Securing the openplc
No Thumbnail Available
Date
2026-06
Journal Title
Journal ISSN
Volume Title
Publisher
AIKTC
Abstract
This project presents a multi-layered security enhancement for Industrial
Control Systems (ICS) by hardening the OpenPLC platform against contemporary
cyber-attacks. The primary objective is to address the inherent
security deficits in legacy industrial protocols, such as Modbus/TCP and
DNP3, which traditionally lack native authentication and encryption. To
achieve this, we engineered an integrated security suite comprising Time-
Based One-Time Password (TOTP) Multi-Factor Authentication for the
web management interface, an automated vulnerability auditing tool for
system boot-up, and TLS 1.3 encryption for data transit.
The methodology further incorporates a real-time Intrusion Detection
System (IDS) using Snort to perform Deep Packet Inspection (DPI), specifically
targeting unauthorized industrial command injections. This objective
was successfully achieved, resulting in a controller appliance capable
of resisting sophisticated network-based threats. Experimental evaluations
demonstrate that the proposed framework successfully identifies 98 percent
of unauthorized industrial commands and completely mitigates credentialbased
attacks. Significantly, the system maintains high operational efficiency
by introducing a negligible latency overhead of less than 5 milliseconds,
ensuring that the critical timing requirements of real-time industrial
processes are never compromised.