跳至正文

Modbus/ICS Protocol Integration

Overview

Modbus is a serial communication protocol widely used in industrial control systems. KYRA MDR monitors Modbus traffic for detecting unauthorized access and anomalous commands. Supports Modbus TCP and Modbus RTU over TCP.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Network tap or span port mirroring Modbus TCP traffic (port 502)
  • Suricata or Zeek configured for Modbus protocol parsing
  • Network segmentation between IT and OT networks

Configuration

Configure Modbus traffic monitoring:

  1. Deploy a network sensor on the OT network segment
  2. Configure Suricata with ICS rulesets:
suricata.yaml
app-layer:
protocols:
modbus:
enabled: yes
detection-ports:
dp: 502
  1. Configure Zeek for Modbus logging:
local.zeek
@load policy/protocols/modbus/known-masters-slaves
@load policy/protocols/modbus/track-memmap
  1. Forward ICS events to the collector via syslog

Collected Log Types

Log TypeDescriptionSecurity Use
Read CoilsCoil read operationsProcess monitoring
Write CoilsCoil write operationsUnauthorized control detection
Read RegistersRegister read operationsData access monitoring
Write RegistersRegister write operationsProcess manipulation detection
ExceptionsProtocol exception eventsError and attack detection
ConnectionTCP connection eventsNetwork access monitoring

Troubleshooting

No Modbus traffic: Verify the sensor is on the correct OT network segment. Port 502 by default.

ICS rules not triggering: Load ICS-specific rulesets in Suricata.

Safety warning: Use passive monitoring (IDS mode) only on OT networks. Never deploy inline IPS.

Contact kyra@seekerslab.com for support.