INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Syn hesizing TCP Da a T a ic om Indus ial
Ne wo ks o Simula ions
Tomas HEGR, Leos BOHAC
Depa men o Telecommunica ion Enginee ing, Facul y o Elec ical Enginee ing,
Czech Technical Uni e si y in P ague, Technicka 2, 166 27 P ague, Czech Republic
[email p o ec ed], b[email p o ec ed]
DOI: 10.15598/aeee. 13i5.1501
Abs ac . In his pape , au ho s deal wi h a p oblem
o an impai ed TCP s eam econs uc ion om a eal-
wo ld cap u ed da a. The goal is o ob ain an o iginal
applica ion da a. The da a a e syn hesized o be used
as an inpu o a a ic gene a o . Au ho s desc ibe a
way o sol e speci ic p oblems a anspo and appli-
ca ion laye s du ing he econs uc ion o an impai ed
TCP s eam. The a ic econs uc ion is o ien ed o
IEC 60870-5-104 p o ocol on op o TCP. The e al-
ua ion o p oposed algo i hms shows ha i is possible
o es ima e o iginal ime dependencies be ween ecei ed
and dispa ched messages wi h high accu acy.
Keywo ds
IEC 60870-5-104, simula ion, sma g ids,
TCP, a ic gene a o .
1. In oduc ion
Simula ions ha e been one o he mos a o ed ways o
e i ying new a chi ec u es and p o ocols in da a ne -
wo ks o many yea s. Al hough many simula ion ools
and en i onmen s a e used on daily basis, some unda-
men al p oblems p ese e. When a simula ion model is
designed, i is impo an o conside wha is he eligible
inpu da a o he simula ed scena io. In he con ex o
communica ion sys ems, he simula ion inpu is gene -
ally p oduced by a a ic gene a ion model. Al hough
he gene a ion model is o en seen as a single en i y, i
is no a omic and can be decomposed o he simula-
ion componen p o iding he a ic gene a ion and a
desc ip ion o he gene a ed a ic.
T adi ionally, he a ic gene a ion model is s ochas-
ic, bu he e exis simula ions whe e a de e minis ic
model is p e e able. When he de e minis ic simula-
ion app oach is applied on o a limi ed p oblem a ea, i
can deli e p ecise esul s aluable o a ne wo k ou-
bleshoo ing o o ensic analysis. On he o he hand,
in case he numbe o simula ed a ic lows is exces-
si e, he de e minis ic a ic gene a o can become an
obs acle due o i s scalabili y.
Illus a i e applica ions sui able o de e minis ic
a ic models a e implemen ed in some a eas o he
Sma G id concep . Sma -G id applica ions ou o
he p ima y mission-c i ical con ol p e e eliabili y
o la ency and use TCP (T anspo Con ol P o o-
col), which p o ides a connec ion-o ien ed, eliable, in-
sequence, by e-s eam se ice [6]. A common example
is a SCADA (Supe iso y Con ol And Da a Acquisi-
ion) egula ly p obing a Remo e Te minal Uni (RTU)
o ope a ional da a. The SCADA es ablishes a session
i egula ly, and du a ion o each session is a ying in
ime. As each ISO/OSI lowe laye , including TCP,
is usually simula ed acco ding o he de ined model,
he only a ic desc ip ion needed is a he applica ion
laye . Howe e , his is e y o en he mos p oblem-
a ic pa , o ma ch eal a ic pa e ns. While eques s
gene a ed by adi ional use applica ions is common
o simula e, closed indus ial applica ions a e speci ic
and can be limi ed only o a single anonymous a ic
cap u e, because o i s con iden ial na u e.
The simula ion model o lowe ISO/OSI laye s in-
cluding TCP is al eady implemen ed in mos simula-
o s, bu he a ic gene a ion a he applica ion laye
is limi ed. I u ns ou ha he c ea ion o a a -
ic model based on a eal-wo ld cap u ed da a is chal-
lenging, especially, i i comes o uncommon p o ocols.
Mo eo e , he cap u ed a ic in he a ea o indus-
ial ne wo ks is o en hea ily bu dened by ansmis-
sion e o s, and i has o be pu ged o e ansmissions,
ou -o -o de packe s, e c.
The main goal o ou a ic analysis is o desc ibe he
de e minis ic a ic model o a pa icula TCP s eam,
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 536
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
and hus, syn hesize he a ic o any simula ion sce-
na io. This model can be imagined as a a ic desc ip-
ion se con aining ins uc ions abou segmen leng hs,
p ecise dispa ch imes and logical dependencies. Con-
side ing he place o a cap u ing poin in he ne wo k,
he es ima ion o pa ame e s men ioned abo e is a ha d
ask. In his pape , we add ess se e al p oblems e-
la ed o he p ocess o syn hesizing a ic desc ip ion
om da a cap u ed in a eal-wo ld indus ial ne wo k.
We ocus pa icula ly on IEC 60870-5-104 p o ocol [4],
which is s ill one o he mos deployed p o ocols in
powe -enginee ing o a emo e con ol ope a ions.
The pape is s uc u ed as ollows:
•In Sec ion 2. , we p esen ela ed esea ch wo ks
and s anda ds.
•Sec ion 3. de ails challenging p oblems.
•Sec ion 4. closes up cap u ed s eam speci ics.
•Sec ion 5. desc ibes ou app oach o selec ed
p oblems.
•In Sec ion 6. , achie ed esul s a e p esen ed and
we conclude ou pape by summa y in Sec ion 7.
2. Rela ed Wo k
Since he p oblem o he a ic analysis is complex
and pe ades se e al laye s, i equi es knowledge o
di e en p o ocols and echniques. Beside he applica-
ion laye p o ocol IEC 60870-5-104 s anda dized in [4],
he undamen al is he TCP speci ica ion published in
RFC 793 [13]. Mos o he wo k on cap u ed da a e-
lies on p ope da a p ep ocessing. In he con ex o he
de e minis ic gene a o , i means o app oxima e he
ime when he packe is o be dispa ched and o eo de
o d op e ansmi ed and ou -o -o de packe s.
De e mining when he packe was o iginally dis-
pa ched, i he cap u ed da a a e collec ed by an un-
known middle-box, is a ask o en ackled by au ho s
in he ela ed a ea o he passi e TCP Round-T ip
Time (RTT) measu emen . In ecen publica ions, e-
sea che s equen ly g ounds hei es ima ions in he
Times amp ex ension in oduced in RFC 1323 [14].
Fo example, au ho s o he ollowing publica ions im-
plemen ed me hods based on he Times amp ex en-
sion [12], [9]. E en hough imes amps a e e y use-
ul when de e mining he dispa ch ime, he equi ed
ex ension is o en no inco po a ed in he TCP imple-
men a ion a simple RTUs. Mo eo e , he published
echniques adi ionally neglec pa o he la ency and
conside he RTT as ime i akes o he clien ’s ou go-
ing TCP packe o be answe ed by he se e igh on
he middle-box. This is only ue i we can assume ha
one pa o he ne wo k spli by he middle-box e inces
a signi ican ly lowe la ency han he o he pa . This
app oach was a emp ed by au ho s in [8].
Focusing on he da a p ep ocessing p oblem, i.e.
packe e ansmission, ou -o -o de packe s and o he
ansmission dis u bances, i is necessa y o unde -
s and packe ’s meaning in he con ex o he TCP low.
Au ho s sugges o ack he connec ion s a e using a
ini e ansi ion-s a e model as i is p oposed in [8],
[7], bu such solu ion is complex. Ano he app oach
published in [1] p o ides a mo e s aigh o wa d solu-
ion. I is based on a basic packe o de ing acco ding
o sequence numbe s and consequen iden i ica ion o
ahole in he communica ion. Al hough he p oposed
algo i hm is simple i gi es as and accu a e esul s in
mos cases.
The simple algo i hm was inco po a ed in a a ic
gene a o called Swing [11]. This a ic gene a o ob-
se es cap u ed a ic and ies o play i back in a
way ha he esul ing packe ace ealis ically ma ch
he cha ac e is ics o he o iginal ace. The simila
app oach was implemen ed in RENETO a ic gene -
a o [2] which is aimed o he simula ion en i onmen
OMNeT++ [10]. Al hough he la e gene a o is no
he only a ic gene a o o he OMNeT++ en i on-
men , which is he subjec o ou in e es , i is as he
only one dedica ed o he ep oduc ion o he eal cap-
u ed a ic. Howe e , he gene a o is ocused on he
s a is ical desc ip ion o he cap u ed a ic which does
no co espond o ou goal.
3. P oblem De ini ion
Syn hesizing he a ic desc ip ion om da a cap u ed
in an unknown ne wo k is a complex ask o en wi hou
any way o e i ica ion. To ul ill equi emen s o he
de e minis ic a ic model, i was necessa y o econ-
s uc a ime and logical dependencies o messages a
he applica ion laye . The TCP s eam econs uc ion
was limi ed by he ollowing inpu condi ions:
•The da a was cap u ed a an a bi a y poin be-
ween clien and se e s.
•The cap u ed a ic con ains IEC 60870-5-104, i.e.
i is buil on op o TCP/IP.
•The ne wo k opology is unknown.
•The cap u ed a ic may be impai ed.
As he cap u ing in e ace could be placed anywhe e
be ween TCP clien and se e , i was no possible
o u ilize any knowledge o he ne wo k opology du -
ing he TCP s eam econs uc ion. The me hod had
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 537
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
o be based only on cha ac e is ics o he TCP and
IEC 60870-5-104 p o ocol. We ha e iden i ied h ee
main asks o accomplish he a ic econs uc ion:
•Clean he cap u e o e ansmi ed packe s and
ea ange ou -o -o de packe s.
•Iden i y logical dependencies be ween applica ion
messages and i necessa y o eo de hese mes-
sages.
•Es ima e ime when he pa icula applica ion
message was sen and ecei ed in con ex o i s
logical dependency.
The a ic gene a o model equi es ou pa ame-
e s o gene a e a pa icula , namely sende , message
leng h, o igina ing message causing gene a ion o he
message (logical dependency) and ela i e ime di e -
ence o i s o igina o a e which he message is o
be dispa ched ( ime dependency). Howe e , only he
leng h o messages and sende a e known di ec ly. Two
emaining pa ame e s ha e o be es ima ed as a esul
o he analysis in Sec ion 4.
3.1. Spli Communica ion Domain
E en hough a ic can be cap u ed in dis ibu ed
manne on in e aces o communica ing o in e con-
nec ing de ices, mos equen ly he cap u e is eco ded
only on a single in e ace o an in e connec ing ne wo k
de ice. This se up is common o ne wo k moni o ing
s a ions, o en in eg a ed in o egula ou e s, b idges,
e c. Cap u ing on he in e connec ing de ice, om now
on e e ed o as Moni o , always leads o a spli com-
munica ion domain. As is showed in Fig. 1, he spli
esul s in wo ne wo k segmen s, which a e con en ion-
ally called ups eam and downs eam depending on he
placemen o he TCP clien and se e in he ne wo k.
In ou case, he SCADA se e esides in he ups eam
segmen and RTU is in he downs eam pa h.
SCADA RTUMoni o
Downs eam
Bi-di ec ional
TCP s eam
Ups eam
Fig. 1: The communica ion domain is spli by he Moni o o
wo segmen s wi h dissimila ansmission condi ions a -
ec ing he RTT es ima ion.
Ha ing in o ma ion only om he Moni o , i is no
possible exac ly de e mine he end- o-end delay be-
ween bo h communica ing de ices. Mo eo e , due o
he na u e o ups eam and downs eam pa hs, whe e
he bandwid h can be dissimila , he adi ional pas-
si e RTT es ima ion is no enough o sa is y analysis
equi emen s. The RTT can a y signi ican ly du ing
he ime o he connec ion depending on local ansmis-
sion condi ions. As was men ioned be o e, TCP ex en-
sion is also no possible o use since many RTU s ill
implemen simple old TCP algo i hms. As he p ope
knowledge o a delay be ween RTU and SCADA is nec-
essa y o u he in es iga ion o TCP e ansmissions
and dispa ch imes, we ha e decided o implemen dy-
namic RTT- o-ACK es ima ion h oughou he whole
cap u e. The RTT- o-ACK is a ime in e al be ween
he TCP segmen and i s co esponding acknowledg-
men a e cap u ed a he Moni o . The algo i hm is
desc ibed in he analysis pa in Subsec ion 5.2.
3.2. TCP Re ansmissions
One o he main challenges in he TCP s eam econ-
s uc ion p oblem is o deal wi h TCP e ansmissions.
When he TCP e ansmission occu s, i dis up s he
o de ing o iming o da a a he applica ion laye . A
i s , o deal wi h e ansmissions, i is necessa y o
iden i y hem oge he wi h side e ec s accompany-
ing e ansmission om he Moni o pe spec i e, e.g.
duplica ed acknowledgmen s (DUP-ACK) and missing
segmen s. P ima ily, ollowing asks ha e o be sol ed
a anspo laye in bo h di ec ions be o e i he anal-
ysis o cap u ed da a o applica ion dependencies:
•Selec ion o e ansmi ed packe s o d op and o
keep o he u he analysis.
•Reo de ing o e ansmi ed ou -o -o de packe s.
•Selec ion o pai s o e ansmi ed packe and i s
duplica ed acknowledgmen o d op.
4. S eam-Speci ic Cons ains
We ha e in es iga ed se e al a ailable a ic cap u es
con aining dozens o TCP s eams o IEC 60870-5-104.
Since he TCP implemen a ion a RTUs is o en only
basic TCP Reno, he analysis is in some pa s imple-
men a ion speci ic. Main obse a ions esul ing om
he a ailable cap u es a e ollowing:
•No all s eams a e p ope ly s a ed by he SYN,
SYN-ACK, ACK sequence and p ope ly ended.
Some s eams s eams a e ime-ou ed.
•IEC 60870-5-104 messages a e no segmen ed by
TCP o mo e packe s.
•Mos o he cap u ed messages is di ec ly ollowed
by emp y acknowledgmen s.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 538
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
•Delayed acknowledgmen s a e a e.
•All ansmi ed messages has se up he TCP push
lag.
•Some s eams con ain e ansmissions o igina ed
in he applica ion laye .
A e e ansmissions we e iden i ied using exp es-
sions de ailed in Subsec ion 5.1. , i u ned ou ha
he da a o he applica ion laye a e a ec ed in ollow-
ing cases:
•F om he Moni o pe spec i e, a TCP segmen
was acknowledged be o e i s e ansmission oc-
cu s. This means ha he TCP segmen was suc-
cess ully ecei ed and an ACK was sen by he
ecei e , bu he ACK was los a e i passed he
Moni o . The sende e ansmi he packe a e
eaching he Re ansmission Timeou (RTO) wai -
ing o he ACK again. In such case, we simply
ake in o accoun only he i s occu ence o he
TCP segmen and d op all e ansmissions includ-
ing DUP-ACKs.
•The e is one o mo e e ansmissions de ec ed wi h
an ACK ollowing he e ansmission sequence.
The e ansmi ed TCP segmen was los a e i
passed he Moni o a leas once. In his case, i is
necessa y o decide which packe s o he sequence
a e o be d opped o accep ed. The selec ion p o-
cess is de ailed in Subsec ion 5.3.
•When TCP segmen wi h a sequence numbe
lowe han al eady passed segmen om he same
sende , i is conside ed o be ou -o -o de . In such
case, he i s packe was los be o e i passed he
Moni o . This ou -o -o de TCP segmen has o
be shi ed o di e en place in ime. The algo i hm
o he selec ion and ime shi p ocess is desc ibed
in Subsec ion 5.4.
Cases abo e co e ed all cases o e ansmissions oc-
cu ing in ou cap u ed da a which does no mean ha
hese co e all possible TCP s a es. Ou goal was o
deal wi h he iden i ied issues and no o p oduce a uni-
e sal ool o he TCP a ic econs uc ion. Due o
he al eady men ioned complexi y o wo inal s a e ma-
chines a wo p o ocol laye s we pos poned ad anced
ime shi s o ou u u e wo k. The main algo i hmic
pa s o he a ic econs uc ion p ocess a e desc ibed
in ollowing subsec ions.
5. Algo i hm Designs
The a ic econs uc ion p ocess is comp ised o se -
e al s eps. A i s , he cap u ed da a is eassembled o
a ma ix con aining pa ame e s o he ollowing analy-
sis. Subsequen ly, he e ansmi ed packe s a e iden-
i ied (Subsec ion 5.1. ), RTT- o-ACK is es ima ed
o bo h ne wo k segmen s (Subsec ion 5.2. ), e ans-
mi ed packe s o d op a e selec ed (Subsec ion 5.3. )
o eo de ed (Subsec ion 5.4. ), and e en ually he
dependencies be ween IEC 60870-5-104 messages a e
de ined (Subsec ion 5.5. ).
5.1. Iden i ica ion o Re ansmi ed
Packe s
We ha e inspi ed app oach in he wo k [1] and based
he e ansmission iden i ica ion on he de ec ion o
holes in sequence numbe s. Since he sequence num-
be s om bo h communica ion sides ha e o be mono-
onically inc easing wi h he numbe o sen by es, he
iden i ica ion o TCP segmen s s anding ou side o he
sequence is s aigh o wa d. The basic idea is depic ed
in Fig. 2.
Since necessa y da a was s uc u ed in o a ma ix,
we we e able o iden i y e ansmissions using basic
column ope a ions. A i s we il e ed packe s om a
ime o de ed se o packe s Eq. (1) o one di ec ion
depending on a sou ce po as in Eq. (2|) o he clien
side and in Eq. (3) o he se e side. Subsequen ly,
we il e ed ou h ee se s o packe s o each o he
communica ing sides. This il e is based on di e ence
o TCP sequence numbe s and leng hs o TCP segmen
in shi ed column as is exp essed in Eq. (4), Eq. (5)
and Eq. (6). Using his app oach, i is ob ained a se
o e ansmi ed packe s C e , a se packe s Cpnc whe e
he p e ious segmen was no cap u ed and inally a se
o DUP-ACKs Cdack. The same p ocess was applied on
he se e side packe s.
P={p0, p1...pn},
pc ime
i≤pc ime
i+1 ;i∈ h0; n−1i,(1)
C={p∈P|ps c =clien },(2)
S={p∈P|ps c =se e },(3)
,C e =C|(Csnum
i−(Csnum
i+1 +Cslen
i+1 ))<0,
i∈ h0; |C|i,(4)
Cpnc =C|(Csnum
i−(Csnum
i+1 +Cslen
i+1 ))>0,
i∈ h0; |C|i,(5)
Cdack =C|(Canum
i−Canum
i+1 =0)∧(Cslen
i=0)∧(C in
i6=1),
i∈ h0; |C|i.(6)
Each uppe index exp ess an a ibu e o he pa ic-
ula objec as ollows: pc ime s ands o packe ’s cap-
u ed ime, ps c is packe ’s sou ce IP add ess, Csnum is
TCP sequence numbe , Cslen is TCP segmen leng h,
Canum is TCP acknowledgmen numbe and C in
s ands o TCP FIN lag.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 539
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Time
Sequence numbe
Packe loss on he
way o Moni o
Packe loss on he
way om Moni o
Fig. 2: The undis u bed TCP sequence numbe ing should be
mono onically inc easing. De ec ing miss-o de ed se-
quence numbe s iden i ies TCP e ansmissions.
SCADA RTUMoni o
RTT o ACK X
RTT o ACK Y
RTT o ACK A
ACK X
ACK Y
SEG Y
ACK A
SEG A
SEG X
Time
Fig. 3: The RTT- o-ACK sequence o ime windows, whe e
g een windows a e o he downs eam and ed windows
a e o he ups eam.
5.2. RTT- o-ACK Es ima ion
Ha ing iden i ied he e ansmi ed packe , i is pos-
sible o compu e he RTT- o-ACK delay h oughou
he whole cap u e dynamically. I e a ing h ough he
cap u ed packe s, we simply compu e a ime di e ence
be ween a TCP segmen and i s ACK coming back
as a esponse o he sende when passing he Mon-
i o . The algo i hm skips iden i ied e ansmissions.
As he e was a g ea amoun o emp y ACKs, i.e. seg-
men s wi hou any payload, coming back om he e-
cei e in bo h di ec ions immedia ely a e he TCP
segmen s, we could limi he algo i hm only o such
RTT- o-ACK delays wi h emp y ACKs. This app oach
emo es an e o caused by he ime, which is needed
by he ecei e o p ocess he applica ion message.
The inal p oduc o he RTT- o-ACK is a sequence
o ime windows o bo h ups eam and downs eam
ne wo k segmen s. I can be in e p e ed as in he
Fig. 3. We did no in ol e packe leng hs in his
algo i hm, as mos o he packe s we e abou he same
leng h.
5.3. Selec ion om Re ansmi ed
Packe s
When he e a e one o mo e iden ical e ansmi ed
TCP segmen s cap u ed one by one and ollowed only
by an ACK, i is necessa y o decide o which o hem
he ACK was o iginally assigned. To deal wi h his
p oblem, we ook in o conside a ion he RTT- o-ACK
ime windows e lec ing condi ions on he ansmission
channel in he pa icula ime domain. Since he anal-
ysis is made o -line, i is possible o inco po a e no
only he ime windows be o e he e ansmission occu s
bu also hose om he u u e.
The Alg. 1 is based on he pa ame e -scaled RTT- o-
ACK ime window closes o he i s occu ence o he
e ansmission. The pa ame e σde e mine a numbe
o ime windows accep ed o a mean RTT- o-ACK.
This alue is subs i u ed om he ime when he ACK
was cap u ed and hen he closes o he e ansmi -
ed packe s is selec ed o u he analysis. O he s a e
d opped. The numbe o conside ed RTT- o-ACKs is
limi ed by τin ime and by pa ame e φin minimum
numbe o ime windows.
Algo i hm 1 Re ansmission selec ion.
Requi e: Se o e ansmi ed packe s R, RTT- o-
ACK imes RA ime o sende , σscaling ac o ,
τmax one side ime limi , φmin packe limi .
Ensu e: Index o he selec ed packe i.
1: RAcloses =min(|RA ime −R. i s ime|)
2: wini =RAcloses ·σ
3: RA =RA ∈((R. i s ime −wini ),(R.las ime +
wini ))
4: wRAs =RA.las ime −RA. i s ime
5: wτ= (R.las ime +τ)−(R. i s ime −τ)
6: i wRAs > wτ hen
7: RA =RA ∈wτ
8: end i
9: i |RA|< φ hen
10: RA =φcloses RA
11: end i
12: =ACKR
ime −mean(RA)
13: e u n i=minindex(| −R ime|)
5.4. Packe Reo de ing
In case he TCP segmen was los be o e i passed he
Moni o , he e ansmi ed one can be cap u ed o he
i s ime a e a segmen wi h highe sequence num-
be al eady passed he Moni o . The e ansmi ed
TCP segmen is o be placed in be o e he i s occu -
ence o he ollowing segmen , which cap u ed ime is
sou ce
p e . This is he only case whe e we a emp ed o
do a ime shi du ing he packe eo de ing. As i is
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 540
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
easy o ind ou a minimal ime del a δsou ce
min be ween
wo consecu i e packe s om a common sende , we es-
ima ed he ime o he ou -o - he-o de TCP segmen
as sou ce
p e −δsou ce
min .
5.5. Message Dependencies
Finally, las wo algo i hms desc ibe he way a pa icu-
la IEC 60870-5-104 message depends on i s o igina ing
message in bo h ime and logical domain. A i s , i
is necessa y o es ima e he ime when a message was
sen and ecei ed on bo h communica ing sides. This
can be done again using a column shi me hod on a
newly c ea ed column in he o iginal ma ix. As we as-
sume ha bo h TCP he bi-di ec ional low is passing
he same cap u ing in e ace and he pa h in a ne wo k
is in bo h di ec ions symme ical, we o he simplici y
app oxima e he end- o-Moni o delay e m as a hal o
RTT- o-ACK which is closes o he in es iga ed TCP
segmen . The dispa ch ime o he message is hen es-
ima ed as d= cap − e m, whe e cap is a ime when
he TCP segmen was cap u ed (including he eo de -
ing). Simila ly, he ime o he message ecep ion is
es ima ed as = cap + e m.
The second s ep is o de e mine logical dependen-
cies be ween messages. Since he IEC 60870-5-104 uses
simila mechanism o TCP wi h sen / o- ecei e coun-
e s, he ela ions a e simply iden i ied o numbe ed
messages ( ype I). Howe e , he IEC 60870-5-104 does
con ain also unnumbe ed messages ( ype U) and supe -
iso messages (S). Fo his eason, we implemen ed a
simple decision algo i hm in Alg. 2.
Algo i hm 2 Message dependencies.
Requi e: In es iga ed message m. Se o cap u ed
messages M.
Ensu e: O igina ing message o.
1: α= (Ms c 6=ms c)∧(M cap < m cap )
2: i m ype == U hen
3: o=las (M|α)
4: end i
5: i m ype == S hen
6: o=las (M|α∧(M x=m x−1))
7: end i
8: i m ype == I hen
9: o= (M|α∧(M x=m x)∧max(M x))
10: end i
11: e u n o
Al hough he Alg. 2 always led o p ope esul s wi h
logical dependencies, i was necessa y o co ec some
esul s in he case o he ime dependencies. The ime
di e ence be ween he o igina o and i s successo s
scould gi e he o e lapping imes amps. Since he
message canno be sen be o e i s logical o igina o
was ecei ed, we ha e implemen ed ime ba ie s. In
case o he o e lapping imes, he ime di e ence o
he successo dispa ch ime is changed o ze o. Time
ba ie s a e also implemen ed o check es ima ed imes
agains cap u ed imes. As he message, depending on
he communica ing side, canno be ecei ed o sen be-
o e i was cap u ed. In such case, he dispa ch ime is
shi ed in he middle o ela ed cap u ed imes.
6. E alua ion
Each algo i hm desc ibed in p e ious Sec ion 5. was
in eg a ed in o a complex applica ion o analyze TCP
s eams om a eal-wo ld cap u e con aining he IEC
60870-5-104 communica ion. Since i was no possible
o e i y he p oposed app oach on a cap u e om he
unde ined ne wo k opology wi hou exac in o ma ion
om bo h communica ing sides, we decided o base
he e alua ion on simula ions. The e alua ion ocuses
mainly on he domain o ime dependencies.
The simula ion model was designed as an indus ial
ne wo k wi h a poin - o-poin low-bandwid h channel
o eleme ic ope a ions. E en hough he channel is
usually bu dened wi h high Bi E o Ra e (BER) in
such se ups, i is o en sha ed by mo e TCP s eams
in pa allel. The ne wo k model depic ed in Fig. 4
consis s o wo connec ion ypes. Fi s one, which
is placed be ween Moni o and Rou e s, is a low-
bandwid h channel wi h bandwid h 14 kbps and BER
10−4. The second one, placed be ween Rou e s and end
de ices, is he s anda d Fas E he ne wi h bandwid h
100 Mbps and BER 10−10. The payload o inspec ed
TCP s eams was designed acco ding o pa e ns ound
in he eal-wo ld cap u ed IEC 60870-5-104 a ic. In
ou scena ios, he connec ion was always ini ia ed om
RTU sending bulk applica ion da a [3] in p ede ined
imes owa ds he SCADA se e , which esponded a
leas by 6 by es o applica ion da a wi h p obabili y
a ying om 0.3 o 0.5. To make he simula ion mo e
ealis ic, we loaded sha ed links by 5 concu en TCP
s eams ans e ing andom block da a. Each simula-
ion scena io was epea ed one hund ed imes.
The analysis is based on h ee cap u es p oduced
on SCADA, RTU and Moni o a each simula ion un.
All cap u es we e eco ded a de ices wi h absolu ely
synch onized sys em imes, and hus, cap u e ime o
each cap u ed ame had he same ini ial ime poin .
Following es ima ions a e based clea ly on he cap u e
om he Moni o , as in he eal-wo ld case. Remain-
ing cap u es we e used only o compa ison pu poses.
Resul s cha ac e izing TCP s eams a e shown in
Tab. 1. As one can see, he TCP s eam leng h is
a ying signi ican ly o di e en s eams. This is due
he se e al ac o s. A i s , he cap u e i sel had lim-
i ed leng h, and a second, some s eams we e du ing
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 541
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Fig. 4: Simula ion opology o indus ial ne wo k wi h low-
bandwid h connec ions be ween Rou e s and Moni o .
he cap u ing disconnec ed and epea edly es ablished.
I is also no able ha a o al numbe o packe s is in
some case almos wo imes highe han he o al num-
be o ans e ed applica ion messages (RTU and SCD
messages).
Tab. 1: Rounded mean alues cha ac e izing TCP s eams.
Id Leng h
[s]
To al
pck s.
[-]
Re-
o de
[-]
D op
[-]
RTU
msg.
[-]
SCD
msg
[-]
8 6352 2680 10 69 1073 420
10 2634 406 3 33 87 49
12 1498 419 4 18 163 86
13 1832 298 4 15 102 48
17 4352 1080 12 52 386 126
A i s , we ocused on a ime di e ence be ween
wo messages ep esen ing a SCADA con ol command
and RTU esponses, and ice e sa. As he simula ed
da a had no logical dependency de ined a he applica-
ion laye , we ha e de e mined he o igina o , i.e. he
message causing dispa ch o applica ion igge ed mes-
sages, as he closes TCP segmen wi h non-ze o leng h
and acknowledgmen numbe lowe han message o be
dispa ched. Due o his s ep, all messages had o igi-
na o p eceding hei dispa ch ime which co ela es
wi h he obse ed beha io o he IEC 60870-5-104
p o ocol. The esul s o de ia ions be ween es ima ed
and eal ime di e ences ob ained om simula ions a e
depic ed in Fig. 5a. I we compa e he mean de ia ion
o he pa icula TCP s eam wi h he eal- ime di e -
ence be ween messages showed in Fig. 5b, we can ind
ha he ela i e de ia ion is up o 4 %. This is an
accep able le el o mos simula ion pu poses.
A Second, we a emp ed o e alua e an end- o-end
delay as a second p oduc o he ime es ima ions based
on he dynamic RTT- o-ACK e alua ion. Al hough
his is no di ec ly ela ed o he p oduced a ic
desc ip ion o he a ic gene a o , i illus a es he
accu acy o he p oposed app oach. Resul s showing
de ia ions be ween he es ima ed and eal end- o-end
delays a e depic ed in Fig. 6a. I we compa e hose
esul s wi h a co esponding mean end- o-end delays
showed in Fig. 6, we can see ha he ela i e de ia-
ion eaches 12 % in wo s case. E en hough his is a
highe numbe han in he case o ime dependencies,
i is s ill ole able in he scope o his a icle.
8 10 12 13 17
S eam numbe [-]
0.7
0.8
0.9
1.0
1.1
De ia ion be ween es ima ed and eal ime di e ence [s]
(a) De ia ion be ween es-
ima ed and eal imes
di e ences.
8 10 12 13 17
S eam numbe [-]
0
50
100
150
200
250
Real ime di e ence [s]
(b) Time di e ences be-
ween an o igina o
igge ed messages.
Fig. 5: Compa ison o eal ime di e ences be ween o igina o
and dispa ched messages ob ained om end de ices de-
pic ed in Fig. 5b wi h hei de ia ion showed in Fig. 5a.
A ed line s ands o mean alue, a blue box shows i s
and hi d qua ile and whiske s a e placed on 5 % and
95 % bo de s.
8 10 12 13 17
S eam numbe [-]
0.00
0.05
0.10
0.15
0.20
0.25
0.30
0.35
De ia ion be ween es ima ed and eal end- o-end delay [s]
(a) De ia ion be ween
end- o-end delays.
8 10 12 13 17
S eam numbe [-]
0.35
0.40
0.45
0.50
0.55
0.60
0.65
0.70
0.75
0.80
Real end- o-end delay [s]
(b) Real end- o-end delay
in bo h di ec ions.
Fig. 6: De ia ion o eal end- o-end delays and es ima ed end-
o-end delays in Fig 6a shows he accu acy o he p o-
posed app oach in compa ison o eal end- o-end delays
analyzed in bo h di ec ions and depic ed in Fig. 6b.
7. Conclusion
The a ic gene a o s used in simula ion en i onmen s
o en su e by an insu icien eal-wo ld a ic sou ces.
Due o his eason, we decided o c ea e an analyze o
he IEC 60870-5-104 p o ocol wi h he goal o syn he-
size a cap u ed a ic o o m a desc ip ion ile, which
can be used as an inpu o a ic gene a o s. P oposed
algo i hms show a possible way how o deal wi h he
econs uc ion o he o iginal applica ion da a om an
impai ed TCP s eam.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 542
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
The p esen ed app oach, which is based on he dy-
namic e alua ion o he RTT- o-ACK delay, p o ed i s
usabili y when es ima ing ime dependencies o gen-
e a ed applica ions messages. Simula ion esul s show
ha he ela i e de ia ion be ween es ima ed and eal
end- o-end delays eaches up o 12 %. E en mo e
encou aging esul s we e ob ained in case o ela i e
de ia ion be ween es ima ed and eal ime di e ences
eaching in a e age only 4 % a in es iga ed TCP
s eams.
Since we unde s and ha he analysis is now limi ed
o he speci ic TCP implemen a ion, we plan o ex end
i o o he implemen a ions and o e i y ou esul s
in he ield as well.
Acknowledgmen
This wo k was suppo ed by g an
no. VG20132015104, and by g an no.
SGS13/200/OHK3/3T/13.
Re e ences
[1] BENKO, P. and A. VERES. A passi e me hod o
es ima ing end- o-end TCP packe loss. In: Global
Telecommunica ions Con e ence 2002 (GLOBE-
COM ’02). Taipei: IEEE, 2002, pp. 2609–
2613. ISBN 0-7803-7632-3. DOI: 10.1109/GLO-
COM.2002.1189102.
[2] GEYER, F., S. SCHNEELE and G. CARLE.
RENETO, a ealis ic ne wo k a ic gene a o o
OMNeT++/INET. In: P oceedings o he 6 h In-
e na ional ICST Con e ence on Simula ion Tools
and Techniques. B ussels: ICST, 2013, pp. 73–81.
ISBN 978-1-4503-2464-9.
[3] HEGR, T. Simula ion pa e ns o he RTU a ic.
2015.
[4] IEC 60870-5-104. T ansmission p o ocols-Ne wo k
access o IEC 60870-5-101 using s anda d ans-
po p o iles. Gene a: IEC, 2006.
[5] JIANG, H. and C. DOVROLIS. Passi e es ima-
ion o TCP ound- ip imes. ACM SIGCOMM
Compu e Communica ion Re iew. 2002, ol. 32,
iss. 3, pp. 75–88. ISSN 0146-4833.
[6] LEON-GARCIA, A. and I. WIDJAJA. Com-
munica ion ne wo ks: undamen al concep s and
key a chi ec u es. Bos on: McG aw-Hill, 2000.
ISBN 00-702-2839-6.
[7] LU, G. and X. LI. On he co espondency be-
ween TCP acknowledgmen packe and da a
packe . In: P oceedings o he Con e ence on In-
e ne measu emen - IMC ’03. New Yo k: ACM
P ess, 2003, pp. 259–272. ISBN 1-58113-735-4.
DOI: 10.1145/948205.948239.
[8] SCHIAVONE, M., P. ROMIRER-
MAIERHOFER, F. RICCIATO and A. BAIOC-
CHI. Towa ds Bo leneck Iden i ica ion in Cellula
Ne wo ks ia Passi e TCP Moni o ing. Ad-hoc,
Mobile, and Wi eless Ne wo ks. 2014, ol. 8487,
no. 1, pp. 72–85. ISBN 978-3-319-07424-5.
DOI: 10.1007/978-3-319-07425-2_6.
[9] STROWES, S. D. Passi ely Measu ing TCP
Round- ip Times. Queue - High- equency T ad-
ing. 2013, ol. 11, iss. 8, pp. 50–61. ISSN 1542-
7730. DOI: 10.1145/2523426.2539132.
[10] VARGA, A. The OMNeT++ Disc e e E en Sim-
ula ion Sys em. In: P oceedings o he Eu-
opean Simula ion Mul icon e ence (ESM’2001).
P ague: ESM, 2001, pp. 1–65. ISBN 1-56555-225-
3.
[11] VISHWANATH, K. V. and A. VAHDAT. Real-
is ic and esponsi e ne wo k a ic gene a ion.
In: P oceedings o he 2006 con e ence on Applica-
ions, echnologies, a chi ec u es, and p o ocols o
compu e communica ions (SIGCOMM ’06). New
Yo k: ACM P ess, 2006, pp. 111–122. ISBN 1-
59593-308-5. DOI: 10.1145/1159913.1159928.
[12] HAIJIN, Y., K. LI, S. WATTERSON and D.
LOWENTHAL. Imp o ing passi e es ima ion o
TCP ound- ip imes using TCP imes amps.
In: P oceedings o IEEE In e na ional Wo k-
shop on IP Ope a ions and Managemen . Bei-
jing: IEEE, 2004, pp. 181–185. ISBN 0-7803-8836-
4. DOI: 10.1109/IPOM.2004.1547614.
[13] RFC 793: T ansmission Con ol P o ocol. In-
e ne Enginee ing Task Fo ce (IETF) [online].
1981. A ailable a : h p://www.ie .o g/
c/ c793. x .
[14] RFC 1323: TCP Ex ensions o High Pe o -
mance. In e ne Enginee ing Task Fo ce (IETF)
[online]. 1992. A ailable a : h p://www.ie .
o g/ c/ c1323. x .
Abou Au ho s
Tomas HEGR ecei ed his M.Sc. in compu e
science a he Czech Technical Uni e si y in P ague
in 2012. He pa icipa es in eaching ac i i ies a he
depa men o Telecommunica ion enginee ing. His
esea ch in e es s in ol e indus ial ne wo ks based
on E he ne and So wa e-De ined Ne wo king in all
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 543
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
esea ch a eas.
Leos BOHAC ecei ed he M.Sc. and Ph.D.
deg ees in elec ical enginee ing om he Czech
Technical Uni e si y, P ague, in 1992 and 2001,
espec i ely. Since 1992, he has been eaching op ical
communica ion sys ems and da a ne wo ks wi h he
Czech Technical Uni e si y, P ague. His esea ch
in e es is on he applica ion o high-speed op ical
ansmission sys ems in a da a ne wo k.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 544