Location Research Breakthrough Possible @S-Logix pro@slogix.in

Countering Modbus TCP Function Code Abuse Attacks Against PyModbus Industrial Controllers Through Function-Code Whitelisting and Command-Pattern Monitoring

Description

Industrial organizations use Modbus TCP to exchange control and monitoring information between industrial controllers, supervisory systems, engineering workstations, and other operational-technology components.

Modbus TCP allows devices to perform operations such as reading coils, reading registers, writing coils, and writing holding registers. Because these operations can directly influence industrial process data or control states, unauthorized Modbus commands can create significant operational and safety risks.

An attacker who gains access to an industrial network may send unauthorized Modbus function codes to an industrial controller. If the controller accepts commands that the requesting device or user is not authorized to perform, the attacker may modify process values, change control states, or interfere with industrial operations.

In this use case, a controlled Industry 4.0 / OT laboratory environment is created using Ubuntu virtual machines. A PyModbus-based industrial controller simulator represents the controlled Modbus TCP device.

Kali Linux is used as the authorized security-testing system. A controlled Modbus TCP command-abuse simulation is performed against the laboratory controller.

No real industrial equipment or physical production process is affected. The simulation uses only a software-based industrial controller and harmless laboratory registers.

The defensive mechanism introduces Modbus function-code whitelisting, register-access authorization, command-pattern monitoring, and security alerting.

The security monitoring system identifies Modbus operations that fall outside the expected communication behavior. Unauthorized write operations or unexpected function-code usage generate security alerts and can trigger the configured containment response.

After detection, the suspicious Modbus activity is investigated and contained. Legitimate industrial communication is then tested to verify that authorized controller operations continue normally.

The complete defensive workflow is: Modbus TCP Controller → Unauthorized Function Code → Command Monitoring → Function-Code Validation → Suspicious Modbus Activity → Security Alert → Automated Response → Command Containment → Controller Validation.

Existing Security Problem

Application: Modbus TCP

Modbus TCP is an industrial communication protocol used to exchange data between control systems and industrial devices. Industrial applications may use Modbus TCP for reading sensor values, monitoring process states, and writing control values to connected devices.

Existing Problem:

Modbus TCP communication can become a security risk when the industrial network does not adequately restrict which systems can issue control-related commands.A compromised workstation or unauthorized device may attempt to send Modbus write operations to an industrial controller. If the controller accepts unexpected function codes or unauthorized register modifications, an attacker may influence the industrial process represented by the laboratory environment.

The security problem is therefore:

Compromised / Unauthorized Industrial Device → Unauthorized Modbus TCP Request → Unexpected Function Code → Unauthorized Register / Coil Operation → Industrial Control State Modified → Potential Operational Disruption

The proposed solution introduces Modbus function-code allowlisting, register-access control, command-pattern monitoring, security alerting, and automated response to detect and contain unauthorized industrial control commands.

Attack

Specific Attack: Modbus TCP Function Code Abuse

The attack scenario simulates unauthorized use of Modbus TCP function codes against a controlled industrial controller. A laboratory testing system sends controlled Modbus requests to the PyModbus-based industrial controller. The simulation focuses on unauthorized write-related Modbus operations that would normally require specific authorization. The objective is to determine whether the security controls can identify unexpected Modbus commands and prevent unauthorized modification of protected industrial process values.

Attack Behavior:
Controlled Testing System
→
Modbus TCP Connection
→
Unauthorized Function Code
→
Write Operation Attempt
→
Protected Register / Coil Targeted
→
Command-Pattern Monitoring
→
Suspicious Modbus Activity Detected
→
Security Alert
→
Automated Response
→
Unauthorized Command Contained

Security Concept

Industrial Protocol Command Validation:

The primary security concept is industrial protocol command validation.

Instead of allowing every Modbus TCP operation from every connected system, the security architecture defines which function codes and register ranges are expected for each authorized communication relationship. A legitimate industrial communication flow should use only the Modbus operations required by the specific application. Unexpected write operations, unauthorized function codes, or abnormal command sequences should be treated as suspicious and investigated.

The secure processing flow is:

Modbus TCP Request
→
Source Validation
→
Function-Code Validation
→
Register / Coil Authorization
→
Command-Pattern Analysis
→
Suspicious Activity Detection
→
Security Alert
→
Containment
→
Industrial Communication Validation

Defensive Mechanism

Modbus Function-Code Allowlisting

The security architecture defines the Modbus function codes permitted for the laboratory controller.

Purpose

Prevent unexpected Modbus operations from being accepted as normal industrial communication.

Register and Coil Authorization

The security architecture defines the Modbus function codes permitted for the laboratory controller.

Purpose

Prevent unexpected Modbus operations from being accepted as normal industrial communication.

Register and Coil Authorization

Specific Modbus registers and coils are classified according to their permitted operations.

Purpose

Prevent unauthorized modification of protected industrial values.

Source Device Validation

The source of each Modbus TCP request is identified and compared with the expected communication relationship.

Purpose

Ensure that only authorized industrial systems communicate with the controller.

Modbus Command Monitoring

Modbus TCP requests are continuously monitored.

Purpose

Provide visibility into industrial control commands.

Command-Pattern Analysis

Modbus requests are analyzed for abnormal function-code usage, request frequency, and communication sequences.

Purpose

Identify behavior that differs from the established industrial communication baseline.

Unauthorized Write Detection

Unexpected write operations against protected registers or coils are detected.

Purpose

Identify potentially dangerous industrial control activity.

Security Alerting

A security alert is generated when the configured Modbus-abuse detection condition is satisfied.

Purpose

Provide immediate visibility into suspicious industrial protocol activity.

Automated Source Containment

The configured response can temporarily restrict the identified laboratory source from communicating with the industrial controller.

Purpose

Determine whether unauthorized commands changed the expected industrial state.

Post-Containment Validation

Authorized Modbus communication is tested after containment.

Purpose

Confirm that legitimate industrial communication continues to operate correctly.

Security Tools

Primary Industrial Protocol Tool: PyModbus

PyModbus is used to create the controlled Modbus TCP industrial controller and client environment.

Purpose
  • Create a software-based Modbus TCP controller.
  • Create controlled Modbus TCP clients.
  • Generate read and write requests.
  • Simulate industrial register and coil operations.
  • Provide a reproducible OT security laboratory.

Modbus Device Simulation Tool: ModbusPal

ModbusPal is used to simulate Modbus devices and industrial register behavior.

Purpose
  • Represent industrial Modbus devices.
  • Simulate coils and registers.
  • Generate controlled industrial process values.
  • Support testing of Modbus communication behavior.

Modbus Command Testing Tool: mbpoll

mbpoll is used to generate controlled Modbus TCP requests during security validation.

Purpose
  • Send Modbus TCP read operations.
  • Send controlled write operations.
  • Validate function-code behavior.
  • Verify whether unauthorized commands are accepted or rejected.

Industrial Traffic Analysis Tool: TShark

TShark is used to analyze captured Modbus TCP network traffic.

Purpose
  • Capture Modbus TCP communication.
  • Identify Modbus function codes.
  • Analyze request and response sequences.
  • Identify abnormal command patterns.
  • Support investigation of suspicious industrial traffic.

Network Access-Control Tool: UFW

UFW (Uncomplicated Firewall) is used to enforce network restrictions around the controlled Modbus TCP controller.

Purpose
  • Restrict Modbus TCP access.
  • Allow communication only from authorized laboratory systems.
  • Block identified unauthorized sources.
  • Support automated containment.

Target Platform: Ubuntu Linux

Ubuntu provides the controlled industrial server environment.

Purpose
  • Host the PyModbus controller.
  • Run the Modbus services.
  • Generate industrial communication.
  • Apply network restrictions.
  • Support security monitoring and response.

Security Testing Platform: Kali Linux

Kali Linux is used as the controlled security-testing environment.

Purpose
  • Generate authorized Modbus TCP test traffic.
  • Perform controlled function-code testing.
  • Validate detection and containment.
  • Perform post-remediation testing.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated laboratory infrastructure.

Purpose
  • Host Ubuntu industrial systems.
  • Host Kali Linux.
  • Create isolated OT network segments.
  • Maintain a reproducible testing environment.

Process

STEP 01

Prepare the Virtualized Industrial Security Environment

  • Create an isolated Industry 4.0 / OT laboratory using VirtualBox.
  • Configure Ubuntu as the industrial controller environment.
  • Configure Kali Linux as the security-testing system.
  • Create a controlled virtual network between the systems.
  • Assign stable laboratory IP addresses.
  • Verify connectivity between the authorized systems.
  • Ensure that the laboratory is isolated from production networks.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Deploy the PyModbus Industrial Controller

  • Install PyModbus on the Ubuntu industrial server.
  • Create the controlled Modbus TCP server.
  • Configure laboratory coils and holding registers.
  • Assign harmless process values to the registers.
  • Configure the controller to listen only on the laboratory network interface.
  • Start the Modbus TCP service.
  • Verify that the controller is operational.
Tools: PyModbus + Ubuntu
STEP 03

Establish the Normal Industrial Communication Flow

  • Configure the authorized Modbus TCP client.
  • Connect the client to the laboratory controller.
  • Perform legitimate register-read operations.
  • Perform authorized control operations where required.
  • Record the expected Modbus function codes.
  • Record the normal source and destination addresses.
  • Establish the normal industrial communication pattern.
Tools: PyModbus + Ubuntu
STEP 04

Configure the Modbus Device Simulation

  • Configure ModbusPal for the controlled industrial environment.
  • Create representative coils and registers.
  • Assign normal laboratory process values.
  • Establish the expected Modbus device behavior.
  • Verify that simulated devices communicate correctly.
  • Compare the simulated behavior with the PyModbus controller.
  • Preserve the normal industrial state as the baseline.
Tools: ModbusPal + PyModbus
STEP 05

Define the Modbus Function-Code Policy

  • Identify the Modbus function codes required by the laboratory application.
  • Define the permitted read operations.
  • Define the permitted write operations.
  • Identify protected registers and coils.
  • Define which systems are authorized to perform write operations.
  • Document the expected Modbus command behavior.
  • Establish the function-code allowlist.
Tools: PyModbus + ModbusPal
STEP 06

Configure Network Access Control

  • Configure UFW on the Ubuntu controller.
  • Permit Modbus TCP communication from the authorized laboratory client.
  • Restrict unnecessary network access to the controller.
  • Verify that unauthorized network sources cannot communicate with the protected service.
  • Record the firewall policy.
  • Validate legitimate Modbus connectivity.
  • Preserve the access-control configuration as the baseline.
Tools: UFW + Ubuntu
STEP 07

Establish the Industrial Traffic Baseline

  • Capture normal Modbus TCP communication.
  • Analyze the Modbus requests and responses.
  • Identify the normal function-code sequence.
  • Record normal register and coil access.
  • Record the normal request frequency.
  • Identify the authorized source device.
  • Preserve the traffic information for comparison during the security assessment.
Tools: TShark + PyModbus
STEP 08

Configure Modbus Command Monitoring

  • Configure TShark-based monitoring for the laboratory Modbus TCP traffic.
  • Monitor Modbus request and response communication.
  • Identify Modbus function codes.
  • Identify register and coil operations.
  • Record the source and destination systems.
  • Monitor command frequency and sequence.
  • Verify that Modbus traffic can be analyzed successfully.
Tools: TShark + Ubuntu
STEP 09

Configure Function-Code Abuse Detection

  • Define the conditions representing suspicious Modbus activity.
  • Identify unexpected function codes.
  • Identify unauthorized write operations.
  • Identify writes against protected registers or coils.
  • Identify requests originating from unauthorized sources.
  • Define the appropriate security alert severity.
  • Validate the detection conditions using normal Modbus traffic.
Tools: TShark + PyModbus
STEP 10

Generate the Controlled Modbus Function-Code Abuse Activity

  • Use the authorized Kali Linux testing system.
  • Connect to the controlled Modbus TCP environment.
  • Generate a controlled unauthorized function-code request.
  • Target only designated laboratory registers or coils.
  • Avoid modifying any real industrial process.
  • Record the time of the test activity.
  • Monitor the Modbus TCP traffic during the simulation.
Tools: Kali Linux + mbpoll + PyModbus
STEP 11

Detect the Unauthorized Modbus Command

  • Allow the monitoring mechanism to collect the generated Modbus request.
  • Identify the source system.
  • Identify the destination controller.
  • Identify the Modbus function code.
  • Identify the targeted register or coil.
  • Compare the command against the established function-code policy.
  • Determine whether the request represents unauthorized Modbus activity.
Tools: TShark + PyModbus
STEP 12

Analyze the Command Pattern

  • Review the Modbus request sequence.
  • Compare the request with the normal industrial traffic baseline.
  • Analyze the command frequency.
  • Determine whether the operation is a read or write.
  • Verify whether the targeted register or coil is authorized.
  • Correlate the source device with the expected communication relationship.
  • Confirm the function-code abuse condition.
Tools: TShark + ModbusPal + PyModbus
STEP 13

Generate the Security Alert

  • Configure the monitoring mechanism to generate a security alert when the function-code abuse condition is satisfied.
  • Include the source IP address.
  • Include the destination controller.
  • Include the Modbus function code.
  • Include the targeted register or coil.
  • Include the event timestamp.
  • Assign an appropriate alert severity.
  • Verify that the suspicious Modbus activity is recorded.
Tools: TShark + Ubuntu
STEP 14

Investigate the Modbus Function-Code Abuse

  • Review the generated security event.
  • Identify the affected controller.
  • Identify the source of the unauthorized request.
  • Review the Modbus function code.
  • Review the targeted register or coil.
  • Compare the command against the authorized function-code policy.
  • Review the controller state.
  • Determine whether the activity represents unauthorized industrial control behavior.
Tools: TShark + PyModbus + ModbusPal
STEP 15

Configure Automated Network Containment

  • Configure the predefined containment response using UFW.
  • Associate the suspicious source with the response condition.
  • Configure the response to restrict the laboratory source from Modbus TCP communication.
  • Ensure that the response is limited to the isolated OT environment.
  • Test the containment mechanism before the final assessment.
  • Verify that authorized Modbus clients remain permitted.
Tools: UFW + Ubuntu
STEP 16

Contain the Unauthorized Modbus Activity

  • Trigger the configured containment action after the suspicious activity is detected.
  • Restrict the identified laboratory source.
  • Prevent additional unauthorized Modbus TCP commands.
  • Verify that legitimate authorized sources remain able to communicate.
  • Review the firewall state after containment.
  • Record the containment event.
Tools: UFW + Ubuntu
STEP 17

Validate Controller Integrity and Legitimate Communication

  • Review the affected laboratory registers and coils.
  • Confirm that the expected controller state is maintained.
  • Restore any laboratory test values if required.
  • Verify that the unauthorized source cannot continue issuing Modbus commands.
  • Use the authorized client to perform legitimate Modbus operations.
  • Confirm that legitimate industrial communication continues normally.
  • Review the final Modbus traffic.
Tools: PyModbus + ModbusPal + TShark + UFW
STEP 18

Perform Final Detection and Response Validation

  • Repeat the controlled Modbus TCP function-code abuse assessment.
  • Verify that the unauthorized function-code request is detected.
  • Verify that the targeted register or coil is identified.
  • Verify that the suspicious command generates a security alert.
  • Verify that the configured network containment is triggered.
  • Confirm that additional unauthorized Modbus commands are restricted.
  • Confirm that the industrial controller remains operational.
  • Verify that legitimate Modbus communication continues to function.
  • Review the complete detection and containment timeline.
  • Document the final OT security assessment results.
Tools: PyModbus + mbpoll + TShark + UFW + Ubuntu + Kali Linux

Outcome

  1. Modbus TCP Function Code Abuse is successfully simulated within the isolated Industry 4.0 / OT laboratory environment.
  2. A PyModbus-based industrial controller is successfully deployed with controlled coils and registers representing industrial process data.
  3. A normal Modbus TCP communication baseline is established, including authorized sources, function codes, registers, coils, and communication patterns.
  4. Unexpected Modbus function codes and unauthorized write operations are identified through command-level monitoring.
  5. Unauthorized register or coil access is detected and correlated with the corresponding Modbus TCP request, providing evidence of function-code abuse.
  6. Security alerts are generated when the configured Modbus function-code abuse conditions are satisfied, providing visibility into suspicious industrial protocol activity.
  7. The identified laboratory source is automatically contained through the configured network-access control mechanism, preventing continued unauthorized Modbus communication.
  8. The industrial controller's expected laboratory state is validated and restored where required, ensuring that the controlled industrial environment remains consistent.
  9. Legitimate Modbus TCP communication continues to function for authorized systems, minimizing unnecessary disruption to normal industrial operations.
  10. The complete Modbus TCP function-code abuse detection, industrial command monitoring, function-code validation, register/coil authorization, security alerting, automated network containment, controller-state validation, and post-containment verification workflow is successfully demonstrated.