top of page

Industrial Protocols 101: Modbus, DNP3, OPC UA, EtherNet/IP, PROFINET

7 days ago
4 min read

Industrial protocols are the languages controllers, HMIs and SCADA servers use to talk to each other. Most of them were created when control networks were isolated and everyone on the wire was assumed to be trustworthy. That history explains a lot about why OT security looks the way it does today.

The veterans: Modbus and DNP3

Modbus was published by Modicon in 1979 for use with its programmable logic controllers. It's simple, open and royalty-free, which is exactly why it spread so widely. Today Modbus runs over serial links (Modbus RTU and ASCII) and over Ethernet (Modbus TCP), and it shows up in everything from power meters and drives to tank gauges and building systems.

Modbus has no built-in authentication or encryption. Any device that can reach a Modbus server on the network can generally read values and write to registers and coils. A secure variant that wraps Modbus in TLS has been published by the Modbus Organization, but most installed equipment doesn't support it.

DNP3 (Distributed Network Protocol) was developed in the early 1990s and became widely used in electric utilities, water and wastewater systems and other SCADA environments, particularly in North America. It was built for the realities of wide-area telemetry: slow or unreliable links, time-stamped events, and the need to report changes rather than constantly polling every value. It's now standardized as IEEE 1815.

Like Modbus, the original DNP3 had no authentication. To address this, DNP3 Secure Authentication was added to the standard, allowing devices to verify that critical messages, such as control commands, come from a legitimate source. Secure Authentication protects integrity and authenticity but doesn't encrypt traffic on its own, and adoption across the installed base has been gradual.

OPC UA: security built in from the start

OPC UA (Open Platform Communications Unified Architecture) was released by the OPC Foundation in 2008 as the successor to the older, Windows-based OPC Classic specifications. It's platform-independent, is published as IEC 62541, and is widely used to move data between control systems, historians, MES platforms and, increasingly, cloud services.

Unlike most older protocols, OPC UA was built with security in mind. It supports certificate-based application authentication, user authentication, message signing and encryption. The catch is configuration: OPC UA servers can be set to a security mode of "None," and certificate management is often skipped or handled loosely. A protocol with good security options only delivers that security when the options are switched on.

EtherNet/IP and PROFINET: industrial Ethernet

EtherNet/IP carries the Common Industrial Protocol (CIP) over standard Ethernet and TCP/IP. It's managed by ODVA and is widely used in manufacturing and process industries, especially in North America. CIP handles both real-time I/O traffic and configuration and diagnostic messaging.

Standard EtherNet/IP doesn't authenticate who is sending commands. ODVA introduced CIP Security in the mid-2010s, adding device authentication, integrity protection and optional encryption using TLS and DTLS. Support is growing in newer devices, but large numbers of controllers in the field don't support it.

PROFINET is an industrial Ethernet standard maintained by PROFIBUS & PROFINET International (PI). It's common in factory automation and process plants, particularly in Europe, and supports very fast, deterministic communication for motion control and I/O. Traditional PROFINET also lacks authentication and encryption. PI has defined security extensions that add integrity and authenticity protections, with support arriving gradually in newer products.

Why so many lack security, and what that means

Table comparing Modbus, DNP3, OPC UA, EtherNet/IP and PROFINET by origin, typical use and built-in security
Where today's most common industrial protocols came from and what security they offer.

These protocols weren't built carelessly. They were built for isolated networks, limited processing power and strict timing requirements. Adding encryption could introduce delay, and devices with small processors couldn't handle it. Nobody expected a control network to be reachable from an office laptop, a vendor's remote connection or the internet.

The implications for defenders are practical:

  • Anyone on the network can talk to the controller. Without authentication, a device generally can't tell a legitimate HMI from any other system sending well-formed messages.

  • Changes can look normal. A write command from an unauthorized source can look identical to a routine one.

  • Network position is the main control. If the protocol can't protect itself, the network around it has to.

  • Upgrades take years. Secure versions exist for several protocols, but replacing or upgrading field devices happens on OT timelines, not IT ones.

What defenders can do

You can't add authentication to a 20-year-old controller, but you can surround it with controls that reduce risk:

  1. Segment the network. Put controllers in tightly scoped zones so only the HMIs, servers and programming workstations that need to reach them can do so.

  2. Allow-list communications. Define which systems may talk to which controllers, over which protocols, and block everything else at the zone boundary.

  3. Use protocol-aware firewalls. Industrial firewalls with deep packet inspection can understand Modbus, DNP3 or CIP and allow reads while restricting writes, or permit writes only from specific sources.

  4. Monitor passively. OT network monitoring tools can learn normal protocol behaviour and alert on unexpected writes, firmware downloads, mode changes or new devices.

  5. Turn on the security you already have. Enable OPC UA signing and encryption, and plan for DNP3 Secure Authentication or CIP Security as equipment is upgraded.

  6. Protect the programming workstations. These machines can legitimately change controller logic, so they deserve the strongest access controls on the network.

Key takeaways

  • Modbus (1979, Modicon), DNP3 (early 1990s), EtherNet/IP and PROFINET were built for trusted, isolated networks and mostly lack authentication.

  • Secure options exist, including DNP3 Secure Authentication, CIP Security and OPC UA's built-in security, but adoption is uneven.

  • OPC UA only delivers its security benefits when it's configured properly.

  • Segmentation, allow-listing, protocol-aware firewalls and passive monitoring are the practical defences for legacy protocols.

How QBits Networks can help

Knowing which protocols are actually in use, and who is talking to your controllers, is the foundation for protecting them. An OT visibility snapshot uses passive capture from a SPAN or mirror port to map protocol traffic, and a network segmentation review turns those findings into practical allow-list and firewall improvements. Tell us what you need through our contact page and we'll scope it with you.

bottom of page