scieee Science in your language
[en] (orig)

Synthesising TCP data traffic from industrial networks for simulations

Abstract

In this paper, authors deal with a problem of an impaired TCP stream reconstruction from a real-world captured data. The goal is to obtain an original application data. The data are synthesized to be used as an input for a traffic generator. Authors describe a way to solve specific problems at transport and application layers during the reconstruction of an impaired TCP stream. The traffic reconstruction is oriented to IEC 60870-5-104 protocol on top of TCP. The evaluation of proposed algorithms shows that it is possible to estimate original time dependencies between received and dispatched messages with high accuracy.

Read accessible full text

Synthesising TCP data traffic from industrial networks for simulations

Author: Hégr, Tomáš
Publisher: Vysoká škola báňská - Technická univerzita Ostrava
Year: 2015
DOI: 10.15598/aeee.v13i5.1501
Source: https://dspace.vsb.cz/bitstreams/c50453f5-f31a-4cd3-868b-8230af79c950/download
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Syn hesizing TCP Da a T a ic om Indus ial
Ne wo ks o Simula ions
Tomas HEGR, Leos BOHAC
Depa men o Telecommunica ion Enginee ing, Facul y o Elec ical Enginee ing,
Czech Technical Uni e si y in P ague, Technicka 2, 166 27 P ague, Czech Republic
[email p o ec ed], b[email p o ec ed]
DOI: 10.15598/aeee. 13i5.1501
Abs ac . In his pape , au ho s deal wi h a p oblem
o an impai ed TCP s eam econs uc ion om a eal-
wo ld cap u ed da a. The goal is o ob ain an o iginal
applica ion da a. The da a a e syn hesized o be used
as an inpu o a a ic gene a o . Au ho s desc ibe a
way o sol e speci ic p oblems a anspo and appli-
ca ion laye s du ing he econs uc ion o an impai ed
TCP s eam. The a ic econs uc ion is o ien ed o
IEC 60870-5-104 p o ocol on op o TCP. The e al-
ua ion o p oposed algo i hms shows ha i is possible
o es ima e o iginal ime dependencies be ween ecei ed
and dispa ched messages wi h high accu acy.
Keywo ds
IEC 60870-5-104, simula ion, sma g ids,
TCP, a ic gene a o .
1. In oduc ion
Simula ions ha e been one o he mos a o ed ways o
e i ying new a chi ec u es and p o ocols in da a ne -
wo ks o many yea s. Al hough many simula ion ools
and en i onmen s a e used on daily basis, some unda-
men al p oblems p ese e. When a simula ion model is
designed, i is impo an o conside wha is he eligible
inpu da a o he simula ed scena io. In he con ex o
communica ion sys ems, he simula ion inpu is gene -
ally p oduced by a a ic gene a ion model. Al hough
he gene a ion model is o en seen as a single en i y, i
is no a omic and can be decomposed o he simula-
ion componen p o iding he a ic gene a ion and a
desc ip ion o he gene a ed a ic.
T adi ionally, he a ic gene a ion model is s ochas-
ic, bu he e exis simula ions whe e a de e minis ic
model is p e e able. When he de e minis ic simula-
ion app oach is applied on o a limi ed p oblem a ea, i
can deli e p ecise esul s aluable o a ne wo k ou-
bleshoo ing o o ensic analysis. On he o he hand,
in case he numbe o simula ed a ic lows is exces-
si e, he de e minis ic a ic gene a o can become an
obs acle due o i s scalabili y.
Illus a i e applica ions sui able o de e minis ic
a ic models a e implemen ed in some a eas o he
Sma G id concep . Sma -G id applica ions ou o
he p ima y mission-c i ical con ol p e e eliabili y
o la ency and use TCP (T anspo Con ol P o o-
col), which p o ides a connec ion-o ien ed, eliable, in-
sequence, by e-s eam se ice [6]. A common example
is a SCADA (Supe iso y Con ol And Da a Acquisi-
ion) egula ly p obing a Remo e Te minal Uni (RTU)
o ope a ional da a. The SCADA es ablishes a session
i egula ly, and du a ion o each session is a ying in
ime. As each ISO/OSI lowe laye , including TCP,
is usually simula ed acco ding o he de ined model,
he only a ic desc ip ion needed is a he applica ion
laye . Howe e , his is e y o en he mos p oblem-
a ic pa , o ma ch eal a ic pa e ns. While eques s
gene a ed by adi ional use applica ions is common
o simula e, closed indus ial applica ions a e speci ic
and can be limi ed only o a single anonymous a ic
cap u e, because o i s con iden ial na u e.
The simula ion model o lowe ISO/OSI laye s in-
cluding TCP is al eady implemen ed in mos simula-
o s, bu he a ic gene a ion a he applica ion laye
is limi ed. I u ns ou ha he c ea ion o a a -
ic model based on a eal-wo ld cap u ed da a is chal-
lenging, especially, i i comes o uncommon p o ocols.
Mo eo e , he cap u ed a ic in he a ea o indus-
ial ne wo ks is o en hea ily bu dened by ansmis-
sion e o s, and i has o be pu ged o e ansmissions,
ou -o -o de packe s, e c.
The main goal o ou a ic analysis is o desc ibe he
de e minis ic a ic model o a pa icula TCP s eam,
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 536
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
and hus, syn hesize he a ic o any simula ion sce-
na io. This model can be imagined as a a ic desc ip-
ion se con aining ins uc ions abou segmen leng hs,
p ecise dispa ch imes and logical dependencies. Con-
side ing he place o a cap u ing poin in he ne wo k,
he es ima ion o pa ame e s men ioned abo e is a ha d
ask. In his pape , we add ess se e al p oblems e-
la ed o he p ocess o syn hesizing a ic desc ip ion
om da a cap u ed in a eal-wo ld indus ial ne wo k.
We ocus pa icula ly on IEC 60870-5-104 p o ocol [4],
which is s ill one o he mos deployed p o ocols in
powe -enginee ing o a emo e con ol ope a ions.
The pape is s uc u ed as ollows:
•In Sec ion 2. , we p esen ela ed esea ch wo ks
and s anda ds.
•Sec ion 3. de ails challenging p oblems.
•Sec ion 4. closes up cap u ed s eam speci ics.
•Sec ion 5. desc ibes ou app oach o selec ed
p oblems.
•In Sec ion 6. , achie ed esul s a e p esen ed and
we conclude ou pape by summa y in Sec ion 7.
2. Rela ed Wo k
Since he p oblem o he a ic analysis is complex
and pe ades se e al laye s, i equi es knowledge o
di e en p o ocols and echniques. Beside he applica-
ion laye p o ocol IEC 60870-5-104 s anda dized in [4],
he undamen al is he TCP speci ica ion published in
RFC 793 [13]. Mos o he wo k on cap u ed da a e-
lies on p ope da a p ep ocessing. In he con ex o he
de e minis ic gene a o , i means o app oxima e he
ime when he packe is o be dispa ched and o eo de
o d op e ansmi ed and ou -o -o de packe s.
De e mining when he packe was o iginally dis-
pa ched, i he cap u ed da a a e collec ed by an un-
known middle-box, is a ask o en ackled by au ho s
in he ela ed a ea o he passi e TCP Round-T ip
Time (RTT) measu emen . In ecen publica ions, e-
sea che s equen ly g ounds hei es ima ions in he
Times amp ex ension in oduced in RFC 1323 [14].
Fo example, au ho s o he ollowing publica ions im-
plemen ed me hods based on he Times amp ex en-
sion [12], [9]. E en hough imes amps a e e y use-
ul when de e mining he dispa ch ime, he equi ed
ex ension is o en no inco po a ed in he TCP imple-
men a ion a simple RTUs. Mo eo e , he published
echniques adi ionally neglec pa o he la ency and
conside he RTT as ime i akes o he clien ’s ou go-
ing TCP packe o be answe ed by he se e igh on
he middle-box. This is only ue i we can assume ha
one pa o he ne wo k spli by he middle-box e inces
a signi ican ly lowe la ency han he o he pa . This
app oach was a emp ed by au ho s in [8].
Focusing on he da a p ep ocessing p oblem, i.e.
packe e ansmission, ou -o -o de packe s and o he
ansmission dis u bances, i is necessa y o unde -
s and packe ’s meaning in he con ex o he TCP low.
Au ho s sugges o ack he connec ion s a e using a
ini e ansi ion-s a e model as i is p oposed in [8],
[7], bu such solu ion is complex. Ano he app oach
published in [1] p o ides a mo e s aigh o wa d solu-
ion. I is based on a basic packe o de ing acco ding
o sequence numbe s and consequen iden i ica ion o
ahole in he communica ion. Al hough he p oposed
algo i hm is simple i gi es as and accu a e esul s in
mos cases.
The simple algo i hm was inco po a ed in a a ic
gene a o called Swing [11]. This a ic gene a o ob-
se es cap u ed a ic and ies o play i back in a
way ha he esul ing packe ace ealis ically ma ch
he cha ac e is ics o he o iginal ace. The simila
app oach was implemen ed in RENETO a ic gene -
a o [2] which is aimed o he simula ion en i onmen
OMNeT++ [10]. Al hough he la e gene a o is no
he only a ic gene a o o he OMNeT++ en i on-
men , which is he subjec o ou in e es , i is as he
only one dedica ed o he ep oduc ion o he eal cap-
u ed a ic. Howe e , he gene a o is ocused on he
s a is ical desc ip ion o he cap u ed a ic which does
no co espond o ou goal.
3. P oblem De ini ion
Syn hesizing he a ic desc ip ion om da a cap u ed
in an unknown ne wo k is a complex ask o en wi hou
any way o e i ica ion. To ul ill equi emen s o he
de e minis ic a ic model, i was necessa y o econ-
s uc a ime and logical dependencies o messages a
he applica ion laye . The TCP s eam econs uc ion
was limi ed by he ollowing inpu condi ions:
•The da a was cap u ed a an a bi a y poin be-
ween clien and se e s.
•The cap u ed a ic con ains IEC 60870-5-104, i.e.
i is buil on op o TCP/IP.
•The ne wo k opology is unknown.
•The cap u ed a ic may be impai ed.
As he cap u ing in e ace could be placed anywhe e
be ween TCP clien and se e , i was no possible
o u ilize any knowledge o he ne wo k opology du -
ing he TCP s eam econs uc ion. The me hod had
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 537
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
o be based only on cha ac e is ics o he TCP and
IEC 60870-5-104 p o ocol. We ha e iden i ied h ee
main asks o accomplish he a ic econs uc ion:
•Clean he cap u e o e ansmi ed packe s and
ea ange ou -o -o de packe s.
•Iden i y logical dependencies be ween applica ion
messages and i necessa y o eo de hese mes-
sages.
•Es ima e ime when he pa icula applica ion
message was sen and ecei ed in con ex o i s
logical dependency.
The a ic gene a o model equi es ou pa ame-
e s o gene a e a pa icula , namely sende , message
leng h, o igina ing message causing gene a ion o he
message (logical dependency) and ela i e ime di e -
ence o i s o igina o a e which he message is o
be dispa ched ( ime dependency). Howe e , only he
leng h o messages and sende a e known di ec ly. Two
emaining pa ame e s ha e o be es ima ed as a esul
o he analysis in Sec ion 4.
3.1. Spli Communica ion Domain
E en hough a ic can be cap u ed in dis ibu ed
manne on in e aces o communica ing o in e con-
nec ing de ices, mos equen ly he cap u e is eco ded
only on a single in e ace o an in e connec ing ne wo k
de ice. This se up is common o ne wo k moni o ing
s a ions, o en in eg a ed in o egula ou e s, b idges,
e c. Cap u ing on he in e connec ing de ice, om now
on e e ed o as Moni o , always leads o a spli com-
munica ion domain. As is showed in Fig. 1, he spli
esul s in wo ne wo k segmen s, which a e con en ion-
ally called ups eam and downs eam depending on he
placemen o he TCP clien and se e in he ne wo k.
In ou case, he SCADA se e esides in he ups eam
segmen and RTU is in he downs eam pa h.
SCADA RTUMoni o
Downs eam
Bi-di ec ional
TCP s eam
Ups eam
Fig. 1: The communica ion domain is spli by he Moni o o
wo segmen s wi h dissimila ansmission condi ions a -
ec ing he RTT es ima ion.
Ha ing in o ma ion only om he Moni o , i is no
possible exac ly de e mine he end- o-end delay be-
ween bo h communica ing de ices. Mo eo e , due o
he na u e o ups eam and downs eam pa hs, whe e
he bandwid h can be dissimila , he adi ional pas-
si e RTT es ima ion is no enough o sa is y analysis
equi emen s. The RTT can a y signi ican ly du ing
he ime o he connec ion depending on local ansmis-
sion condi ions. As was men ioned be o e, TCP ex en-
sion is also no possible o use since many RTU s ill
implemen simple old TCP algo i hms. As he p ope
knowledge o a delay be ween RTU and SCADA is nec-
essa y o u he in es iga ion o TCP e ansmissions
and dispa ch imes, we ha e decided o implemen dy-
namic RTT- o-ACK es ima ion h oughou he whole
cap u e. The RTT- o-ACK is a ime in e al be ween
he TCP segmen and i s co esponding acknowledg-
men a e cap u ed a he Moni o . The algo i hm is
desc ibed in he analysis pa in Subsec ion 5.2.
3.2. TCP Re ansmissions
One o he main challenges in he TCP s eam econ-
s uc ion p oblem is o deal wi h TCP e ansmissions.
When he TCP e ansmission occu s, i dis up s he
o de ing o iming o da a a he applica ion laye . A
i s , o deal wi h e ansmissions, i is necessa y o
iden i y hem oge he wi h side e ec s accompany-
ing e ansmission om he Moni o pe spec i e, e.g.
duplica ed acknowledgmen s (DUP-ACK) and missing
segmen s. P ima ily, ollowing asks ha e o be sol ed
a anspo laye in bo h di ec ions be o e i he anal-
ysis o cap u ed da a o applica ion dependencies:
•Selec ion o e ansmi ed packe s o d op and o
keep o he u he analysis.
•Reo de ing o e ansmi ed ou -o -o de packe s.
•Selec ion o pai s o e ansmi ed packe and i s
duplica ed acknowledgmen o d op.
4. S eam-Speci ic Cons ains
We ha e in es iga ed se e al a ailable a ic cap u es
con aining dozens o TCP s eams o IEC 60870-5-104.
Since he TCP implemen a ion a RTUs is o en only
basic TCP Reno, he analysis is in some pa s imple-
men a ion speci ic. Main obse a ions esul ing om
he a ailable cap u es a e ollowing:
•No all s eams a e p ope ly s a ed by he SYN,
SYN-ACK, ACK sequence and p ope ly ended.
Some s eams s eams a e ime-ou ed.
•IEC 60870-5-104 messages a e no segmen ed by
TCP o mo e packe s.
•Mos o he cap u ed messages is di ec ly ollowed
by emp y acknowledgmen s.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 538
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
•Delayed acknowledgmen s a e a e.
•All ansmi ed messages has se up he TCP push
lag.
•Some s eams con ain e ansmissions o igina ed
in he applica ion laye .
A e e ansmissions we e iden i ied using exp es-
sions de ailed in Subsec ion 5.1. , i u ned ou ha
he da a o he applica ion laye a e a ec ed in ollow-
ing cases:
•F om he Moni o pe spec i e, a TCP segmen
was acknowledged be o e i s e ansmission oc-
cu s. This means ha he TCP segmen was suc-
cess ully ecei ed and an ACK was sen by he
ecei e , bu he ACK was los a e i passed he
Moni o . The sende e ansmi he packe a e
eaching he Re ansmission Timeou (RTO) wai -
ing o he ACK again. In such case, we simply
ake in o accoun only he i s occu ence o he
TCP segmen and d op all e ansmissions includ-
ing DUP-ACKs.
•The e is one o mo e e ansmissions de ec ed wi h
an ACK ollowing he e ansmission sequence.
The e ansmi ed TCP segmen was los a e i
passed he Moni o a leas once. In his case, i is
necessa y o decide which packe s o he sequence
a e o be d opped o accep ed. The selec ion p o-
cess is de ailed in Subsec ion 5.3.
•When TCP segmen wi h a sequence numbe
lowe han al eady passed segmen om he same
sende , i is conside ed o be ou -o -o de . In such
case, he i s packe was los be o e i passed he
Moni o . This ou -o -o de TCP segmen has o
be shi ed o di e en place in ime. The algo i hm
o he selec ion and ime shi p ocess is desc ibed
in Subsec ion 5.4.
Cases abo e co e ed all cases o e ansmissions oc-
cu ing in ou cap u ed da a which does no mean ha
hese co e all possible TCP s a es. Ou goal was o
deal wi h he iden i ied issues and no o p oduce a uni-
e sal ool o he TCP a ic econs uc ion. Due o
he al eady men ioned complexi y o wo inal s a e ma-
chines a wo p o ocol laye s we pos poned ad anced
ime shi s o ou u u e wo k. The main algo i hmic
pa s o he a ic econs uc ion p ocess a e desc ibed
in ollowing subsec ions.
5. Algo i hm Designs
The a ic econs uc ion p ocess is comp ised o se -
e al s eps. A i s , he cap u ed da a is eassembled o
a ma ix con aining pa ame e s o he ollowing analy-
sis. Subsequen ly, he e ansmi ed packe s a e iden-
i ied (Subsec ion 5.1. ), RTT- o-ACK is es ima ed
o bo h ne wo k segmen s (Subsec ion 5.2. ), e ans-
mi ed packe s o d op a e selec ed (Subsec ion 5.3. )
o eo de ed (Subsec ion 5.4. ), and e en ually he
dependencies be ween IEC 60870-5-104 messages a e
de ined (Subsec ion 5.5. ).
5.1. Iden i ica ion o Re ansmi ed
Packe s
We ha e inspi ed app oach in he wo k [1] and based
he e ansmission iden i ica ion on he de ec ion o
holes in sequence numbe s. Since he sequence num-
be s om bo h communica ion sides ha e o be mono-
onically inc easing wi h he numbe o sen by es, he
iden i ica ion o TCP segmen s s anding ou side o he
sequence is s aigh o wa d. The basic idea is depic ed
in Fig. 2.
Since necessa y da a was s uc u ed in o a ma ix,
we we e able o iden i y e ansmissions using basic
column ope a ions. A i s we il e ed packe s om a
ime o de ed se o packe s Eq. (1) o one di ec ion
depending on a sou ce po as in Eq. (2|) o he clien
side and in Eq. (3) o he se e side. Subsequen ly,
we il e ed ou h ee se s o packe s o each o he
communica ing sides. This il e is based on di e ence
o TCP sequence numbe s and leng hs o TCP segmen
in shi ed column as is exp essed in Eq. (4), Eq. (5)
and Eq. (6). Using his app oach, i is ob ained a se
o e ansmi ed packe s C e , a se packe s Cpnc whe e
he p e ious segmen was no cap u ed and inally a se
o DUP-ACKs Cdack. The same p ocess was applied on
he se e side packe s.
P={p0, p1...pn},
pc ime
i≤pc ime
i+1 ;i∈ h0; n−1i,(1)
C={p∈P|ps c =clien },(2)
S={p∈P|ps c =se e },(3)
,C e =C|(Csnum
i−(Csnum
i+1 +Cslen
i+1 ))<0,
i∈ h0; |C|i,(4)
Cpnc =C|(Csnum
i−(Csnum
i+1 +Cslen
i+1 ))>0,
i∈ h0; |C|i,(5)
Cdack =C|(Canum
i−Canum
i+1 =0)∧(Cslen
i=0)∧(C in
i6=1),
i∈ h0; |C|i.(6)
Each uppe index exp ess an a ibu e o he pa ic-
ula objec as ollows: pc ime s ands o packe ’s cap-
u ed ime, ps c is packe ’s sou ce IP add ess, Csnum is
TCP sequence numbe , Cslen is TCP segmen leng h,
Canum is TCP acknowledgmen numbe and C in
s ands o TCP FIN lag.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 539
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Time
Sequence numbe
Packe loss on he
way o Moni o
Packe loss on he
way om Moni o
Fig. 2: The undis u bed TCP sequence numbe ing should be
mono onically inc easing. De ec ing miss-o de ed se-
quence numbe s iden i ies TCP e ansmissions.
SCADA RTUMoni o
RTT o ACK X
RTT o ACK Y
RTT o ACK A
ACK X
ACK Y
SEG Y
ACK A
SEG A
SEG X
Time
Fig. 3: The RTT- o-ACK sequence o ime windows, whe e
g een windows a e o he downs eam and ed windows
a e o he ups eam.
5.2. RTT- o-ACK Es ima ion
Ha ing iden i ied he e ansmi ed packe , i is pos-
sible o compu e he RTT- o-ACK delay h oughou
he whole cap u e dynamically. I e a ing h ough he
cap u ed packe s, we simply compu e a ime di e ence
be ween a TCP segmen and i s ACK coming back
as a esponse o he sende when passing he Mon-
i o . The algo i hm skips iden i ied e ansmissions.
As he e was a g ea amoun o emp y ACKs, i.e. seg-
men s wi hou any payload, coming back om he e-
cei e in bo h di ec ions immedia ely a e he TCP
segmen s, we could limi he algo i hm only o such
RTT- o-ACK delays wi h emp y ACKs. This app oach
emo es an e o caused by he ime, which is needed
by he ecei e o p ocess he applica ion message.
The inal p oduc o he RTT- o-ACK is a sequence
o ime windows o bo h ups eam and downs eam
ne wo k segmen s. I can be in e p e ed as in he
Fig. 3. We did no in ol e packe leng hs in his
algo i hm, as mos o he packe s we e abou he same
leng h.
5.3. Selec ion om Re ansmi ed
Packe s
When he e a e one o mo e iden ical e ansmi ed
TCP segmen s cap u ed one by one and ollowed only
by an ACK, i is necessa y o decide o which o hem
he ACK was o iginally assigned. To deal wi h his
p oblem, we ook in o conside a ion he RTT- o-ACK
ime windows e lec ing condi ions on he ansmission
channel in he pa icula ime domain. Since he anal-
ysis is made o -line, i is possible o inco po a e no
only he ime windows be o e he e ansmission occu s
bu also hose om he u u e.
The Alg. 1 is based on he pa ame e -scaled RTT- o-
ACK ime window closes o he i s occu ence o he
e ansmission. The pa ame e σde e mine a numbe
o ime windows accep ed o a mean RTT- o-ACK.
This alue is subs i u ed om he ime when he ACK
was cap u ed and hen he closes o he e ansmi -
ed packe s is selec ed o u he analysis. O he s a e
d opped. The numbe o conside ed RTT- o-ACKs is
limi ed by τin ime and by pa ame e φin minimum
numbe o ime windows.
Algo i hm 1 Re ansmission selec ion.
Requi e: Se o e ansmi ed packe s R, RTT- o-
ACK imes RA ime o sende , σscaling ac o ,
τmax one side ime limi , φmin packe limi .
Ensu e: Index o he selec ed packe i.
1: RAcloses =min(|RA ime −R. i s ime|)
2: wini =RAcloses ·σ
3: RA =RA ∈((R. i s ime −wini ),(R.las ime +
wini ))
4: wRAs =RA.las ime −RA. i s ime
5: wτ= (R.las ime +τ)−(R. i s ime −τ)
6: i wRAs > wτ hen
7: RA =RA ∈wτ
8: end i
9: i |RA|< φ hen
10: RA =φcloses RA
11: end i
12: =ACKR
ime −mean(RA)
13: e u n i=minindex(| −R ime|)
5.4. Packe Reo de ing
In case he TCP segmen was los be o e i passed he
Moni o , he e ansmi ed one can be cap u ed o he
i s ime a e a segmen wi h highe sequence num-
be al eady passed he Moni o . The e ansmi ed
TCP segmen is o be placed in be o e he i s occu -
ence o he ollowing segmen , which cap u ed ime is
sou ce
p e . This is he only case whe e we a emp ed o
do a ime shi du ing he packe eo de ing. As i is
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 540

INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
easy o ind ou a minimal ime del a δsou ce
min be ween
wo consecu i e packe s om a common sende , we es-
ima ed he ime o he ou -o - he-o de TCP segmen
as sou ce
p e −δsou ce
min .
5.5. Message Dependencies
Finally, las wo algo i hms desc ibe he way a pa icu-
la IEC 60870-5-104 message depends on i s o igina ing
message in bo h ime and logical domain. A i s , i
is necessa y o es ima e he ime when a message was
sen and ecei ed on bo h communica ing sides. This
can be done again using a column shi me hod on a
newly c ea ed column in he o iginal ma ix. As we as-
sume ha bo h TCP he bi-di ec ional low is passing
he same cap u ing in e ace and he pa h in a ne wo k
is in bo h di ec ions symme ical, we o he simplici y
app oxima e he end- o-Moni o delay e m as a hal o
RTT- o-ACK which is closes o he in es iga ed TCP
segmen . The dispa ch ime o he message is hen es-
ima ed as d= cap − e m, whe e cap is a ime when
he TCP segmen was cap u ed (including he eo de -
ing). Simila ly, he ime o he message ecep ion is
es ima ed as = cap + e m.
The second s ep is o de e mine logical dependen-
cies be ween messages. Since he IEC 60870-5-104 uses
simila mechanism o TCP wi h sen / o- ecei e coun-
e s, he ela ions a e simply iden i ied o numbe ed
messages ( ype I). Howe e , he IEC 60870-5-104 does
con ain also unnumbe ed messages ( ype U) and supe -
iso messages (S). Fo his eason, we implemen ed a
simple decision algo i hm in Alg. 2.
Algo i hm 2 Message dependencies.
Requi e: In es iga ed message m. Se o cap u ed
messages M.
Ensu e: O igina ing message o.
1: α= (Ms c 6=ms c)∧(M cap < m cap )
2: i m ype == U hen
3: o=las (M|α)
4: end i
5: i m ype == S hen
6: o=las (M|α∧(M x=m x−1))
7: end i
8: i m ype == I hen
9: o= (M|α∧(M x=m x)∧max(M x))
10: end i
11: e u n o
Al hough he Alg. 2 always led o p ope esul s wi h
logical dependencies, i was necessa y o co ec some
esul s in he case o he ime dependencies. The ime
di e ence be ween he o igina o and i s successo s
scould gi e he o e lapping imes amps. Since he
message canno be sen be o e i s logical o igina o
was ecei ed, we ha e implemen ed ime ba ie s. In
case o he o e lapping imes, he ime di e ence o
he successo dispa ch ime is changed o ze o. Time
ba ie s a e also implemen ed o check es ima ed imes
agains cap u ed imes. As he message, depending on
he communica ing side, canno be ecei ed o sen be-
o e i was cap u ed. In such case, he dispa ch ime is
shi ed in he middle o ela ed cap u ed imes.
6. E alua ion
Each algo i hm desc ibed in p e ious Sec ion 5. was
in eg a ed in o a complex applica ion o analyze TCP
s eams om a eal-wo ld cap u e con aining he IEC
60870-5-104 communica ion. Since i was no possible
o e i y he p oposed app oach on a cap u e om he
unde ined ne wo k opology wi hou exac in o ma ion
om bo h communica ing sides, we decided o base
he e alua ion on simula ions. The e alua ion ocuses
mainly on he domain o ime dependencies.
The simula ion model was designed as an indus ial
ne wo k wi h a poin - o-poin low-bandwid h channel
o eleme ic ope a ions. E en hough he channel is
usually bu dened wi h high Bi E o Ra e (BER) in
such se ups, i is o en sha ed by mo e TCP s eams
in pa allel. The ne wo k model depic ed in Fig. 4
consis s o wo connec ion ypes. Fi s one, which
is placed be ween Moni o and Rou e s, is a low-
bandwid h channel wi h bandwid h 14 kbps and BER
10−4. The second one, placed be ween Rou e s and end
de ices, is he s anda d Fas E he ne wi h bandwid h
100 Mbps and BER 10−10. The payload o inspec ed
TCP s eams was designed acco ding o pa e ns ound
in he eal-wo ld cap u ed IEC 60870-5-104 a ic. In
ou scena ios, he connec ion was always ini ia ed om
RTU sending bulk applica ion da a [3] in p ede ined
imes owa ds he SCADA se e , which esponded a
leas by 6 by es o applica ion da a wi h p obabili y
a ying om 0.3 o 0.5. To make he simula ion mo e
ealis ic, we loaded sha ed links by 5 concu en TCP
s eams ans e ing andom block da a. Each simula-
ion scena io was epea ed one hund ed imes.
The analysis is based on h ee cap u es p oduced
on SCADA, RTU and Moni o a each simula ion un.
All cap u es we e eco ded a de ices wi h absolu ely
synch onized sys em imes, and hus, cap u e ime o
each cap u ed ame had he same ini ial ime poin .
Following es ima ions a e based clea ly on he cap u e
om he Moni o , as in he eal-wo ld case. Remain-
ing cap u es we e used only o compa ison pu poses.
Resul s cha ac e izing TCP s eams a e shown in
Tab. 1. As one can see, he TCP s eam leng h is
a ying signi ican ly o di e en s eams. This is due
he se e al ac o s. A i s , he cap u e i sel had lim-
i ed leng h, and a second, some s eams we e du ing
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 541
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
Fig. 4: Simula ion opology o indus ial ne wo k wi h low-
bandwid h connec ions be ween Rou e s and Moni o .
he cap u ing disconnec ed and epea edly es ablished.
I is also no able ha a o al numbe o packe s is in
some case almos wo imes highe han he o al num-
be o ans e ed applica ion messages (RTU and SCD
messages).
Tab. 1: Rounded mean alues cha ac e izing TCP s eams.
Id Leng h
[s]
To al
pck s.
[-]
Re-
o de
[-]
D op
[-]
RTU
msg.
[-]
SCD
msg
[-]
8 6352 2680 10 69 1073 420
10 2634 406 3 33 87 49
12 1498 419 4 18 163 86
13 1832 298 4 15 102 48
17 4352 1080 12 52 386 126
A i s , we ocused on a ime di e ence be ween
wo messages ep esen ing a SCADA con ol command
and RTU esponses, and ice e sa. As he simula ed
da a had no logical dependency de ined a he applica-
ion laye , we ha e de e mined he o igina o , i.e. he
message causing dispa ch o applica ion igge ed mes-
sages, as he closes TCP segmen wi h non-ze o leng h
and acknowledgmen numbe lowe han message o be
dispa ched. Due o his s ep, all messages had o igi-
na o p eceding hei dispa ch ime which co ela es
wi h he obse ed beha io o he IEC 60870-5-104
p o ocol. The esul s o de ia ions be ween es ima ed
and eal ime di e ences ob ained om simula ions a e
depic ed in Fig. 5a. I we compa e he mean de ia ion
o he pa icula TCP s eam wi h he eal- ime di e -
ence be ween messages showed in Fig. 5b, we can ind
ha he ela i e de ia ion is up o 4 %. This is an
accep able le el o mos simula ion pu poses.
A Second, we a emp ed o e alua e an end- o-end
delay as a second p oduc o he ime es ima ions based
on he dynamic RTT- o-ACK e alua ion. Al hough
his is no di ec ly ela ed o he p oduced a ic
desc ip ion o he a ic gene a o , i illus a es he
accu acy o he p oposed app oach. Resul s showing
de ia ions be ween he es ima ed and eal end- o-end
delays a e depic ed in Fig. 6a. I we compa e hose
esul s wi h a co esponding mean end- o-end delays
showed in Fig. 6, we can see ha he ela i e de ia-
ion eaches 12 % in wo s case. E en hough his is a
highe numbe han in he case o ime dependencies,
i is s ill ole able in he scope o his a icle.
8 10 12 13 17
S eam numbe [-]
0.7
0.8
0.9
1.0
1.1
De ia ion be ween es ima ed and eal ime di e ence [s]
(a) De ia ion be ween es-
ima ed and eal imes
di e ences.
8 10 12 13 17
S eam numbe [-]
0
50
100
150
200
250
Real ime di e ence [s]
(b) Time di e ences be-
ween an o igina o
igge ed messages.
Fig. 5: Compa ison o eal ime di e ences be ween o igina o
and dispa ched messages ob ained om end de ices de-
pic ed in Fig. 5b wi h hei de ia ion showed in Fig. 5a.
A ed line s ands o mean alue, a blue box shows i s
and hi d qua ile and whiske s a e placed on 5 % and
95 % bo de s.
8 10 12 13 17
S eam numbe [-]
0.00
0.05
0.10
0.15
0.20
0.25
0.30
0.35
De ia ion be ween es ima ed and eal end- o-end delay [s]
(a) De ia ion be ween
end- o-end delays.
8 10 12 13 17
S eam numbe [-]
0.35
0.40
0.45
0.50
0.55
0.60
0.65
0.70
0.75
0.80
Real end- o-end delay [s]
(b) Real end- o-end delay
in bo h di ec ions.
Fig. 6: De ia ion o eal end- o-end delays and es ima ed end-
o-end delays in Fig 6a shows he accu acy o he p o-
posed app oach in compa ison o eal end- o-end delays
analyzed in bo h di ec ions and depic ed in Fig. 6b.
7. Conclusion
The a ic gene a o s used in simula ion en i onmen s
o en su e by an insu icien eal-wo ld a ic sou ces.
Due o his eason, we decided o c ea e an analyze o
he IEC 60870-5-104 p o ocol wi h he goal o syn he-
size a cap u ed a ic o o m a desc ip ion ile, which
can be used as an inpu o a ic gene a o s. P oposed
algo i hms show a possible way how o deal wi h he
econs uc ion o he o iginal applica ion da a om an
impai ed TCP s eam.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 542
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
The p esen ed app oach, which is based on he dy-
namic e alua ion o he RTT- o-ACK delay, p o ed i s
usabili y when es ima ing ime dependencies o gen-
e a ed applica ions messages. Simula ion esul s show
ha he ela i e de ia ion be ween es ima ed and eal
end- o-end delays eaches up o 12 %. E en mo e
encou aging esul s we e ob ained in case o ela i e
de ia ion be ween es ima ed and eal ime di e ences
eaching in a e age only 4 % a in es iga ed TCP
s eams.
Since we unde s and ha he analysis is now limi ed
o he speci ic TCP implemen a ion, we plan o ex end
i o o he implemen a ions and o e i y ou esul s
in he ield as well.
Acknowledgmen
This wo k was suppo ed by g an
no. VG20132015104, and by g an no.
SGS13/200/OHK3/3T/13.
Re e ences
[1] BENKO, P. and A. VERES. A passi e me hod o
es ima ing end- o-end TCP packe loss. In: Global
Telecommunica ions Con e ence 2002 (GLOBE-
COM ’02). Taipei: IEEE, 2002, pp. 2609–
2613. ISBN 0-7803-7632-3. DOI: 10.1109/GLO-
COM.2002.1189102.
[2] GEYER, F., S. SCHNEELE and G. CARLE.
RENETO, a ealis ic ne wo k a ic gene a o o
OMNeT++/INET. In: P oceedings o he 6 h In-
e na ional ICST Con e ence on Simula ion Tools
and Techniques. B ussels: ICST, 2013, pp. 73–81.
ISBN 978-1-4503-2464-9.
[3] HEGR, T. Simula ion pa e ns o he RTU a ic.
2015.
[4] IEC 60870-5-104. T ansmission p o ocols-Ne wo k
access o IEC 60870-5-101 using s anda d ans-
po p o iles. Gene a: IEC, 2006.
[5] JIANG, H. and C. DOVROLIS. Passi e es ima-
ion o TCP ound- ip imes. ACM SIGCOMM
Compu e Communica ion Re iew. 2002, ol. 32,
iss. 3, pp. 75–88. ISSN 0146-4833.
[6] LEON-GARCIA, A. and I. WIDJAJA. Com-
munica ion ne wo ks: undamen al concep s and
key a chi ec u es. Bos on: McG aw-Hill, 2000.
ISBN 00-702-2839-6.
[7] LU, G. and X. LI. On he co espondency be-
ween TCP acknowledgmen packe and da a
packe . In: P oceedings o he Con e ence on In-
e ne measu emen - IMC ’03. New Yo k: ACM
P ess, 2003, pp. 259–272. ISBN 1-58113-735-4.
DOI: 10.1145/948205.948239.
[8] SCHIAVONE, M., P. ROMIRER-
MAIERHOFER, F. RICCIATO and A. BAIOC-
CHI. Towa ds Bo leneck Iden i ica ion in Cellula
Ne wo ks ia Passi e TCP Moni o ing. Ad-hoc,
Mobile, and Wi eless Ne wo ks. 2014, ol. 8487,
no. 1, pp. 72–85. ISBN 978-3-319-07424-5.
DOI: 10.1007/978-3-319-07425-2_6.
[9] STROWES, S. D. Passi ely Measu ing TCP
Round- ip Times. Queue - High- equency T ad-
ing. 2013, ol. 11, iss. 8, pp. 50–61. ISSN 1542-
7730. DOI: 10.1145/2523426.2539132.
[10] VARGA, A. The OMNeT++ Disc e e E en Sim-
ula ion Sys em. In: P oceedings o he Eu-
opean Simula ion Mul icon e ence (ESM’2001).
P ague: ESM, 2001, pp. 1–65. ISBN 1-56555-225-
3.
[11] VISHWANATH, K. V. and A. VAHDAT. Real-
is ic and esponsi e ne wo k a ic gene a ion.
In: P oceedings o he 2006 con e ence on Applica-
ions, echnologies, a chi ec u es, and p o ocols o
compu e communica ions (SIGCOMM ’06). New
Yo k: ACM P ess, 2006, pp. 111–122. ISBN 1-
59593-308-5. DOI: 10.1145/1159913.1159928.
[12] HAIJIN, Y., K. LI, S. WATTERSON and D.
LOWENTHAL. Imp o ing passi e es ima ion o
TCP ound- ip imes using TCP imes amps.
In: P oceedings o IEEE In e na ional Wo k-
shop on IP Ope a ions and Managemen . Bei-
jing: IEEE, 2004, pp. 181–185. ISBN 0-7803-8836-
4. DOI: 10.1109/IPOM.2004.1547614.
[13] RFC 793: T ansmission Con ol P o ocol. In-
e ne Enginee ing Task Fo ce (IETF) [online].
1981. A ailable a : h p://www.ie .o g/
c/ c793. x .
[14] RFC 1323: TCP Ex ensions o High Pe o -
mance. In e ne Enginee ing Task Fo ce (IETF)
[online]. 1992. A ailable a : h p://www.ie .
o g/ c/ c1323. x .
Abou Au ho s
Tomas HEGR ecei ed his M.Sc. in compu e
science a he Czech Technical Uni e si y in P ague
in 2012. He pa icipa es in eaching ac i i ies a he
depa men o Telecommunica ion enginee ing. His
esea ch in e es s in ol e indus ial ne wo ks based
on E he ne and So wa e-De ined Ne wo king in all
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 543
INFORMATION AND COMMUNICATION TECHNOLOGIES AND SERVICES VOLUME: 13 |NUMBER: 5 |2015 |DECEMBER
esea ch a eas.
Leos BOHAC ecei ed he M.Sc. and Ph.D.
deg ees in elec ical enginee ing om he Czech
Technical Uni e si y, P ague, in 1992 and 2001,
espec i ely. Since 1992, he has been eaching op ical
communica ion sys ems and da a ne wo ks wi h he
Czech Technical Uni e si y, P ague. His esea ch
in e es is on he applica ion o high-speed op ical
ansmission sys ems in a da a ne wo k.
c
2015 ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING 544