Monitoring Encrypted Communication with OPC UA

  • Toshiaki Honda Nagoya Institute of Technology
  • Yuki Shimazawa Nagoya Institute of Technology
  • Takashi Hamaguchi Nagoya Institute of Technology
  • Yoshihiro Hashimoto Nagoya Institute of Technology
Keywords: cyber-security, encrypted data, monitoring system, OPC UA, SIEM


Cyber-attacks on critical infrastructure have been on the rise. Therefore, cyber-security has become very important for Industrial Control Systems. For communication protocol in Industrial Control Systems networks, the Open Platform Communications Unified Archi-tecture communication protocol, which enables secure and platform-independent commu-nications, is expected to be widely used. An important property of Open Platform Commu-nications Unified Architecture is encryption. It is effective in protecting communication data from tampering and eavesdropping but also makes it impossible to monitor communications. In Industrial Control Systems, inappropriate commands to controllers can cause dangerous situations. Even a secure communication protocol cannot guarantee that the data being communicated are safe. There are many types of machines, such as operating support sys-tems and engineering workstations, that can send commands to controllers. They are im-plemented in common operating systems and may fall victim to a cyber-attack. Therefore, the commands to controllers should be monitored. We monitor the communication by de-crypting the encrypted data. In addition, we propose a method of monitoring without communication loads by making the decryption mechanism independent and using the de-crypted data to enable flexible integration with other systems such as Security Information and Event Management.


