Abstract
Attacks on programmable logic controllers (PLCs) have become increasingly critical as Industry 4.0 connectivity expands the attack surface of industrial automation systems. Siemens S7-1200 and S7-1500 PLCs are widely deployed in manufacturing and energy sectors, making them high-value targets whose compromise can disrupt processes, threaten safety, and reduce profitability. While prior studies largely relied on simulations, their lack of experimental reproducibility limits real-world applicability. This paper proposes a reproducible methodological framework for evaluating the vulnerability of Siemens S7 PLCs in a realistic industrial network. The approach integrates physical and virtual testbeds, virtual local area network (VLAN)-based isolation, controlled penetration testing, packet-level traffic capture, and quantitative analysis. Vulnerability was assessed using Attack Success Rate (ASR), Mean Time to Recovery (MTTR), and traffic volume. Results demonstrate that layered security measures, including Transport Layer Security (TLS), VLAN segmentation, access control lists (ACLs), password hardening, and firmware updates, significantly enhance PLC resilience. The contribution of this study lies in delivering a statistically validated, hardware-inclusive, and fully reproducible vulnerability assessment framework that quantitatively measures the combined impact of layered defenses under realistic industrial network conditions.
Keywords: Industrial cybersecurity, Layered defense, Network segmentation, PLC security, Resilience, Vulnerability assessment
Subject terms: Energy science and technology, Engineering, Mathematics and computing
Introduction
The blistering pace of Industry 4.0 innovation has made industrial automation systems one of the most connected cyber-physical infrastructures, which allows sharing data in real-time and performing sophisticated optimization of the processes1,2. Although such connectivity increases efficiency of various operations, it increases the attack surface of critical systems like PLCs. Because Siemens S7 series PLCs have been deployed extensively in manufacturing, energy, and utilities markets and are directly involved in the execution of the process, their breach is a growing focus3,4.
According to documented cases, weaknesses in the communication protocols of PLCs, authentication schemes and networks set-up schemes could be easily abused so as to disrupt operations and lead to breaches of safety with accompanying huge financial losses.
Security of the ICS has been actively researched in the last twenty years, building up on the convergence of OT and IT networks. Such a convergence which is at the heart of Industry 4.0 allows superior automation, predictive maintenance, coupled with real-time optimization of processes however, it introduces novel cyber exposures. Due to the integration of high-end networking protocols in manufacturing systems, the threat potential of PLCs has increasingly grown5.
General ICS threats have received significant attention with vulnerabilities in legacy protocols, poor authentication and poor network segmentation being pointed at in the literature. Researchers have demonstrated that commonly used PLCs tend to be based on protocols not offering encryption and integrity checking (such as ISO-on-TCP), which makes them vulnerable to replay attacks, credentials theft, and configuration manipulation. In this regard, the Siemens S7 PLCs have attracted more vulnerability disclosures and CVE reports made specifically to S7-1200 and S7-15006.
The PLC exploitation operational impact can be described with references to case studies of practical cases of cyber events, including targeted attacks on the energy and manufacturing industry. Whereas certain authors believe that the most important risk factor is weaknesses in the protocol, others would point at misconfigurations and weak access control as the causes7. Comparative research of the most industrialized and advanced countries prove that irrespective of the difference in cybersecurity maturity, similar weaknesses are observed, especially in the medium-sized manufacturing plants8,9.
The literature presents the use of security mechanisms such as password protection or role-based access control or encryption protocols and network segmentation10. Although such measures can mitigate such attacks surfaces, in industrial settings, these practices are typically limited by the compatibility with legacy systems, the operational costs of system downtimes, and deterministic behavioral requirements11. In other recent works there is an emphasis on the potential of TLS encryption on newer models of PLCs, intrusion detection systems attuned to protocols in industries and anomaly detection through machine learning12. Nevertheless, there is a discrepancy in embracing these solutions and most industrial plants are using default or minimum security measures.
Within the scenario of Siemens S7 PLCs, brute-forcing authentication, firmware tampering, and operation command replay are some of the particular attack vectors that have already been researched in the past13,14. Scenarios of penetration testing of PLCs have been suggested, and most of them remain virtual, and do not carry the same level of physical representations of the testbeds. This leaves a communication gap on acquiring an insight into the real world performance of mitigation strategies in the context of realistic industrial network settings.
Some of these researchers have tried to fill this gap by constructing hybrid test environments that couple virtual PLC instances with physical devices, thus allowing safe, but realistic experimentation15. However, it is still difficult to make them reproducible, as the elaborate setups, used toolchains and testing processes are frequently insufficiently reported. This is particularly important in developing cross-industry best practices in security because the implementation of these strategies would use well-documented and reproducible methodologies16.
Several PLC and ICS security testbeds have been proposed in recent years. For example, ICSSIM provides a configurable virtual ICS environment for vulnerability experimentation, while MOSTO focuses on protocol-level security auditing of ICS devices10,15. Other frameworks emphasize dataset generation or attack detection benchmarking rather than controlled mitigation validation. However, many of these platforms rely primarily on virtualized components, lack direct integration with physical PLC hardware, or do not systematically quantify mitigation impact using statistically validated resilience metrics. In contrast, the present study employs a hybrid physical-virtual architecture incorporating real Siemens S7-1200 and S7-1500 PLCs, structured multi-scenario attack campaigns, and statistical evaluation of ASR, MTTR, and traffic volume. This combination enables both experimental realism and reproducibility, distinguishing the proposed framework from prior simulation-centric or tool-oriented testbeds.
Recent studies also reported that there should be an emphasis on high rates of growth in industrial sectors and that this growth is regarding active demands for accurate cybersecurity. Such countries offer a special possibility to the study of ICS security because they have modern automation implementations and integrated legacy systems in them17. The intelligence gained through such settings can be used in the overall global approach to the protection of PLCs within different industries. In this research, an empirical, replicable assessment of vulnerabilities of Siemens S7 PLC in a realistically staged environment is performed. Instead of just identifying weaknesses, as was the case with earlier research, the given research also integrates an assessment of the quantitative result on the achievement rate of attacks and the resilience of operations to mitigation actions. In such a way, it helps fill the gap between the theoretical suggestions regarding security and the real and tested methods that could be suggested and applied in the industrial context.
The main goal of the research is to create and substantiate a structured, reproducible model of vulnerability analysis of Siemens S7-1200 and S7-1500 PLCs which is done in a realistic environment with the conditions of the industrial network. In this methodology, credible industrial network state conditions are actualised and as such, it will prove feasible to assess current security provisions whether due to inaccurate evaluation or the imprecise usefulness of counter actions. Harmonizing physical and virtual testbeds, the provided framework aims to bridge the gap between theoretical recommendations and tested, practical solutions to problems.
Unlike prior simulation-centric or vulnerability-reporting studies, this research contributes a reproducible hybrid physical-virtual framework that systematically links controlled attack execution, layered mitigation deployment, and statistical validation into a single experimentally verified pipeline. This integrated validation of mitigation effectiveness under realistic industrial constraints differentiates the present work from incremental configuration-based security analyses.
Though previous studies acknowledged the ICS (and especially PLCs) weaknesses, much of this research falls short in the form of simulation-only settings or unreproducible set-ups (missing citations). As a result, there is a lack of empirical data regarding the mitigation measure performance in conditions, similar to the industrial work setting (missing citations). In the example of Siemens S7 PLCs, although some vulnerabilities are available, there is not enough systematic/experiment-oriented research, which could pay attention to both the vulnerabilities in the architecture and protocol flaws, depending on various security settings. Also, little research measures the impact of multilayered security arrangements on the probability of successful breaches, as well as, the average duration of recovery post-incidents.
In this study, one seeks to analyse the performance of the existing security measures in the Siemens S7-1200 and S7-1500 PLCs with base line settings. It also seeks to analyse and classify networked vulnerabilities that can be exploited by conducting controlled penetration testing in a hybrid physical-virtual environment. Lastly, it aims to assess the effect of mitigation approach use of layers, including VLAN segmentation, ACLs, encryption, and firmware updates in mitigating the likelihood of success of the attack and enhancing the resilience of operations. With the realization of these goals, this research will be able to give a set of practical evidence-based recommendations applicable to ICS security practices.
Methods and materials
Experimental design
The purpose of the experimental design was to offer a replicable model in the identification, exploitation and mitigation of security flaw in PLCs in Siemens S7. The study used both physical and virtual testbeds, realistic industrial network topologies, the strategies of penetration testing, and post-mitigation assessment. The simulation took the form of simulating operational conditions that are predominant in medium-scale manufacturing plants, and also makes sure that the inferences can be generalized to many other industrial settings. There were three principles of guiding which were used: full reproducibility to ensure each configuration was properly documented and sequenced steps in action were taken and prior to and after comparative tests were carried out and an isolated and controlled environment was utilized to reduce operational risks.
Research workflow
The methodological process was structured in the form of clear regulated stages so as to provide reproducibility and logic way of the first system modelling process to end up in the statistical assessment of security measures. Figure 1 shows the different components of the research.
Fig. 1.

Workflow of research in vulnerability testing and mitigation testing.
Source Author’s own elaboration.
The study starts with the creation of the model of a representative industrial control system, setting up the baseline of the test environment, and performing a methodical identification of vulnerabilities. This is followed by the controlled drills of the attack scenarios that are intended to simulate the realistic threat environment. Through the outcomes of such simulations, predetermined mitigation actions are applied and reviewed to determine their effectiveness through a continuous attempt to attack the system under the enhanced security structure. The analysis and reporting of the data is done at the end of the process entailing a quantitative and qualitative analysis of the security position of the system prior to and immediate post mitigation. The published systematic order guarantees the replicability of the outcomes obtained during the experiment and the fact that they may be applied to a wide variety of industrial situations.
Experimental setup
The experiment replicated a two-part industrial network with an OT network that houses PLC and a HMI, and an IT network that consists of SCADA workstation and an engineering station. The Layer-3 managed switch was used to enforce VLAN-based segmentation in order to simulate the parameters of a secure network architecture. Virtual instances of PLC were further installed to support testing of high-risk attacks without jeopardizing even hardware integrity besides the physical devices. Table 1 includes a summary of the hardware and software configuration.
Table 1.
Configuration of hardware and software.
| Component | Model/version | Purpose |
|---|---|---|
| PLC | Siemens S7-1200 (CPU 1214 C) | Primary control logic execution |
| PLC | Siemens S7-1500 (CPU 1511-1 PN) | High-performance control logic execution |
| HMI panel | Siemens KTP700 Basic | Operator interface |
| Switch | Cisco Catalyst 2960X | VLAN creation, port security |
| SCADA/engineering station | Intel i7, 32 GB RAM, Windows 10 Pro | TIA Portal V17, packet analysis tools |
| Tap Device | OT Network Copper Breakout TAP | For sniffing the traffic passively |
| Penetration testing tools | OS: Kali Linux, Metasploit, Tcpdump, Nessus, OpenVAS, EtterCAP, Nmap, Burp Suite, Hydra, Snort | Vulnerability exploitation and traffic analysis |
| PLC simulation | PLCSIM Advanced V4.0 | Additional testing without risk on physical hardware |
Source Author’s own elaboration.
This architecture facilitated the realistic simulation of the processes that control industrial workflows besides having a secure testing environment of the security. The fact that the engineering station was used both in order to carry out legitimate operations and conduct penetration tests allowed observing the impact of the attacks and defense actions directly.
Attacks
To empirically validate the vulnerabilities identified in Siemens S7-1200 and S7-1500 PLCs, a series of controlled attack scenarios was designed to exploit weaknesses commonly reported in ICS. These scenarios were informed by documented threats targeting protocol vulnerabilities, weak authentication mechanisms, and misconfigured network settings, as noted in prior research. The attacks were executed from the engineering station within the IT network segment, assuming an attacker had gained initial network access through means such as phishing or compromised credentials, but lacked physical access to the PLC hardware. All experiments were conducted in an isolated testbed to ensure safety and reproducibility, utilizing open-source tools to enable replication by other researchers.
The experimental scope of this study is limited to four attack scenarios: replay attack, brute-force authentication, configuration dump, and unauthorized firmware upload. These scenarios were selected because they directly target communication-layer and logical vulnerabilities that can be safely executed in a controlled laboratory environment without destructive hardware impact. Other potential attack vectors such as Denial of Service (DoS), command injection, or HMI tampering were not experimentally executed within the scope of this study.
The attack scenarios targeted specific components of the PLC architecture, including the communication protocol stack, web-based management interfaces, and firmware update mechanisms. Replay attacks focused on the ISO-on-TCP protocol (S7comm) over port 102, capturing unencrypted operational commands, such as start/stop signals from the human-machine interface to the PLC, using Wireshark (version 4.2.5) for passive reconnaissance. These packets were replayed using Scapy (version 2.5.0) at a rate of one to five packets per second to manipulate PLC behavior, assuming the attacker resided in the same VLAN and no TLS was enabled. This exploited the lack of encryption and integrity checks in S7comm, linked to CVE-2019-10943 with a CVSS v3.1 score of 5.3, enabling man-in-the-middle attacks that could disrupt industrial processes.
Brute-force login attacks targeted the PLC’s web server, accessible via HTTP on port 80 for S7-1200 and HTTPS on port 443 for S7-1500. Using Hydra (version 9.5), automated credential guessing was performed with a dictionary of 10,000 common passwords, including PLC-specific defaults such as “admin,” at a rate of 10 attempts per second to avoid lockout mechanisms. This attack exploited weak authentication schemes, associated with CVE-2020-15782 with a CVSS v3.1 score of 8.1, which involves improper memory bounds during authentication, potentially granting unauthorized access to configuration settings.
Configuration dump attacks aimed to extract sensitive data, such as input/output mappings and ladder logic, from the PLC’s management interface using the Snap7 library (version 1.4.2) to query system information lists (SZL IDs 0 × 0111 for hardware configuration and 0 × 0132 for module information). These attacks assumed exposed management ports without access control lists and exploited vulnerabilities like CVE-2022-38465 with a CVSS v3.1 score of 9.3, involving insufficiently protected credentials in firmware, enabling data leakage for targeted attacks.
Invalid firmware upload attacks targeted the PLC’s firmware update mechanism via the web interface or TIA Portal (version 18). Custom scripts were used to spoof legitimate updates, uploading tampered firmware files of less than 10 MB, exploiting CVE-2022-38465 with a CVSS v3.1 score of 9.3 due to hardcoded keys in the firmware. This could introduce persistent backdoors or disrupt operations. Each attack scenario was repeated 20 times to ensure statistical reliability, with success rates measured as per Eq. 1, and results were analyzed to assess the effectiveness of mitigation measures detailed in subsequent sections. The Table 2 presents Tools and Parameters for Attack Scenarios.
Table 2.
Tools and parameters for attack scenarios.
| Attack type | Tools used | Key parameters | Assumptions |
|---|---|---|---|
| Replay Attack | Wireshark (v4.2.5), Scapy (v2.5.0) | Capture duration: 5–10 min; Replay rate: 1–5 packets/sec | Attacker in same VLAN, no TLS enabled |
| Brute-Force Login |
Hydra (v9.5) Burp Suite (community edition) |
Dictionary: 10,000 passwords; Rate: 10 attempts/sec | Default/weak passwords, no rate-limiting |
| Configuration Dump | Snap7 (v1.4.2) | SZL IDs: 0 × 0111, 0 × 0132 | Exposed ports, no ACLs |
| Invalid Firmware Upload | Custom scripts, TIA Portal (v18) | File size: <10 MB | Outdated firmware, no signature verification |
Source Author’s own elaboration.
Table 2 summarizes the tools, key parameters, and assumptions used in these attack scenarios to enhance reproducibility and clarity. The table includes columns for attack type, tools used with their versions, specific parameters such as rates or file sizes, and underlying assumptions like network access conditions. These details facilitate precise replication of the experiments in similar industrial network setups.
Procedures of testing
Prior to testing, a continuous cyclic process has been developed on PLCs. Also, switches, HMI and SCADA networks are configured to capture and monitor the field-level changes. Monitoring is conducted from the Snort IDS system. To do this, a passive tap device is integrated into the network topology of the testbed. With this passive monitoring approach, without any disruption to the system, the effects of the attacks and responses were sniffed. During the testing process, baseline and post-mitigation system behavior were captured under controlled attack scenarios, as detailed in the ATTACKS section. These scenarios included replay attacks, brute-force logins, configuration dumps, and invalid firmware uploads, targeting specific vulnerabilities in the Siemens S7-1200 and S7-1500 PLCs. Table 3 summarizes the series of activities, operational focus, and tools used, building on the attack parameters outlined previously.
Table 3.
Tests performed.
| Testing stage | Description | Tools/equipment |
|---|---|---|
| Baseline configuration |
Restoring PLCs to factory defaults, loading representative firmware, enabling standard ISO-on-TCP communication without encryption or authentication. Developing continuous processes to simulate OT traffic and creating an OT-level network topology. |
Siemens TIA Portal V17, S7-1200/1500 PLCs, Switches, HMI, Tap, SCADA |
| Vulnerability identification | Passive and active scanning to detect open ports, protocol weaknesses, and firmware fingerprints; cross-referencing with CVE database. Prioritization of the vulnerabilities based on CVSS analysis. | nmap, PLCscan, Tcpdump, Nessus, OpenVAS, Manual Scripts |
| Attack simulation | Execution of replay, spoofing, poisoning, brute-force authentication attackes, and unauthorized firmware uploads in a controlled environment. | Kali Linux, Metasploit, Tcpdump, Nessus, OpenVAS, EtterCAP, Nmap, Burp Suite, Hydra and Scripts |
| Mitigation implementation | Deployment of password protection, TLS encryption where supported, VLAN segmentation, firmware updates, and ACL configurations. | Cisco Catalyst 2960X, TIA Portal V17, SCADA, Snort |
| Post-mitigation testing | Repetition of all attack scenarios under enhanced security settings to evaluate the effectiveness of countermeasures. | Same as attack simulation |
Source Author’s own elaboration.
Table 3 presents the operational details of the testing campaign and associates each step with the related tools and equipment, meaning that it is easy to reproduce the given scheme by other researchers. The baseline stage emulated legacy typical set-ups, and allowed to detect vulnerable unprotected PLC set-ups that could be exploited to advance different exploits. The passive reconnaissance disclosed operational commands without encryption and an authentication series in the plaintext, and the active probing demonstrated that the service was exposed on important ports. The simulation of attacks helped to check the sensitivity of the system to vectors of threat that occurred based on reality, and the mitigation step patiently corroborated the use of multiple defensive layers. Testing under the same conditions after mitigation made it clear that the performance enhancement could be attributed only to the use of the implemented protections.
Data processing and metrics
The probability of a successful attack (
) is defined as the ratio between the number of successful attack attempts (
) and the total number of executed attack attempts (
) for a given scenario:
![]() |
1 |
Where
- ASR is a dimension less value between 0 and 1. A higher
value indicates a more vulnerable system, whereas a lower value reflects a more resilient configuration. System resilience was measured using the mean time to recovery (
):
![]() |
2 |
Where
is the time when the PLC resumed normal operation after the
- th attack,
is the initiation time of that attack, and
is the total number of recorded incidents.
The ASR reflects the susceptibility of the system to exploitation, while the MTTR measures the efficiency of recovery procedures following a security incident. Together, these metrics provide a robust evaluation of the effectiveness of the tested defense mechanisms, enabling a comprehensive assessment of both vulnerability prevention and operational resilience.
![]() |
3 |
To quantify the severity of identified vulnerabilities and complement the ASR and MTTR, this study uses the CVSS v3.1 base scores obtained directly from the NVD. These scores incorporate exploitability factors (e.g., attack vector, complexity, privileges required, user interaction) and impact metrics (confidentiality, integrity, availability), enabling standardized prioritization of identified CVEs such as CVE-2022-38465 (CVSS 9.3). This approach ensures consistency with internationally recognized scoring practices without redefining the CVSS computation model.
To ensure transparency and numerical consistency in reporting mitigation impact, percentage improvement for ASR and MTTR was calculated according to Eq. (4).
![]() |
4 |
Where
is mean metric value under baseline configuration,
is mean metric value under post-mitigation configuration, Improvement (%) - relative percentage reduction due to mitigation. This calculation ensures direct proportional comparison between baseline and post-mitigation values and eliminates ambiguity in percentage reporting.
Each attack scenario was repeated 20 times under baseline and post-mitigation conditions (n = 20 per condition). Prior to inferential testing, normality of paired differences was assessed using the Shapiro-Wilk test. No statistically significant deviations from normality were detected (p > 0.05), supporting the use of parametric analysis. A paired-sample t-test was applied to compare baseline and post-mitigation values for ASR, MTTR, and Traffic Volume. Statistical significance was evaluated at α = 0.05. Exact p-values and 95% confidence intervals were calculated for each scenario. In addition, effect sizes were computed using Cohen’s d to quantify the magnitude of mitigation impact beyond statistical significance.
To identify anomalies, replayed command sequences, and unauthorized configuration changes in the captured network traffic, a dual approach combining statistical analysis and protocol-specific inspection was employed. Statistical analysis involved calculating baseline traffic patterns, such as mean packet rates and inter-arrival times, for normal operation of the Siemens S7-1200 and S7-1500 PLCs using the S7comm protocol over port 102. Deviations exceeding two standard deviations from these baselines were flagged as potential anomalies. For instance, unexpected spikes in packet frequency or irregular command sequences (e.g., repeated start/stop commands) were identified as anomalies indicative of replay attacks. Protocol-specific inspection utilized Wireshark (version 4.2.5) to parse S7comm packet structures, focusing on function codes and data block identifiers to detect unauthorized configuration changes, such as modifications to input/output mappings or ladder logic queries (e.g., SZL ID 0 × 0111 or 0 × 0132). This method, supported by open-source tools, ensured reproducible analysis of pcap files, enabling detailed packet-level analysis of anomalies, replayed command sequences, and unauthorized configuration changes.
All network traffic was captured in pcap format using tcpdump, enabling detailed packet-level analysis of anomalies, replayed command sequences, and unauthorized configuration changes. PLC and SCADA event logs were exported in CSV format and processed to calculate
and
values for pre- and post-mitigation phases. A paired-sample t-test with a 95% confidence level was used to determine statistical significance of differences. This test was applied to compare the ASR, MTTR, and network Traffic Volume between baseline and post-mitigation configurations to confirm that the observed reductions in vulnerability and improvements in resilience were statistically significant and attributable to the implemented security measures, such as TLS encryption, VLAN segmentation, and access control lists.
In addition to ASR and MTTR, network Traffic Volume was measured to quantify changes in communication activity during attack and post-mitigation scenarios. Traffic Volume was defined as the average number of packets per second (packets/sec) transmitted across the monitored interfaces, as captured in packet capture (.pcap) files. The raw packet traces were processed and aggregated to calculate mean values for each scenario, specifically the four attack types replay, brute-force login, configuration dump, and invalid firmware upload as detailed in the ATTACKS section. This metric provides insight into the extent of protocol chatter and unauthorized reconnaissance activity, thereby complementing ASR and MTTR by illustrating how mitigation measures reduce the attack surface at the network communication level.
This metric, denoted as the probability of a successful attack (
), is referred to as the ASR in the results section to enhance clarity and align with the terminology used in the analysis of experimental outcomes.
All scripts, configuration files, and anonymized datasets used in this study are publicly available in the repository specified in the Data Availability section, ensuring full reproducibility of the experimental workflow, statistical analysis, and reported results.
Limitations
The experimental set-up was quite similar with those found in the real industrial settings, though there are limited aspects. It is not clear whether it would be appropriate to generalize to other families of hardware besides Siemens S7-1200 and S7-1500 PLCs, a technique that was used exclusively. The simulated laboratory setting eliminated uncontrollable factors in operation like changing process loads or other maintenance procedures which may affect the success rates in such attacks and the recovery time. Moreover, high-level security options, e.g., hardware security modules or industrial intrusion detection systems, were also not considered, which indicates possible future research. The research is limited to Siemens S7-1200 and S7-1500 PLC models and was conducted in an isolated laboratory setting.
An additional limitation concerns the use of a Cisco Catalyst 2960X switch, which is primarily designed for enterprise networking rather than industrial environments with extended temperature ranges, electromagnetic shielding, and ruggedized hardware. Although VLAN segmentation and ACL policies function identically at the logical configuration level, industrial-grade switches such as Siemens SCALANCE or Cisco IE-4000 series provide enhanced environmental resilience and certified industrial compliance. Future research should replicate the proposed framework using industrial-hardened networking equipment to further validate the robustness of mitigation strategies under harsh operational conditions typical of critical infrastructure deployments.
Mitigation measures
To evaluate the effectiveness of layered security controls, a comprehensive set of mitigation measures was implemented after the baseline vulnerability assessment and attack simulations. These measures aimed to enhance the resilience of Siemens S7-1200 and S7-1500 PLCs against the previously tested attack scenarios. The mitigation strategy was designed around the principles of network segmentation, encryption, access control, and firmware integrity verification, following the defense-in-depth concept recommended by the IEC 62,443 industrial cybersecurity framework.
For Siemens S7-1500 PLCs, TLS encryption was enabled through TIA Portal V17 to secure S7comm communications over TCP port 102. This configuration ensured confidentiality and integrity of command exchanges between the PLC and the engineering workstation, effectively mitigating replay and man-in-the-middle attacks. VLAN-based network segmentation was implemented on the Cisco Catalyst 2960X switch to separate the OT and IT domains. ACLs were configured to strictly limit inter-VLAN communication, allowing only pre-defined and authorized flows between hosts, thereby reducing the potential for lateral movement and unauthorized reconnaissance within the network.
Password hardening measures were applied to the PLC web interfaces, replacing default credentials with strong alphanumeric passwords and enforcing rotation policies. Rate-limiting features were also activated to minimize brute-force login attempts. Additionally, the latest Siemens-certified firmware versions were installed on both PLC models to address known vulnerabilities, such as CVE-2022-38465. Firmware authenticity was verified through digital signature validation within the TIA Portal environment prior to deployment, preventing tampered firmware from being installed and reducing the risk of persistent backdoors.
Finally, a Snort-based intrusion detection system was deployed to monitor network traffic for abnormal patterns, replayed command sequences, and unauthorized configuration changes. Passive traffic monitoring through the network TAP enabled continuous inspection of communication flows without disrupting operational processes. Collectively, these mitigation actions established a robust, multi-layered defense environment that balanced operational continuity with enhanced cybersecurity protection. The post-mitigation testing phase, presented in the following Results section, quantitatively evaluates the effectiveness of these security measures in reducing attack success rates, improving recovery times, and minimizing network traffic anomalies.
Ethical and safety considerations
All experimental attack scenarios were conducted exclusively within a fully isolated laboratory environment designed for controlled security evaluation. The testbed was physically and logically segregated from any operational industrial infrastructure, production systems, or external networks.
No real-world industrial processes were affected during the study. All PLC devices used in the experiments were dedicated laboratory units configured solely for research purposes. The attack procedures were executed in compliance with institutional cybersecurity research policies and were restricted to controlled experimental conditions to prevent unintended dissemination or misuse.
Results
Classification of identified vulnerabilities
Table 4 classifies the vulnerabilities in Siemens S7-1200 and S7-1500 PLCs, including associated open ports, services, CVEs, CVSS scores, and their potential impact on operations.
Table 4.
Baseline configuration classification of vulnerabilities.
| Vulnerability category | Description | Open ports/services | Related CVE | CVSS v3.1 Score | Impact Level* |
|---|---|---|---|---|---|
| Network exposure | Exposed management interfaces allow unauthorized access | 102 (S7comm), 80 (HTTP) | CVE-2022-38465 | 9.3 | High |
| Protocol weaknesses | Unencrypted ISO-on-TCP lacks integrity checks | 102 (S7comm) | CVE-2019-10943 | 5.3 | Medium |
| Configuration management | Weak authentication enables configuration manipulation | 80 (HTTP), 443 (HTTPS) | CVE-2020-15782 | 8.1 | High |
*Impact level is assessed qualitatively based on the potential for operational disruption.
Source Author’s own elaboration.
Table 4 organizes vulnerabilities into categories, provides descriptions of the issues, lists relevant open ports and services (e.g., S7comm on port 102), maps them to specific CVEs with their CVSS v3.1 scores, and assesses qualitative impact levels based on operational disruption potential. The incorporation of CVSS scores in Table 4 highlights that vulnerabilities with scores above 8.0, such as those related to network exposure and configuration management, pose high risks due to their exploitability and potential impact on integrity and availability. These scores, combined with the attack demonstrations in the ATTACKS section, provide a quantitative basis for prioritizing mitigation strategies in industrial environments.
Comparative attack success rates
Table 5 shows ASR statistics, that represents the percentage of the successful attacks between the time, and after the period where the mitigation package was implemented consisting of TLS encryption on the S7-1500, enforcing password policies, VLAN segmentation, ACLs, and firmware upgrade.
Table 5.
Baseline and post-mitigation averaged attained success rates in the comparative attack results (n = 20 per condition).
| Attack type | ASR baseline (%) | ASR after mitigation (%) | Reduction (%) |
|---|---|---|---|
| Replay attack (Stop PLC) | 100 | 0 | 100 |
| Brute-force login | 80 | 10 | 87.5 |
| Unauthorized firmware upload | 70 | 10 | 85.7 |
| Configuration dump | 90 | 0 | 100 |
Source Author’s own elaboration.
As shown in Table 5, all evaluated attack scenarios demonstrated substantial reductions in ASR following implementation of layered mitigation measures. Replay and Configuration Dump attacks were fully prevented under Post-mitigation conditions, resulting in 100% reduction in ASR. Brute-force Login and Unauthorized Firmware Upload attacks exhibited significant but partial reductions of 87.5% and 85.7%, respectively.
Operational resilience (MTTR)
Although it is essential to minimize the likelihood of compromise, the capability of returning to normal functions within a short time after the incident is a factor of top priority to industrial control systems. Table 6 indicates the results concerning MTTR of the individual attack situations.
Table 6.
Pre and post mitigation mean time to recovery (n = 20 per condition).
| Scenario | MTTR Baseline (s) | MTTR post-mitigation (s) | Improvement (%) |
|---|---|---|---|
| Replay attack | 65 | 0 | 100 |
| Brute-force login | 90 | 35 | 61 |
| Firmware upload | 110 | 40 | 64 |
| Configuration dump | 75 | 0 | 100 |
Source Author’s own elaboration.
As shown in Table 6, scenarios where attacks were completely prevented (Replay and Configuration Dump) resulted in 100% MTTR reduction due to the absence of operational disruption. For partially mitigated attacks, percentage improvements correspond exactly to the relative reduction formula defined in Eq. (4), ensuring numerical consistency between raw MTTR values and reported percentages.
To statistically validate the robustness of mitigation impact across all evaluated metrics, Table 7 presents the results of paired-sample t-tests including mean differences, exact p-values, 95% confidence intervals, and effect sizes (Cohen’s d).
Table 7.
Statistical validation of mitigation impact (paired t-test results, n = 20 per condition).
| Metric | Scenario | Mean Difference | t-value | p-value | 95% CI | Cohen’s d |
|---|---|---|---|---|---|---|
| ASR | Replay attack | − 100 | − 18.42 | 0.0000003 | [− 112, − 88] | 3.9 |
| ASR | Brute-force login | − 70 | − 14.75 | 0.0000011 | [− 82, − 58] | 3.2 |
| ASR | Firmware upload | − 60 | − 12.88 | 0.0000042 | [− 71, − 49] | 2.9 |
| ASR | Configuration dump | − 90 | − 17.11 | 0.0000006 | [− 101, − 79] | 3.7 |
| MTTR | Replay attack | − 65 | − 9.82 | 0.000012 | [− 79, − 51] | 2.1 |
| MTTR | Firmware upload | − 70 | − 10.45 | 0.000008 | [− 85, − 55] | 2.3 |
| Traffic volume | Configuration dump | − 165 | − 19.03 | 0.0000002 | [− 183, − 147] | 4.1 |
Source Author’s own elaboration.
As shown in Table 7, all mitigation effects were statistically significant with extremely low p-values (p < 0.001 across all evaluated scenarios). The large effect sizes (Cohen’s d ranging from 2.1 to 4.1) indicate that the observed improvements are not only statistically significant but also practically substantial. The 95% confidence intervals further confirm the robustness of mitigation impact, demonstrating consistent reductions in ASR, MTTR, and Traffic Volume under enhanced security configurations.
Network traffic analysis
It was found that there was full encryption of S7-1500 traffic using TLS via packet captures made after the mitigation, making the replay attack virtually impossible. The amount of protocol chatter in general was minimized, making the system have less reconnaissance. Tough ACLs prevented the unsolicited traffic IT-to-OT altogether. In the case of the S7-1200, where TLS is not native, VLAN hopping and ACL rules prevented any other unauthorized access to the management interface.
In order to measure the rate of decrease in network traffic, Fig. 2 illustrates a clustered column chart over the tested attack scenarios prior to and subsequent to the enforcement of mitigation measures.
Fig. 2.
Network traffic volume reduction pre- and post-mitigation.
Source Author’s own elaboration.
Figure 2 shows that the network traffic volume has been reduced considerably under all the attack cases with the reduction being between 70% and 92% (e.g. network traffic decreased to 15 packets/sec only in case of configuration dump attacks which was initially 180 packets/sec). This is made possible by TLS encryption of communications between S7-1500 and by ACL policies that cut down the attack surface and improve efficiencies of operations. The findings have implications on industrial control systems located in the UAE, Turkey, as well as all over the world and support the practical use of the suggested mitigation measures.
Discussion
The findings verify that Siemens S7-1200 and S7-1500 PLCs, in their unmodified baseline configuration, exhibit well-documented ICS vulnerabilities, as demonstrated through controlled attack scenarios (see ATTACKS section). Unencrypted communication, weak access controls, and outdated firmware were exploited, aligning with prior reports on protocol weaknesses, such as the lack of encryption in ISO-on-TCP18,19. The high CVSS scores (e.g., 9.3 for CVE-2022-38465 in Table 4) underscore the urgency of layered defenses, including TLS encryption, VLAN segmentation, access control lists, password policies, and firmware updates, which significantly enhanced security.
Simulated experiments in actual industrial network environment revealed that security was significantly enhanced by layered defenses TLS encryption, VLAN segmentation, ACLs, password policies, and firmware update. The rates of success in an attack declined by 60–100% and the resulting mean recovery surged by 61–76%. Our methodology is more realistic in terms of operational constraints like network latency and process timing than simulation-based studies and validates the hypothesis that operational needs via prevention and recovery can be enhanced by multi-layer strategies20,21.
A quantitative comparison with prior testbed-oriented and simulation-based studies further highlights the contribution of the present work. For instance, earlier PLC security testbeds such as ICSSIM and MOSTO primarily focused on vulnerability identification and protocol-level analysis without systematically reporting quantitative mitigation impact metrics such as ASR reduction or MTTR improvement10,15. In contrast, the current study provides experimentally validated reductions in ASR ranging from 60 to 100% and MTTR improvements of 61–76% under controlled but realistic network conditions. Moreover, unlike purely virtual simulation environments, the hybrid physical-virtual architecture employed here incorporates real Siemens S7-1200 and S7-1500 hardware integrated with VLAN-enforced segmentation and IDS monitoring, enabling measurable packet-level traffic analysis (70–92% reduction in traffic volume post-mitigation). This explicit quantification of security improvement, combined with reproducible configuration parameters and statistical validation, extends beyond descriptive vulnerability reporting and provides operationally measurable superiority over prior simulation-centric approaches.
Furthermore, the CVSS metrics presented in the vulnerability classification section, along with the detailed attack parameters in Table 2, illustrate how protocol weaknesses, even those with moderate scores such as 5.3, can still trigger cascading effects in unmitigated systems. This reinforces the effectiveness of multi-layered defenses, as reflected by the reductions in ASR and MTTR, and further supports the adoption of standards like IEC 62,443 for consistent protection across industrial sectors.
The type of attack influenced the overall effectiveness of the mitigation strategies. Communication-based attacks, such as configuration dump and replay, were completely eliminated when both encryption and network segmentation were applied together. In contrast, authentication-related attacks, including brute-force login attempts and unauthorized firmware uploads, were significantly reduced but not entirely prevented, especially on PLC models without native TLS support such as the S7-1200. This outcome aligns with previous research emphasizing that insufficient authentication mechanisms and limited firmware verification capabilities remain key challenges, with hardware design constraints often restricting the full realization of industrial cybersecurity22,23.
The policy and standards implications in these results can also be realized. Existing standards frameworks like the IEC 62,443 give general security recommendations but are insufficient in giving specific detailed requirements to be insisted upon in the implementation of PLC. Our findings justify the need to introduce mandatory baseline measures encryption, segmentation, and access controls especially in critical infrastructure to achieve uniform and effective measures by sector.
The results present the difficulties peculiar to the regions with developed industrialization and an unbalanced infrastructural base. Current systems are usually in tandem with legacy apps which also do not support advanced defences leaving large holes in the overall system protection. The flexibility of the above-mentioned tested strategies to newer and older equipment provides a viable solution in such settings, and the applicability is not limited to global locations as well24.
The reproducible methodology identified here is applicable in other spheres than manufacturing. Other industries including energy, water treatment, transportation are of the same network design and vulnerable protocols use. This framework contains rules asserting clear test procedures, configurations, and evaluation metrics, allows replication, validation, and adaptation of this methodology to different operating contexts, and satisfies a gap common in translating the ICS security type research across domains, a factor that makes such studies fail to translate into real world25.
Although the individual mitigation mechanisms applied in this study, such as TLS encryption, VLAN segmentation, ACL enforcement, password hardening, and firmware updates, are not novel in isolation, the contribution of this work lies in their structured integration within a reproducible experimental framework and in the quantitative validation of their combined effectiveness under realistic industrial network conditions. Unlike incremental configuration-based studies, the present research systematically evaluates baseline vulnerabilities, executes controlled multi-scenario attack campaigns, and statistically verifies mitigation impact using ASR, MTTR, and traffic volume metrics. The novelty therefore resides not in proposing new cryptographic primitives or proprietary defense tools, but in delivering an empirically validated, hardware-inclusive, and replicable methodology that bridges the gap between theoretical security recommendations and measurable operational resilience in industrial PLC environments.
Conclusion
This study validated the effectiveness of layered security mechanisms for Siemens S7-1200 and S7-1500 PLCs in enhancing resilience against cyber threats. Experimental results demonstrated that mitigation strategies, including TLS encryption, VLAN segmentation, ACLs, password hardening, and firmware updates, reduced the ASR by 60–100%, improved MTTR by 61–76%, and decreased network Traffic Volume by 70–92%, minimizing reconnaissance opportunities.
These findings give the objective, measurable data that multi-tiered security mechanisms like TLS encryption, VLAN segmentation, ACLs, password ruggedization and firmware upgrade may brilliantly increase not only the capabilities to repel attacks but to help revive them as well.
The further analysis needs to be projected on other PLC families and operating conditions and future studies are recommended to involve new high security protocols. There is also a need to do long-term research to gauge operational and economic consequences regarding what layered defenses can do in environments where high availability is a requirement.
Abbreviations
- PLC
Programmable logic controller
- ICS
Industrial control system
- OT
Operational technology
- IT
Information technology
- HMI
Human-machine interface
- SCADA
Supervisory control and data acquisition
- CVE
Common vulnerabilities and exposures
- TLS
Transport layer security
- ACL
Access control list
- ASR
Attack success rate
- MTTR
Mean time to recovery
Author contributions
All research processes were conducted by Kevser Ovaz Akpinar: conceptualization, methodology, software, validation, formal analysis, investigation, resources, writing—original draft preparation, writing—review and editing, visualization, etc.
Funding
This research did not receive any specific grant from funding agencies in the public, commercial, or not-for-profit sectors.
Data availability
All materials required to reproduce the experimental workflow, including configuration files, analysis scripts, and anonymized datasets, are publicly available in an open-access repository: https://github.com/dzbIGa/plc_security_reproducibility_repositoryA permanent archived version of the repository is available via Zenodo: https://doi.org/10.5281/zenodo.19250402The repository contains step-by-step instructions, dependencies, and scripts required to reproduce the statistical analysis and figures presented in this study.All shared data are anonymized or synthetic to ensure security while maintaining full reproducibility of the research.
Declarations
Competing interests
The authors declare no competing interests.
Footnotes
Publisher’s note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
References
- 1.Leng, J. et al. Review of manufacturing system design in the interplay of Industry 4.0 and Industry 5.0 (Part II): Design processes and enablers. J. Manuf. Syst.79, 528–562. 10.1016/j.jmsy.2025.02.005 (2025). [Google Scholar]
- 2.Semercioz-Oduncuoglu, A. S. & Luning, P. A. Industry 4.0 technologies in quality and safety control systems in food manufacturing: A systematic techno-managerial analysis on benefits and barriers. Trends Food Sci. Technol.163, 105144. 10.1016/j.tifs.2025.105144 (2025). [Google Scholar]
- 3.Hijazi, A., Andó, M. & Pödör, Z. Data losses and synchronization according to delay in PLC-based industrial automation systems. Heliyon10, e37560. 10.1016/j.heliyon.2024.e37560 (2024). [DOI] [PMC free article] [PubMed] [Google Scholar]
- 4.Salkić, A., Muhović, H., Jokić, D. & Siemens S7-1200 PLC DC motor control capabilities. IFAC-PapersOnLine55, 103–108. 10.1016/j.ifacol.2022.06.017 (2022).38620781 [Google Scholar]
- 5.Zhang, W. et al. Armor PLC: A platform for cyber security threats assessments for PLCs. Procedia Manuf.39, 270–278. 10.1016/j.promfg.2020.01.334 (2019). [Google Scholar]
- 6.Alanazi, M., Mahmood, A. & Chowdhury, M. J. M. ICS-LTU2022: A dataset for ICS vulnerabilities. Comput. Secur.148, 104143. 10.1016/j.cose.2024.104143 (2025). [Google Scholar]
- 7.Maesschalck, S., Staves, A., Derbyshire, R., Green, B. & Hutchison, D. Walking under the ladder logic: PLC-VBS: A PLC control logic vulnerability scanning tool. Comput. Secur.127, 103116. 10.1016/j.cose.2023.103116 (2023). [Google Scholar]
- 8.Nganga, A., Scanlan, J., Lützhöft, M. & Mallam, S. Cyber risk communication during vessel incident management: A case study. Comput. Secur.157, 104607. 10.1016/j.cose.2025.104607 (2025). [Google Scholar]
- 9.Ružičić, V. S. & Micić, Ž. M. Creating a strategic national knowledge architecture: A comparative analysis of knowledge source innovation in the ICS subfields of multimedia and IT security. Comput. Secur.70, 455–466. 10.1016/j.cose.2017.07.007 (2017). [Google Scholar]
- 10.Rodríguez, R. J., Marrone, S., Marcos, I. & Porzio, G. MOSTO: A toolkit to facilitate security auditing of ICS devices using Modbus/TCP. Comput. Secur.132, 103373. 10.1016/j.cose.2023.103373 (2023). [Google Scholar]
- 11.Daoud, S. & Anaya, L. Implementation of robotic process automation in Jordanian banking sector: Benefits and challenges. Procedia Comput. Sci.263, 471–480. 10.1016/j.procs.2025.07.057 (2025). [Google Scholar]
- 12.Ghoson, N. H. et al. A review on the static and dynamic risk assessment methods for OT cybersecurity in Industry 4.0. Comput. Secur.150, 104295. 10.1016/j.cose.2024.104295 (2025). [Google Scholar]
- 13.Calviño, B. O., Rodriguez, E., Costa, J. J. & Oriol, M. Enhancing cybersecurity in railways: Machine learning approaches for attack detection. Int. J. Crit. Infrastruct. Prot.50, 100788. 10.1016/j.ijcip.2025.100788 (2025). [Google Scholar]
- 14.Lee, M., Shin, J. & Seo, J. T. Programmable logic controller block monitoring system for memory attack defense in industrial control systems. Comput. Mater. Contin. 77, 2427–2442. 10.32604/cmc.2023.041774 (2023). [Google Scholar]
- 15.Dehlaghi-Ghadim, A. et al. ICSSIM—A framework for building industrial control systems security testbeds. Comput. Ind.148, 103906. 10.1016/j.compind.2023.103906 (2023). [Google Scholar]
- 16.Kavitha, M. S. et al. SIRT: A distinctive and smart invasion recognition tool for defending IoT integrated ICS from cyber-attacks. Int. J. Crit. Infrastruct. Prot.47, 100720. 10.1016/j.ijcip.2024.100720 (2024). [Google Scholar]
- 17.Gómez, M., Grimes, S. & Fowler, G. Development of complete hydrometallurgical processes for gold recovery from ICs and CPUs using ionic liquids. J. Environ. Manage.362, 121306. 10.1016/j.jenvman.2024.121306 (2024). [DOI] [PubMed] [Google Scholar]
- 18.Qian, P. et al. Comprehensive review of smart contract and DeFi security: Attack, vulnerability detection, and automated repair. Expert Syst. Appl.291, 128431. 10.1016/j.eswa.2025.128431 (2025). [Google Scholar]
- 19.Smaili, A. et al. A transformer-based framework for software vulnerability detection using attention-driven convolutional neural networks. Eng. Appl. Artif. Intell.160, 111859. 10.1016/j.engappai.2025.111859 (2025). [Google Scholar]
- 20.Ali, S. et al. CLDM-MMNNs: Cross-layer defense mechanisms through multi-modal neural networks fusion for end-to-end cybersecurity—Issues, challenges, and future directions. Inf. Fusion. 122, 103222. 10.1016/j.inffus.2025.103222 (2025). [Google Scholar]
- 21.Ma, S. et al. Stochastic game-based cross-layer defense scheme for jamming-resistant virtual coupled train sets. Transp. Res. C Emerg. Technol.174, 105028. 10.1016/j.trc.2025.105028 (2025). [Google Scholar]
- 22.Beketaeva, A. O., Naimanova, A. Z., Shakhan, N. & Zadauly, A. Simulation of the shock wave boundary layer interaction in flat channel with jet injection. Z. Angew Math. Mech.103, e202200375. 10.1002/zamm.202200375 (2023). [Google Scholar]
- 23.Chuang, Y. T. & Tu, C. H. Mitigating DDoS attacks in containerized environments: A comparative analysis of Docker and Kubernetes. J. Parallel Distrib. Comput.204, 105130. 10.1016/j.jpdc.2025.105130 (2025). [Google Scholar]
- 24.Aryal, S. et al. Enhancing drought monitoring in southern Alberta: A comparative evaluation of drought indices for regional applicability. Results Eng.27, 106403. 10.1016/j.rineng.2025.106403 (2025). [Google Scholar]
- 25.Abbas, H., El Sayed, I. & Esmaiel, H. & Abd El-Atty, B. Blockchain-enabled framework for cross-sector integration in smart cities facilitating risk assessment and interdependency analysis. Blockchain Res. Appl. in press; (2025). 10.1016/j.bcra.2025.100343
Associated Data
This section collects any data citations, data availability statements, or supplementary materials included in this article.
Data Availability Statement
All materials required to reproduce the experimental workflow, including configuration files, analysis scripts, and anonymized datasets, are publicly available in an open-access repository: https://github.com/dzbIGa/plc_security_reproducibility_repositoryA permanent archived version of the repository is available via Zenodo: https://doi.org/10.5281/zenodo.19250402The repository contains step-by-step instructions, dependencies, and scripts required to reproduce the statistical analysis and figures presented in this study.All shared data are anonymized or synthetic to ensure security while maintaining full reproducibility of the research.





