Submitted:
24 April 2025
Posted:
28 April 2025
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Related Works
3. Methodology
3.1. Identification of Possible Communication Failures
3.2. Active Network Implications
3.3. Mitigation Strategies
4. Results
4.1. Testbed Effects of Malicious Traffic
5. Results Discussion
6. Conclusions
Author Contributions
Funding
References
- Boeding, M.; Boswell, K.; Hempel, M.; Sharif, H.; Lopez Jr, J.; Perumalla, K. Survey of cybersecurity governance, threats, and countermeasures for the power grid. Energies 2022, 15, 8692. [Google Scholar] [CrossRef]
- Manias, D.M.; Saber, A.M.; Radaideh, M.I.; Gaber, A.T.; Maniatakos, M.; Zeineldin, H.; Svetinovic, D.; El-Saadany, E.F. Trends in Smart Grid Cyber-Physical Security: Components, Threats and Solutions. IEEE Access 2024. [Google Scholar] [CrossRef]
- Modbus Organization, I. MODBUS Application Protocol Specification v1.1b3. Modicon Inc. Ind. Autom. Syst. Tech. Rep 2012. [Google Scholar]
- Power, I.; Society, E. IEEE Standard for Electric Power Systems Communications-Distributed Network Protocol (DNP3). IEEE Std 1815-2012 (Revis. IEEE Std 1815-2010) 2012, pp. 1–821. [CrossRef]
- Labs, V. OT-Icefall: The legacy of “insecure by design” and its implications for certifications and risk management, 2022.
- Porcu, D.; Castro, S.; Otura, B.; Encinar, P.; Chochliouros, I.; Ciornei, I.; Hadjidemetriou, L.; Ellinas, G.; Santiago, R.; Grigoriou, E.; et al. Demonstration of 5G solutions for smart energy grids of the future: a perspective of the Smart5Grid project. Energies 2022, 15, 839. [Google Scholar] [CrossRef]
- Jafary, P.; Supponen, A.; Repo, S. Network Architecture for IEC61850-90-5 Communication: Case Study of Evaluating R-GOOSE over 5G for Communication-Based Protection. Energies 2022, 15. [Google Scholar] [CrossRef]
- Boeding, M.; Hempel, M.; Sharif, H. End-to-End Framework for Identifying Vulnerabilities of Operational Technology Protocols and Their Implementations in Industrial IoT. Future Internet 2025, 17, 34. [Google Scholar] [CrossRef]
- Banik, S.; Manicavasagam, R.; Banik, T.; Banik, S. Simulation and analysis of cyber-attack on modbus protocol for smart grids in virtual environment. In Proceedings of the Science and Information Conference. Springer, 2024, pp. 384–401. [CrossRef]
- de Brito, I.B.; de Sousa Jr, R.T. Development of an open-source testbed based on the modbus protocol for cybersecurity analysis of nuclear power plants. Applied Sciences 2022, 12, 7942. [Google Scholar] [CrossRef]
- Rodriguez, J.D.P.; Boakye-Boateng, K.; Kaur, R.; Zhou, A.; Lu, R.; Ghorbani, A.A. SoK: A Reality Check for DNP3 Attacks 15 Years Later. Smart Cities 2024, 7, 3983–4001. [Google Scholar] [CrossRef]
- Ozdogan, E. Structured Defense Model Against DNP3-Based Critical Infrastructure Attacks. Arabian Journal for Science and Engineering 2024, pp. 1–19. [CrossRef]
- Kelli, V.; Radoglou-Grammatikis, P.; Sesis, A.; Lagkas, T.; Fountoukidis, E.; Kafetzakis, E.; Giannoulakis, I.; Sarigiannidis, P. Attacking and defending DNP3 ICS/SCADA systems. In Proceedings of the 2022 18th International Conference on Distributed Computing in Sensor Systems (DCOSS). IEEE, 2022, pp. 183–190. [CrossRef]
- Dangwal, G.; Mittal, S.; Wazid, M.; Singh, J.; Das, A.K.; Giri, D.; Alenazi, M.J. An effective intrusion detection scheme for Distributed Network Protocol 3 (DNP3) applied in SCADA-enabled IoT applications. Computers and Electrical Engineering 2024, 120, 109828. [Google Scholar] [CrossRef]
- Elamanov, S.; Son, H.; Flynn, B.; Yoo, S.K.; Dilshad, N.; Song, J. Interworking between Modbus and internet of things platform for industrial services. Digital Communications and Networks 2024, 10, 461–471. [Google Scholar] [CrossRef]
- Bastidas, A.J.C.; Méndez, G.L.A.; Revelo-Fuelagán, J.; Candelo-Becerra, J.E. Performance evaluation of modbus and DNP3 protocols in the communication network of a university campus microgrid. Results in Engineering 2024, 24, 103656. [Google Scholar] [CrossRef]
- Katulić, F.; Sumina, D.; Groš, S.; Erceg, I. Protecting modbus/TCP-based industrial automation and control systems using message authentication codes. IEEE access 2023, 11, 47007–47023. [Google Scholar] [CrossRef]
- Rodríguez-Pérez, N.; Domingo, J.M.; López, G.L.; Stojanovic, V. Scalability evaluation of a Modbus TCP control and monitoring system for Distributed Energy Resources. In Proceedings of the 2022 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe). IEEE, 2022, pp. 1–6. [CrossRef]
- Huang, H.; Davis, C.M.; Davis, K.R. Real-time power system simulation with hardware devices through dnp3 in cyber-physical testbed. In Proceedings of the 2021 IEEE Texas Power and Energy Conference (TPEC). IEEE, 2021, pp. 1–6. [CrossRef]
- Moldovan, D.; Ayyanar, R. DNP3 Implementation in a High DER Penetration Distribution System. In Proceedings of the 2024 IEEE Kansas Power and Energy Conference (KPEC). IEEE, 2024, pp. 1–5. [CrossRef]
- Boeding, M.; Hempel, M.; Sharif, H. Vulnerability Identification of Operational Technology Protocol Specifications Through Formal Modeling. In Proceedings of the 2023 16th International Conference on Signal Processing and Communication System (ICSPCS), 2023, pp. 1–6. [CrossRef]
- Modbus Organization, I. MODBUS Messaging on TCP/IP Implementation Guide V1.0b. Modicon Inc. Ind. Autom. Syst. Tech. Rep 2012. [Google Scholar]








| Latency (ms) | Background Traffic (Mbps) | ||||||||||
| 5 | 10 | 15 | 20 | 25 | 30 | 35 | 40 | 45 | 50 | 55 | |
| Gateway | 2.898 | 3.123 | 2.880 | 2.896 | 2.835 | 2.924 | 2.865 | 2.931 | 2.886 | 3.107 | 3.117 |
| Security Gateway | 3.001 | 3.201 | 3.0331 | 3.277 | 3.210 | 3.070 | 3.093 | 3.900 | 3.086 | 3.002 | 3.192 |
| Difference (ms) | 0.103 | 0.078 | 0.153 | 0.381 | 0.374 | 0.146 | 0.227 | 0.968 | 0.199 | -0.104 | 0.074 |
| Protection Tested | Attacks | |||
| SYN-Flood | RST Attack | External Connection | Background Traffic | |
| None | X | X | ✓ | ✓ |
| Gateway | ||||
| SYN-Flood Protection | X | X | ✓ | ✓ |
| DoS Prevention | X | X | ✓ | ✓ |
| Security Gateway | ||||
| All TCP Allowed | X | X | ✓ | ✓ |
| Port Specific Filtering | ✓ | ✓ | ✓ | ✓ |
| Software Defined Switch | ||||
| Static Route Configuration | ✓ | ✓ | ✓ | ✓ |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).