Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.
An anatomy of how Achilles Communications Certification (ACC) tests PLCs, RTUs, and industrial switches. It covers the classification of 31 L1 / 54 L2 test cases, the seven test types (Scans, Storms, Fuzzers, Grammars), control-protocol coverage from the IP stack up to DNP3, Modbus, and IEC 61850, and what the Normal/Warning/Failure monitors actually determine.
A primer map for anyone new to IEC 62443-4-2. Covers why the 62443 series is divided by audience rather than topic, the four faces of SL and the three faces of SL 0, the Component Requirements (CR) of the seven Foundational Requirements (FR1-7), the SAR/EDR/HDR/NDR component types, and the distinctly industrial-security idea of "maintain degraded mode instead of preventing DoS."
When a manufacturer says "we're IEC 62443-4-2 SL2 certified," the sentence alone tells you nothing about what was actually verified. This post dissects the arithmetic behind the three numbers (RA, NAR, TR) printed on a certificate, the decisive difference between N/A and out-of-scope, and why confusing SL-T/SL-C/SL-D/SL-A ruins any reading of the certificate.
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the world's first law to mandate cybersecurity for physical products with digital elements. This post lays out the incoming timeline (reporting obligations on 2026-09-11, full application on 2027-12-11), how 62443 becomes the basis of CE marking as a harmonised standard, and the 6 CRA-specific requirements 62443 does not cover.
Many legacy industrial control protocols were designed without authentication or integrity guarantees. This wasn't a mistake — it was a rational choice for the 2000s, premised on an air-gapped network, and this post examines how that choice became today's security debt, using open protocols (Modbus, DNP3) as examples.
A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.