Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.
Rinieri, L., Melis, A., Girau, R., Pau, G., Prandini, M., Callegati, F. (2026). P4ICS: P4 in-network security for Industrial Control Systems networks. COMPUTER NETWORKS, 287, 1-15 [10.1016/j.comnet.2026.112560].
P4ICS: P4 in-network security for Industrial Control Systems networks
Rinieri, Lorenzo;Melis, Andrea;Girau, Roberto;Pau, Giovanni;Prandini, Marco;Callegati, Franco
2026
Abstract
Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



