Design and Simulation of a Hardware Firewall for Protecting Industrial Control Systems in Oil and Gas Facilities in Rivers State

📖 ABSTRACT/OVERVIEW

Industrial control systems at oil and gas facilities in Rivers State, South South Nigeria, are increasingly targeted by cyber attacks that exploit the convergence of IT and OT networks, and dedicated hardware firewall protection for these systems is urgently needed. This project designed and simulated a hardware firewall specifically tailored for Modbus TCP-based industrial control system traffic using an FPGA-based packet classification engine. The firewall was modelled using Vivado Design Suite on a Xilinx Artix-7 FPGA, implementing a stateless packet filter that applied Modbus function code whitelisting, IP address allowlisting, and rate limiting rules in hardware. Traffic pattern simulation was generated using a custom Python script mimicking SCADA polling traffic, and attack scenarios including Modbus command injection and replay attack packets were injected. The hardware classifier processed packets at 1 Gbps line rate with a packet latency of 180 nanoseconds. Malicious Modbus command injection packets were blocked in 100 percent of test cases. Replay attack sequences were detected and dropped with a 97.4 percent accuracy rate. False positive rate for legitimate traffic was 0.6 percent, meeting industrial control system availability requirements. Resource utilisation on the Artix-7 was 34 percent of available LUTs. Power consumption at full throughput was 1.1W. The study recommends implementing the hardware firewall as a security-hardened PLC gateway module and pursuing evaluation against IEC 62443 industrial cybersecurity standards.

Keywords: hardware firewall, industrial control systems, FPGA, OT security, Rivers State

Need Complete Chapters of the Above Topic?

Get high-quality, Zero-AI research materials with current citations.

Request via WhatsApp 💬