A Packet-Layer Capability Triad for Remote Operational Technology: A Candidate Compensating Control for Physically Exposed, Resource-Constrained Sites
Authors/Creators
Description
Remote operational-technology (OT) sites—including water and wastewater pump and lift stations, roadside traffic-control cabinets, distribution substations, and oil-and-gas remote terminal unit locations—often combine legacy endpoints, remote administration, sparse staffing, and shared or insufficiently segmented field networks. Standards and government guidance correctly prioritize reducing external exposure, segmenting networks, and replacing or hardening insecure equipment. In documented small-system settings, however, cost, outage, and workforce constraints can delay those preferred controls.
This paper asks a narrower question: which packet-layer capabilities could reduce cyber-physical risk while full segmentation, protocol modernization, or equipment replacement remains incomplete? It presents a conceptual synthesis rather than an experimental validation or systematic review. A purposively selected primary-source incident corpus is used to identify recurring stages of attack: discovery or remote access, traversal of weak boundaries, and manipulation through authorized interfaces or well-formed control actions. Cases involving direct OT manipulation show that the final process effect can be delivered through legitimate control-system functionality even when malware enables access or persistence. Colonial Pipeline is treated separately as a boundary case because public reporting found no lateral movement into OT; its operational disruption followed loss of confidence in interconnected business and operational dependencies rather than demonstrated command-level compromise.
The paper defines a candidate packet-layer capability triad: (1) automated moving target defense (AMTD) with embedded deception; (2) cyber-physical anomaly enforcement based on communication and process state; and (3) command-aware industrial-protocol enforcement. The triad is intended to operate on the network path without requiring software agents on protected controllers. It is not presented as equivalent to zones-and-conduits segmentation, nor as a substitute where segmentation is feasible. The paper maps the three capabilities to the derived attack path, relates them to NIST cyber-resiliency guidance and IEC 62443 compensating-measure concepts, and specifies a falsifiable evaluation program covering security efficacy, process safety, availability, false decisions, bypass resistance, and deployment economics. Important limitations include direct physical bypass, encrypted traffic, authorized-but-malicious command paths, model drift, inline-device failure modes, and the concentration of economic evidence in the U.S. water sector.
Other (English)
Technical preprint; not peer reviewed. This version supersedes the author's local draft v0.2. It reframes the architecture as a candidate compensating control, adds an explicit method and evidence-boundary section, updates the current TSA pipeline directive and 2026 GAO water-sector evidence, corrects and normalizes references, removes unpublished self-citations, and expands treatment of safety, availability, physical bypass, encrypted traffic, model drift, parser risk, and falsifiable evaluation. No new dataset was generated or analyzed. The author is affiliated with PacketViper, LLC, whose first-party implementation is identified solely to establish realizability; first-party product documentation is not treated as efficacy evidence. AI tools assisted with literature discovery, citation checking, editing, and preparation of archival files; the author reviewed and is responsible for all claims and conclusions.
Files
Citation_Verification_Ledger.csv
Files
(939.0 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:bf0c1cf927529568afc44b50958df03a
|
3.7 kB | Download |
|
md5:6dd2848ade1d1c6df0478089935d01c8
|
22.6 kB | Preview Download |
|
md5:cba8047e21d6bfe8eff29d0feea2b4ee
|
727 Bytes | Preview Download |
|
md5:e84c3d61a885bde35f719683f6f18dd7
|
1.3 kB | Preview Download |
|
md5:ec03062d7c89663da62ca4ccca2a09f9
|
2.6 kB | Preview Download |
|
md5:28ac7b55d37b1fdda0574f70bbff0b8a
|
246.7 kB | Preview Download |
|
md5:714a64b7eea36117e592ac32f2e10b0c
|
14.4 kB | Download |
|
md5:b5874c582803923cdf8970ace3e01fa1
|
11.8 kB | Download |
|
md5:315b924f1db916597fe4019e4ea40fcd
|
62.5 kB | Download |
|
md5:358dc7dc91be39669c42a877832b4f52
|
73.8 kB | Preview Download |
|
md5:16e432e8e93af67db560e1af1c0bddb0
|
499.0 kB | Preview Download |
Additional details
References
- REFERENCE 1 K. Stouffer, M. Pease, C. Tang, T. Zimmerman, V. Y. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, *Guide to Operational Technology (OT) Security*, NIST Special Publication 800-82 Revision 3. Gaithersburg, MD, USA: National Institute of Standards and Technology, Sept. 2023. doi: 10.6028/NIST.SP.800-82r3. https://csrc.nist.gov/pubs/sp/800/82/r3/final
- REFERENCE 2 Cybersecurity and Infrastructure Security Agency, Environmental Protection Agency, and Federal Bureau of Investigation, *Top Cyber Actions for Securing Water Systems*, joint fact sheet, revised Feb. 23, 2024. https://www.cisa.gov/resources-tools/resources/top-cyber-actions-securing-water-systems
- REFERENCE 3 Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, *DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks*, Joint Cybersecurity Advisory AA21-131A, May 11, 2021. https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a
- REFERENCE 4 Transportation Security Administration, *Security Directive Pipeline-2021-02G: Pipeline Cybersecurity Mitigation Actions, Contingency Planning, and Testing*, effective May 3, 2026 through May 2, 2027. https://www.tsa.gov/sites/default/files/signed_security_directive_pipeline-2021-02g_and_transmittal_memo_508c.pdf
- REFERENCE 5 U.S. Government Accountability Office, *Critical Infrastructure Protection: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector*, GAO-26-109159, May 21, 2026. https://www.gao.gov/products/gao-26-109159
- REFERENCE 6 Congressional Research Service, *Cybersecurity of the Municipal Water Sector: Background and Issues for Congress*, CRS Report R48556, June 3, 2025. https://crsreports.congress.gov/product/pdf/R/R48556
- REFERENCE 7 R. M. Lee, M. J. Assante, and T. Conway, *Analysis of the Cyber Attack on the Ukrainian Power Grid: Defense Use Case*. E-ISAC and SANS ICS, Mar. 18, 2016. https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2016/05/20081514/E-ISAC_SANS_Ukraine_DUC_5.pdf
- REFERENCE 8 S. Miller and E. Reese, "A Totally Tubular Treatise on TRITON and TriStation," Mandiant Threat Intelligence, June 7, 2018. https://cloud.google.com/blog/topics/threat-intelligence/totally-tubular-treatise-triton-and-tristation
- REFERENCE 9 Dragos, Inc., *CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations*, June 2017. https://hub.dragos.com/hubfs/116-Whitepapers/CrashOverride-whitepaper.pdf
- REFERENCE 10 Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, National Security Agency, Environmental Protection Agency, and Israel National Cyber Directorate, *IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including U.S. Water and Wastewater Systems Facilities*, Joint Cybersecurity Advisory AA23-335A, Dec. 2023, updated Dec. 18, 2024. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a
- REFERENCE 11 Idaho National Laboratory, *Precursor Analysis Report: Remote Access Attack on Oldsmar Water Treatment Facility 2021*, INL/RPT-22-70551, Dec. 31, 2022. https://cyote.inl.gov/content/uploads/24/2025/12/CyOTE-Case-Study_Oldsmar.pdf
- REFERENCE 12 R. Ross, V. Pillitteri, R. Graubart, D. Bodeau, and R. McQuaid, *Developing Cyber-Resilient Systems: A Systems Security Engineering Approach*, NIST Special Publication 800-160 Volume 2 Revision 1. Gaithersburg, MD, USA: National Institute of Standards and Technology, Dec. 2021. doi: 10.6028/NIST.SP.800-160v2r1. https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final
- REFERENCE 13 R. Zhuang, S. A. DeLoach, and X. Ou, "Towards a Theory of Moving Target Defense," in *Proceedings of the First ACM Workshop on Moving Target Defense (MTD '14)*, 2014, pp. 31–40. doi: 10.1145/2663474.2663479.
- REFERENCE 14 B. C. Ward, S. R. Gomez, R. W. Skowyra, D. Bigelow, J. N. Martin, J. W. Landry, and H. Okhravi, *Survey of Cyber Moving Targets*, 2nd ed., MIT Lincoln Laboratory Technical Report 1228, Jan. 17, 2018. https://web.mit.edu/ha22286/www/papers/MTSurvey.pdf
- REFERENCE 15 C. Lei, H.-Q. Zhang, J.-L. Tan, Y.-C. Zhang, and X.-H. Liu, "Moving Target Defense Techniques: A Survey," *Security and Communication Networks*, vol. 2018, art. 3759626, 2018. doi: 10.1155/2018/3759626.
- REFERENCE 16 J.-H. Cho, D. P. Sharma, H. Alavizadeh, S. Yoon, N. Ben-Asher, T. J. Moore, D. S. Kim, H. Lim, and F. F. Nelson, "Toward Proactive, Adaptive Defense: A Survey on Moving Target Defense," *IEEE Communications Surveys & Tutorials*, vol. 22, no. 1, pp. 709–745, 2020. doi: 10.1109/COMST.2019.2963791.
- REFERENCE 17 A. C. Pappa, A. Ashok, and M. Govindarasu, "Moving Target Defense for Securing Smart Grid Communications: Architecture, Implementation & Evaluation," in *2017 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT)*, 2017. doi: 10.1109/ISGT.2017.8085954.
- REFERENCE 18 Y. Hu, P. Xun, P. Zhu, and W. Kang, "Moving Target Defense Based on Adaptive Forwarding Path Migration for Securing the SCADA Network," *Security and Communication Networks*, vol. 2021, art. 1704125, 2021. doi: 10.1155/2021/1704125.
- REFERENCE 19 S. Cheung, B. Dutertre, M. Fong, U. Lindqvist, K. Skinner, and A. Valdes, "Using Model-Based Intrusion Detection for SCADA Networks," in *Proceedings of the SCADA Security Scientific Symposium*, Miami Beach, FL, USA, Jan. 2007, pp. 127–134. https://www.csl.sri.com/papers/scadaIDS07/SCADA-IDS-S4-2007.pdf
- REFERENCE 20 T. H. Morris, B. A. Jones, R. B. Vaughn, and Y. S. Dandass, "Deterministic Intrusion Detection Rules for MODBUS Protocols," in *2013 46th Hawaii International Conference on System Sciences*, 2013, pp. 1773–1781. doi: 10.1109/HICSS.2013.174.
- REFERENCE 21 I. N. Fovino, A. Carcano, T. De Lacheze Murel, A. Trombetta, and M. Masera, "Modbus/DNP3 State-Based Intrusion Detection System," in *2010 24th IEEE International Conference on Advanced Information Networking and Applications*, 2010, pp. 729–736. doi: 10.1109/AINA.2010.86.
- REFERENCE 22 A. Kleinmann and A. Wool, "Accurate Modeling of the Siemens S7 SCADA Protocol for Intrusion Detection and Digital Forensics," *Journal of Digital Forensics, Security and Law*, vol. 9, no. 2, art. 4, 2014. doi: 10.15394/jdfsl.2014.1169. https://commons.erau.edu/jdfsl/vol9/iss2/4/
- REFERENCE 23 O. N. Nyasore, P. Zavarsky, B. Swar, R. Naiyeju, and S. Dabra, "Deep Packet Inspection in Industrial Automation Control System to Mitigate Attacks Exploiting Modbus/TCP Vulnerabilities," in *2020 IEEE 6th International Conference on Big Data Security on Cloud, High Performance and Smart Computing, and Intelligent Data and Security*, 2020, pp. 241–245. doi: 10.1109/BigDataSecurity-HPSC-IDS49724.2020.00051.
- REFERENCE 24 S. Maesschalck, V. Giotsas, B. Green, and N. Race, "Don't Get Stung, Cover Your ICS in Honey: How Do Honeypots Fit Within Industrial Control System Security," *Computers & Security*, vol. 114, art. 102598, 2022. doi: 10.1016/j.cose.2021.102598.
- REFERENCE 25 K. Wilhoit, *The SCADA That Didn't Cry Wolf: Who's Really Attacking Your ICS Equipment?*, Trend Micro Research, 2013. https://documents.trendmicro.com/assets/white_papers/wp-the-scada-that-didnt-cry-wolf.pdf
- REFERENCE 26 M. Dodson, A. R. Beresford, and M. Vingaard, "Using Global Honeypot Networks to Detect Targeted ICS Attacks," in *2020 12th International Conference on Cyber Conflict (CyCon)*, 2020, pp. 275–291. doi: 10.23919/CyCon49761.2020.9131734.
- REFERENCE 27 S. Gokhale, A. Dalvi, and I. Siddavatam, "Industrial Control Systems Honeypot: A Formal Analysis of Conpot," *International Journal of Computer Network and Information Security*, vol. 12, no. 6, pp. 44–56, 2020. doi: 10.5815/ijcnis.2020.06.04.
- REFERENCE 28 J. J. Williams, M. Edwards, and J. Gardiner, "Time-to-Lie: Identifying Industrial Control System Honeypots Using the Internet Control Message Protocol," in *2025 IEEE 45th International Conference on Distributed Computing Systems Workshops (ICDCSW)*, 2025. doi: 10.1109/ICDCSW63273.2025.00141.
- REFERENCE 29 Water Sector Coordinating Council, *Cybersecurity: 2021 State of the Sector*, survey report, June 2021. https://www.waterisac.org/2021survey
- REFERENCE 30 ISA/IEC 62443-3-2:2020, *Security for Industrial Automation and Control Systems—Part 3-2: Security Risk Assessment for System Design*. International Society of Automation / International Electrotechnical Commission, 2020.
- REFERENCE 31 ISA/IEC 62443-3-3:2013, *Industrial Communication Networks—Network and System Security—Part 3-3: System Security Requirements and Security Levels*. International Society of Automation / International Electrotechnical Commission, 2013.
- REFERENCE 32 IEC 62443-2-1:2024, *Security for Industrial Automation and Control Systems—Part 2-1: Security Program Requirements for IACS Asset Owners*. International Electrotechnical Commission, 2024.
- REFERENCE 33 E. Byres, E. Schweigert, and M. Thomas, "Securing EtherNet/IP Control Systems Using Deep Packet Inspection Firewall Technology," in *2014 ODVA Industry Conference & 16th Annual Meeting*, 2014. https://www.odva.org/wp-content/uploads/2022/06/2014_ODVA_Conference_Byres_Schweigert_Thomas_Securing_EtherNetIP_with_DPI_FINAL.pdf
- REFERENCE 34 A. Gebhard and D. Perouli, "Attacks on EtherNet/IP and Migrations through CIP Security," in *2024 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)*, 2024, pp. 145–154. doi: 10.1109/ACSACW65225.2024.00022.
- REFERENCE 35 B. Ghena, W. Beyer, A. Hillaker, J. Pevarnek, and J. A. Halderman, "Green Lights Forever: Analyzing the Security of Traffic Infrastructure," in *Proceedings of the 8th USENIX Workshop on Offensive Technologies (WOOT '14)*, 2014. https://www.usenix.org/conference/woot14/workshop-program/presentation/ghena
- REFERENCE 36 PacketViper, "OT Protocol Command Control," company product documentation, accessed July 17, 2026. https://packetviper.com/ot-protocol-command-control/
- REFERENCE 37 PacketViper, *Operational Technology Remote (OTRemote) Solution*, company product brief, accessed July 17, 2026. https://packetviper.com/wp-content/uploads/2026/03/Product-Brief-packetviper-otr-solution-product-brief-3.21.23.pdf