INFORMATIZATION AND MANAGEMENT

The use of behavioral profiles and DPI-based command detection to protect against unauthorized changes in NCU parameters in food production

Authors

  • Xia Endo Belarusian State University, 4 Nezavisimosti Ave., Minsk, 220030, Belarus
  • He Hunyan Belarusian State University, 4 Nezavisimosti Ave., Minsk, 220030, Belarus
  • Fan Linda Belarusian State University, 4 Nezavisimosti Ave., Minsk, 220030, Belarus
  • Xu Yifan Belarusian State University, 4 Nezavisimosti Ave., Minsk, 220030, Belarus

How to cite

GOST Endo X., Hunyan H., Linda F., Yifan X. The use of behavioral profiles and DPI-based command detection to protect against unauthorized changes in NCU parameters in food production // Bakery of Russia. 2025. Vol. 69. No. 1-2. P. 37-46.
APA Endo, X., Hunyan, H., Linda, F. & Yifan, X. (2025). The use of behavioral profiles and DPI-based command detection to protect against unauthorized changes in NCU parameters in food production. Bakery of Russia, 69(1-2), 37-46.

Abstract

The article examines the provision of cyber resilience of low-voltage switchgear devices (LVSD) in the food industry under conditions of increasing network connectivity driven by the concepts of Industry 4.0 and the convergence of operational and information technologies, in which LVSD cease to be an isolated physical interface and become a vulnerable point of impact on recipe and process parameters of technological lines (pasteurization, sterilization, control of pump groups and thermal units). The limitations of traditional signature-based and threshold-based monitoring tools are analyzed; such tools fail to recognize the misuse of legitimate industrial protocol commands and generate excessive false alarms during transient modes (CIP cleaning, reconfiguration, commissioning), which undermines operator trust in protection systems. An approach is proposed and verified that combines deep packet inspection (DPI) with machine-learning-based behavioral profiling, enabling the extraction of command semantics at the level of Modbus TCP registers and Profinet IO objects and the correlation of network actions with the context of the production cycle. An experimental implementation on a hybrid testbed with Siemens S7-1500 and Schneider Electric Modicon M340 PLCs and high-performance traffic capture is described; a long-term dataset of network exchanges was formed, including normal and non-standard modes, and 15 classes of attacks were synthetically reproduced, including command injections, MITM, and replay scenarios. Quantitative detection characteristics are presented: high effectiveness for direct setpoint writes and command injections with millisecond-level reaction times, while replay attacks pose the greatest challenge, requiring accumulation of historical context and demonstrating a higher miss rate and increased detection latency. The impact of the DPI gateway on latency and jitter is analyzed: with active blocking, delays increase nonlinearly with load but remain within typical Modbus TCP tolerances; at the same time, increased delay variability under peak traffic is noted as a risk factor for real-time control loops. The heterogeneity of false blocking across operating modes is considered separately: minimal values are characteristic of steady-state production, whereas modes with high command entropy (CIP, reconfiguration, commissioning) require context-dependent profile switching.

Keywords

deep packet inspection DPI behavioral profiling industrial cybersecurity Modbus TCP Profinet low-voltage switchgear devices

References

Аникеев Д. А. Исследование возможности использования флэш-накопителей для защиты от несанкционированного доступа к информации // Россия молодая: мат. VI Всерос. науч.-прак. конф. мол. учен. с межд. участ. Под ред. В. Ю. Блюменштейна. 2014. С. 141.

Боровлев Б.С., Мушта А.И., Панарин С.И., Бачурин В.И. Встраиваемая программа защиты от несанкционированного доступа // Информация и безопасность. 2000. Т. 3. № 1. С. 84-85.

Гончарова О. Н., Никифоров С. В. Средства защиты от несанкционированного доступа // Проблемы информационной безопасности. 2015. С. 77.

Демкин Д. А. Защита базы данных от несанкционированного доступа // Актуальные проблемы науки и техники: мат. Всерос. (Национ.) науч.-прак. конф. Ростов н/Дону, 2024. С. 243-245.

Десницкий В. А., Котенко И. В. Модель защиты программ от несанкционированных изменений на основе механизма удаленного доверия // Информационная безопасность регионов России (ИБРР-2007): мат. конф. 2007. С. 81.

Запорожцев А.А., Козубенко М.В., Шейдаков Н.Е. Использование асимметричных криптосистем для защиты информации от несанкционированного доступа // Информационные системы, экономика, управление трудом и производством: ученые записки. Ростов н/Дону, 2014. С. 89-93.

Земляченко В.В., Бабаев А.А. Способы защиты беспроводных сетей Wi-Fi от несанкционированного доступа // Молодежь и кооперация: реальность и будущее: мат. Межд. студ. науч. конф. Белгород, 2011. С. 9-11.

Казанский Л.А., Письменный А.А., Фаерович С.И., Камынин И.П., Воронов А.Б., Сериков А.А. Устройство для защиты дифманометра: авт. свидет. SU 744256 A1 / № 2334699; заявл. 18.03.1976; опубл. 30.06.1980.

Краснопевцев А. А. Защита от несанкционированного копирования приложений, компилируемых в промежуточное представление: дис. ... канд. техн. наук. М., 2011. 24 с.

Краснопевцев А.А. Разработка автоматической защиты от несанкционированного копирования .NET приложений с использованием внешнего аппаратного модуля // Безопасность информационных технологий. 2009. Т. 16. № 1. С. 54-57.

Крахмальный И.О. Разработка модели прогнозирования кибератак // Академический исследовательский журнал. 2025. Т. 3. № 5. С. 180-184.

Кузнецов А.В. Информационная технология пассивной защиты цифровых изображений и видеосигналов от несанкционированных изменений: отчет о НИР: грант № СП-66.2015.5. 2015. 54 с.

Магомедова Н.А., Аливагабов М.К. Средства защиты информации от несанкционированного доступа // Вопросы структуризации экономики. 2009. № 1. С. 87.

Муратов А. В., Дубровин А. С., Коротков М. В., Рогозин Е. А. Оценка системы защиты информации от несанкционированного доступа при проектировании электронных средств // Проектирование и технология электронных средств. 2003. № 3. С. 7-10.

Степанцов А.А., Осадчий Ю.Ю., Танчер С.В. Новый класс устройств защиты информации от несанкционированного доступа – технические средства контроля доступа к аппаратным средствам ПЭВМ // Интеграл. 2007. № 5. С. 38-39.

Issue

Section

INFORMATIZATION AND MANAGEMENT

Metrics

99 views
0 downloads
Want to publish with us?
Submit an article

Machine-readable metadata