Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.

Rinieri, L., Melis, A., Girau, R., Pau, G., Prandini, M., Callegati, F. (2026). P4ICS: P4 in-network security for Industrial Control Systems networks. COMPUTER NETWORKS, 287, 1-15 [10.1016/j.comnet.2026.112560].

P4ICS: P4 in-network security for Industrial Control Systems networks

Rinieri, Lorenzo;Melis, Andrea;Girau, Roberto;Pau, Giovanni;Prandini, Marco;Callegati, Franco
2026

Abstract

Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.
2026
Rinieri, L., Melis, A., Girau, R., Pau, G., Prandini, M., Callegati, F. (2026). P4ICS: P4 in-network security for Industrial Control Systems networks. COMPUTER NETWORKS, 287, 1-15 [10.1016/j.comnet.2026.112560].
Rinieri, Lorenzo; Melis, Andrea; Girau, Roberto; Pau, Giovanni; Prandini, Marco; Callegati, Franco
File in questo prodotto:
Eventuali allegati, non sono esposti

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11585/1072513
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact