Research units A-Z

Programmable Network Architectures for OT Digital Resilience

The most recent fully programmable data plane technology – eBPF – has enabled, among other use cases, highly scalable network softwarisation architectures. Previous approaches, such as software-defined networking (SDN) and P4, offered some degree of programmability, but required specialised target devices, largely tailored for high-performance data center environments. With eBPF, more complex network functions can be supported even on smaller form-factor and lower-capacity devices, making it a suitable network softwarisation framework for Operation Technology (OT) networks.

This research theme explores how such architectures can accelerate resilience functions in-network, transparently to industrial end devices. These functions include asset discovery, network segmentation, (D)DoS mitigation, and in-network protocol encryption. Our experiments show that these functions can meet strict real-time latency requirements and in-line performance constraints, and can be centraly orchestrated and deployed in a zero-touch fashion.

 

                                          Figure: eBPF-based programmable network architecture for OT digital resilience

Publications