AN OPEN-SOURCE INTRUSION DETECTION AND NOTIFICATION FRAMEWORK FOR OT ATTACKS TARGETING S7-SERIES PLCS
Date
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
This article presents an open-source intrusion detection and notification (IDN) framework designed to detect attacks targeting Siemens S7-series programmable logic controllers (PLCs) in operational technology (OT) environments. The framework is validated using a simulated weight-based sorting system developed in Factory I/O, with TIA Portal control programs deployed on S7-300, S7-1200, and S7-1500 PLCs. Suricata serves as the core intrusion detection engine, while the Elasticsearch, Logstash, and Kibana (ELK) stack and LINE Notify are integrated to visualize alerts and provide realtime operator notifications. Simulated attacks are carried out using Snap7 to interact with each PLC during live process operations. The experimental results show that the framework reliably detects intrusions across all tested S7 PLC models and delivers timely alerts, demonstrating its effectiveness for real-time monitoring and incident response. In contrast to previous studies that focus primarily on protocol analysis or on individual PLC types, this work offers a practical and scalable intrusion detection solution validated on real hardware and designed to accommodate the coexistence of legacy and modern controllers within OT systems.
