Install passive sensors out of band.
4
Learn Baseline
Run in learning mode for 30 to 90 days.
5
Tune Alerts
Remove noise and confirm real events.
6
Plan Response
Link alerts to an incident procedure.

Alerts are useful only when someone acts on them, and responders should know common attack patterns described in types of cyber attacks. Train staff using resources from free OT cybersecurity training.

Packet Retention Storage Formula

Storage per day in TB = Average Mbps × 1000000 ÷ 8 × 86400 ÷ 10^12
Total storage = Storage per day × Retention days

Example:
Average mirrored traffic 50 Mbps
Per day = 50 × 1000000 ÷ 8 × 86400 ÷ 10^12 = 0.54 TB
30 days × 0.54 TB = 16.20 TB

Use the average rate, not the link speed, and add headroom for growth. The unit conversions are explained in network speed, bandwidth and throughput.

SPAN and TAP Storage Calculator

Full Packet Retention Storage
Result
Storage per day 0.54 TB, total 16.20 TB for 30 days

Many sites keep full packets for a shorter time and metadata for much longer. Metadata needs only a small fraction of the storage.

Plan retention around how long an investigation might need to look back. If intrusions can stay hidden for months, a few days of full packets plus long term flow records is a sensible balance.

Advantages
  • No latency or risk to the process.
  • Finds unknown and insider threats.
  • Builds a live asset inventory.
  • Packet records support investigations.
Limitations
  • Detects but does not block attacks.
  • Baselines need time and tuning.
  • Encrypted traffic limits visibility.
  • Full capture needs large storage.

Detection works best alongside segmentation, see air gapped vs segmented ICS networks and zero trust for OT networks. Use the SCADA security checklist to find other gaps.

NIST Anomaly Detection PDF

PDF
NISTIR 8219 Securing Manufacturing ICS: Behavioral Anomaly Detection
NIST report on anomaly detection tools in manufacturing

Safe Network Monitoring Video

OT Intrusion Detection FAQ

What does an OT IDS do?
It passively watches industrial network traffic and alerts on attacks, misuse and unusual behaviour. It does not block traffic or change anything in the process.
Why is passive capture preferred?
SentryWire explains that passive capture sits outside the data path, so it adds no latency. A sensor failure therefore cannot interrupt or slow down control traffic.
Why are industrial protocols vulnerable?
Modbus, DNP3 and S7comm were designed without authentication. A device accepts valid commands from almost any host that can reach it on the network.
How long should the baseline run?
Common guidance is 30 to 90 days, covering shifts, batches and maintenance. A short baseline usually produces many false alerts that operators soon ignore.
SPAN port or TAP?
A SPAN port is cheap and easy but can drop packets under heavy load. A hardware TAP copies every frame and is preferred for critical links.
How much storage is needed?
Multiply average Mbps by 1000000, divide by 8, and multiply by seconds and days. For example, 50 Mbps for 30 days needs about 16.2 TB.
Does OT intrusion detection replace firewalls?
No, detection and prevention work together as separate layers. Firewalls block known bad traffic while detection finds whatever slips through or starts inside.

Related Articles

External References

What We Learn Today

  • OT intrusion detection passively watches control traffic for threats.
  • Baselines of 30 to 90 days reduce false alerts.
  • Full packet retention storage grows with average traffic and days.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *