Modbus Function-Code Allowlisting
The security architecture defines the Modbus function codes permitted for the laboratory controller.
Prevent unexpected Modbus operations from being accepted as normal industrial communication.
Industrial organizations use Modbus TCP to exchange control and monitoring information between industrial controllers, supervisory systems, engineering workstations, and other operational-technology components.
Modbus TCP allows devices to perform operations such as reading coils, reading registers, writing coils, and writing holding registers. Because these operations can directly influence industrial process data or control states, unauthorized Modbus commands can create significant operational and safety risks.
An attacker who gains access to an industrial network may send unauthorized Modbus function codes to an industrial controller. If the controller accepts commands that the requesting device or user is not authorized to perform, the attacker may modify process values, change control states, or interfere with industrial operations.
In this use case, a controlled Industry 4.0 / OT laboratory environment is created using Ubuntu virtual machines. A PyModbus-based industrial controller simulator represents the controlled Modbus TCP device.
Kali Linux is used as the authorized security-testing system. A controlled Modbus TCP command-abuse simulation is performed against the laboratory controller.
No real industrial equipment or physical production process is affected. The simulation uses only a software-based industrial controller and harmless laboratory registers.
The defensive mechanism introduces Modbus function-code whitelisting, register-access authorization, command-pattern monitoring, and security alerting.
The security monitoring system identifies Modbus operations that fall outside the expected communication behavior. Unauthorized write operations or unexpected function-code usage generate security alerts and can trigger the configured containment response.
After detection, the suspicious Modbus activity is investigated and contained. Legitimate industrial communication is then tested to verify that authorized controller operations continue normally.
The complete defensive workflow is: Modbus TCP Controller → Unauthorized Function Code → Command Monitoring → Function-Code Validation → Suspicious Modbus Activity → Security Alert → Automated Response → Command Containment → Controller Validation.
Modbus TCP is an industrial communication protocol used to exchange data between control systems and industrial devices. Industrial applications may use Modbus TCP for reading sensor values, monitoring process states, and writing control values to connected devices.
Modbus TCP communication can become a security risk when the industrial network does not adequately restrict which systems can issue control-related commands.A compromised workstation or unauthorized device may attempt to send Modbus write operations to an industrial controller. If the controller accepts unexpected function codes or unauthorized register modifications, an attacker may influence the industrial process represented by the laboratory environment.
The security problem is therefore:
The proposed solution introduces Modbus function-code allowlisting, register-access control, command-pattern monitoring, security alerting, and automated response to detect and contain unauthorized industrial control commands.
The attack scenario simulates unauthorized use of Modbus TCP function codes against a controlled industrial controller. A laboratory testing system sends controlled Modbus requests to the PyModbus-based industrial controller. The simulation focuses on unauthorized write-related Modbus operations that would normally require specific authorization. The objective is to determine whether the security controls can identify unexpected Modbus commands and prevent unauthorized modification of protected industrial process values.
The primary security concept is industrial protocol command validation.
Instead of allowing every Modbus TCP operation from every connected system, the security architecture defines which function codes and register ranges are expected for each authorized communication relationship. A legitimate industrial communication flow should use only the Modbus operations required by the specific application. Unexpected write operations, unauthorized function codes, or abnormal command sequences should be treated as suspicious and investigated.
The secure processing flow is:
The security architecture defines the Modbus function codes permitted for the laboratory controller.
Prevent unexpected Modbus operations from being accepted as normal industrial communication.
The security architecture defines the Modbus function codes permitted for the laboratory controller.
Prevent unexpected Modbus operations from being accepted as normal industrial communication.
Specific Modbus registers and coils are classified according to their permitted operations.
Prevent unauthorized modification of protected industrial values.
The source of each Modbus TCP request is identified and compared with the expected communication relationship.
Ensure that only authorized industrial systems communicate with the controller.
Modbus TCP requests are continuously monitored.
Provide visibility into industrial control commands.
Modbus requests are analyzed for abnormal function-code usage, request frequency, and communication sequences.
Identify behavior that differs from the established industrial communication baseline.
Unexpected write operations against protected registers or coils are detected.
Identify potentially dangerous industrial control activity.
A security alert is generated when the configured Modbus-abuse detection condition is satisfied.
Provide immediate visibility into suspicious industrial protocol activity.
The configured response can temporarily restrict the identified laboratory source from communicating with the industrial controller.
Determine whether unauthorized commands changed the expected industrial state.
Authorized Modbus communication is tested after containment.
Confirm that legitimate industrial communication continues to operate correctly.
PyModbus is used to create the controlled Modbus TCP industrial controller and client environment.
ModbusPal is used to simulate Modbus devices and industrial register behavior.
mbpoll is used to generate controlled Modbus TCP requests during security validation.
TShark is used to analyze captured Modbus TCP network traffic.
UFW (Uncomplicated Firewall) is used to enforce network restrictions around the controlled Modbus TCP controller.
Ubuntu provides the controlled industrial server environment.
Kali Linux is used as the controlled security-testing environment.
VirtualBox provides the isolated laboratory infrastructure.