Badgerboard: Weaseling Out The Unknown
Carl Hurd
S4x24 - ICS Security Conference · Day 3 · Main Stage
Overview
In the realm of Industrial Control System (ICS) security, a persistent blind spot has long hindered effective threat detection: the internal communications within Programmable Logic Controllers (PLCs). Carl Hurd's talk, "Badgerboard: Weaseling Out The Unknown," presented at S4, delves into this critical visibility gap and proposes a novel approach to bridge it. The research, conducted by Hurd and his colleague Jared Riddle at Talos (Cisco), introduces the concept of Badgerboard, an ambitious project aimed at gaining unprecedented insight into the proprietary backplane networks that interconnect PLC modules.

Key moments
- 0:00 Introduction to Badgerboard and its research background
- 1:45 Maturity and limitations of current OT security tools
- 3:15 Critical lack of visibility into PLC backplane communications
- 3:45 Benefits of a retrofit visibility module for current systems
- 4:30 Major challenges: undocumented protocols and vendor lock-in
- 5:25 Leveraging Sandia National Labs' Weasel Board research
- 5:50 Enormous effort to understand proprietary backplane networks
Badgerboard: Weaseling Out The Unknown
Speakers: Carl Hurd, Vulnerability Researcher, Talos (Cisco)
Conference: S4
YouTube: https://www.youtube.com/watch?v=5an8N-tx2zg
Overview
In the realm of Industrial Control System (ICS) security, a persistent blind spot has long hindered effective threat detection: the internal communications within Programmable Logic Controllers (PLCs). Carl Hurd's talk, "Badgerboard: Weaseling Out The Unknown," presented at S4, delves into this critical visibility gap and proposes a novel approach to bridge it. The research, conducted by Hurd and his colleague Jared Riddle at Talos (Cisco), introduces the concept of Badgerboard, an ambitious project aimed at gaining unprecedented insight into the proprietary backplane networks that interconnect PLC modules.
The significance of this work cannot be overstated. While the OT security landscape has matured considerably in recent years, with a proliferation of vendors offering asset inventories and passive network monitoring solutions, true innovation in deep-level visibility has lagged. This presentation highlights that current approaches often treat PLCs as monolithic black boxes, despite their internal architecture resembling complex switched networks. Badgerboard seeks to retroactively secure the vast installed base of operational PLCs, offering a practical solution for today's industrial environments rather than solely focusing on future, more secure architectures.
By challenging the status quo of limited visibility within ICS, Badgerboard addresses a fundamental vulnerability that adversaries could exploit with impunity. The talk emphasizes that in IT networks, a lack of visibility behind a network switch would be unacceptable, yet this is precisely the reality in many OT deployments. Hurd's research, building upon prior work like Sandia National Labs' Weasel Board, aims to equip defenders with the tools to "see more" within these critical systems, ultimately enhancing the resilience and security of industrial operations against sophisticated cyber threats.
Background
▶ Watch: Introduction to Badgerboard and its research background (0:00)
The journey into the "unknown" of PLC backplanes is rooted in a historical perspective on Industrial Control System security. Carl Hurd began by reflecting on his work six years prior at Idaho National Lab, where he co-authored a paper on the general state of ICS security tooling. At that time, the OT security market was nascent, and the paper served as a crucial reference for organizations seeking to understand available solutions, their capabilities, and expected success rates – largely based on vendor self-reporting. While that document was highly useful in its era, Hurd notes that the industry has since matured significantly, with a greater number of vendors and more sophisticated offerings. However, this maturity has predominantly focused on asset inventories and passive network monitoring, which, while valuable, still leave critical gaps.
The core problem identified is the lack of deep visibility into the internal workings of PLCs. Hurd states that "all of these PLCs are effectively routers and switches with multiple modules on the back plane that communicate to each other and we have absolutely no visibility into what's happening." This is a stark contrast to modern IT networks, where comprehensive visibility down to the host level is considered a baseline requirement. In OT, security tools typically monitor network traffic flowing to and from the PLC, but not within it, effectively treating the entire PLC as a single, opaque entity. This blind spot allows potential adversaries to operate undetected once they've gained a foothold inside the PLC's internal network.
The motivation for Badgerboard stems from a desire to push beyond these limitations. Hurd and his team at Talos, known for their work on Snort (Cisco's open-source network intrusion detection and prevention system), explored the concept of a "visibility IDS or IPS module." The goal was to extend Snort's capabilities to "see more" and get "closer to the root of truth" on OT networks. A crucial aspect of this vision was that such a module should be "easily retrofit into current installations," acknowledging that the vast majority of PLCs in the field today will remain operational for decades, making solutions focused solely on future, more secure PLC designs impractical for immediate security needs.
The research is not entirely unprecedented. Hurd acknowledges standing "on the shoulders of giants," specifically referencing the Weasel Board project that emerged from Sandia National Labs. The Weasel Board was pitched as a zero-day exploit detection device for PLCs, focusing on the Allen Bradley ControlLogix 5000 backplane and the Siemens S7 300 backplane. However, even that groundbreaking work highlighted the immense difficulty of understanding these internal networks. Hurd sarcastically notes that the Sandia document contained "four entire paragraphs" about how backplane networks operate, underscoring the "enormous" amount of work required to understand pins, functions, capture digital logic, and lift it into an analyzable state. This prior research confirmed the technical feasibility but also the significant challenges of interacting with these highly proprietary and undocumented internal systems.
Key Findings
▶ Watch: Critical lack of visibility into PLC backplane communications (3:15)
The central finding of the Badgerboard research is the identification of a significant, yet addressable, visibility gap within Industrial Control Systems: the internal communications of PLC backplanes. While the OT security industry has matured, its focus on external network monitoring leaves internal PLC module-to-module traffic largely unobserved. This creates a critical blind spot that Badgerboard aims to illuminate.
A crucial realization during the research was the inherent difficulty in developing a commercial, third-party solution for backplane monitoring. Hurd explicitly states, "most of these vendor back planes are walled gardens. You have service contracts that guarantee that there's no way an end user would plug in a third-party product into their back plane, without major repercussions from the vendor that they purchased from." This finding highlights a significant barrier to entry for innovative security solutions and underscores the necessity for either vendor cooperation or a highly discreet, non-invasive approach. Despite this commercial infeasibility, the team at Talos decided to pursue the research anyway, recognizing the paramount security need.
Technically, a key finding relates to the nature of PLC backplanes themselves. Hurd clarifies that the backplane "is a layer two switch, but it is not a complete hub in terms of not everybody sees everything unless you follow that ARP poisoning step and then you can see data from the other modules." This distinction is vital. If a backplane were a simple hub, all modules would see all traffic, making passive sniffing relatively straightforward. As a layer two switch, however, traffic is directed only to its intended recipient, significantly complicating passive monitoring. This finding directly points to ARP poisoning as a potential technique to overcome the switched nature of the backplane and force traffic through the monitoring device, thereby gaining the desired visibility.
Furthermore, the research confirms the persistent challenge of dealing with undocumented, proprietary protocols. Hurd mentions that "there's many, many vendors with many, many protocols, none of which are documented publicly." This necessitates extensive reverse engineering efforts to understand the underlying communication patterns, data structures, and functional commands exchanged between PLC modules. The sheer breadth of vendor-specific implementations makes a universal solution incredibly complex, requiring dedicated effort for each target platform. The project, therefore, is not just about hardware interception, but also about the painstaking process of protocol analysis.
Technical Deep Dive
▶ Watch: Benefits of a retrofit visibility module for current systems (3:45)
The technical underpinning of Badgerboard centers on penetrating the proprietary and largely undocumented internal networks of PLCs. The core challenge lies in the fact that these backplanes, which interconnect various modules such as processors, I/O cards, and communication interfaces, function as fully-fledged, albeit specialized, networks. As Carl Hurd clarified during the Q&A, a PLC backplane operates as a layer two switch, not a simple hub. This distinction is critical: in a switched environment, traffic is directed only to its intended destination, meaning a passively connected monitoring device would typically only see traffic addressed to it or broadcast traffic. This significantly complicates the goal of achieving comprehensive visibility into all module-to-module communications.
To overcome the switched nature of the backplane, the proposed technical approach involves ARP poisoning. In standard Ethernet networks, ARP poisoning is a technique where an attacker sends forged ARP messages to associate their MAC address with the IP address of another host, or with the default gateway. This causes traffic intended for the legitimate host or gateway to be redirected through the attacker's machine. In the context of a PLC backplane, if a similar mechanism can be implemented, the Badgerboard device could position itself as a man-in-the-middle, intercepting and logging traffic between legitimate PLC modules. This would allow the security module to "see data from the other modules" that it wouldn't otherwise observe. The success of this technique hinges on the backplane's internal protocol stack supporting ARP-like resolution mechanisms and being vulnerable to such manipulation.
The process of developing Badgerboard also involves an "enormous" amount of reverse engineering. This includes:
- Physical Interface Analysis: Identifying the specific pins on the backplane connectors, understanding their electrical properties (voltage levels, signaling types), and determining their function (data lines, clock signals, power, control lines). This often requires specialized hardware tools like logic analyzers and oscilloscopes.
- Digital Logic Capture: Once the physical interface is understood, the next step is to capture the digital signals exchanged between modules. This involves connecting to the relevant data lines and recording the raw bitstreams during normal operation of the PLC.
- Protocol Reverse Engineering: The captured digital logic then needs to be "lifted into a state that you can actually operate on." This is the most complex phase, involving the painstaking reconstruction of the proprietary communication protocols. This means identifying packet boundaries, message types, command codes, data fields, and checksums. Given that "none of which are documented publicly," this is a highly iterative process of observing patterns, making hypotheses, and testing them. The protocols likely vary significantly between different PLC vendors (e.g., Allen Bradley ControlLogix 5000 vs. Siemens S7 300, which were mentioned as targets for the Weasel Board).
- Integration with IDS/IPS: The ultimate goal is to integrate this newfound visibility into an Intrusion Detection System (IDS) or Intrusion Prevention System (IPS) like Snort. This would involve developing custom parsers and rules to identify anomalous or malicious traffic patterns within the backplane. For example, detecting unexpected commands, unusual data transfers, or unauthorized module interactions that could indicate a compromise or an attempt to manipulate industrial processes.
The very nature of backplane communication, often high-speed and real-time, adds another layer of complexity. The monitoring solution must be able to capture and process this data without introducing unacceptable latency or interfering with the critical timing requirements of industrial control. The fact that the backplane is a "walled garden" also implies that the solution must be physically robust and discreet, ideally designed to be minimally invasive to avoid voiding warranties or requiring extensive system modifications.
Demo / Proof of Concept
▶ Watch: Leveraging Sandia National Labs' Weasel Board research (5:25)
While Carl Hurd's talk provided a compelling conceptual framework for the Badgerboard project and detailed the significant technical challenges involved, it did not feature a live demonstration or a fully realized proof of concept of the Badgerboard device itself. The presentation focused more on the research journey, the problem statement, the inspiration from prior work like the Weasel Board, and the strategic vision for deeper OT network visibility.
Hurd mentioned that he and his co-worker, Jared Riddle, "spent a couple months working on this" and, despite concluding that a commercial third-party solution was "infeasible to develop" due to vendor "walled gardens" and service contracts, they "started on it anyways." This implies that Badgerboard is an ongoing research initiative, still in the developmental and exploratory phases of overcoming the identified technical hurdles, rather than a finished product ready for live demonstration. The discussion around the backplane being a layer two switch and the potential use of ARP poisoning to gain visibility points to theoretical approaches being explored, rather than a fully implemented and showcased interception method.
Therefore, the talk served more as a public unveiling of the research direction and its motivations, inviting discussion and collaboration on a critical, yet neglected, area of OT security. The absence of a physical demo does not diminish the significance of the problem identified or the innovative thinking behind the proposed solution. Instead, it highlights the early-stage, foundational nature of the work and the considerable effort still required to bring such a complex technical solution to fruition within the highly proprietary and sensitive environment of industrial control systems.
Defensive Implications
▶ Watch: Enormous effort to understand proprietary backplane networks (5:50)
The Badgerboard project, even in its conceptual and developmental stages, carries profound defensive implications for critical infrastructure and Industrial Control Systems. The primary benefit is the promise of unprecedented visibility into an area that is currently a major blind spot for most OT security solutions: the internal communications within PLC backplanes.
- Enhanced Threat Detection: By gaining insight into module-to-module traffic, defenders can detect anomalous behaviors that would otherwise go unnoticed. This includes unauthorized commands, unusual data transfers between internal components (e.g., a processor module attempting to communicate with an I/O module in an unexpected way), or attempts by an adversary to manipulate internal PLC logic directly. This moves detection capabilities much closer to the "root of truth" within the control system.
- Early Warning for Sophisticated Attacks: Advanced persistent threats (APTs) and nation-state actors targeting ICS often seek to establish persistent access and manipulate control logic at the deepest levels. Current external network monitoring may only detect the initial ingress or exfiltration. Badgerboard's ability to monitor internal backplane traffic could provide an early warning system for lateral movement or malicious activity occurring within the PLC itself, before it manifests as a physical disruption or compromise of the process.
- Improved Incident Response and Forensics: In the event of a compromise, the lack of internal PLC data significantly hampers incident response efforts. With Badgerboard, security teams would have access to granular logs of internal PLC communications, enabling more accurate root cause analysis, identification of compromised modules, and understanding of the attack's full scope and impact. This detailed telemetry is invaluable for effective recovery and preventing future incidents.
- Retrofitting Existing Infrastructure: A key defensive advantage highlighted by Hurd is that Badgerboard is designed to be "easily retrofit into current installations." This is crucial because the vast majority of operational PLCs are legacy systems that will remain in service for decades. Unlike "PLCs of tomorrow" solutions that require wholesale architectural changes, Badgerboard offers a path to enhance the security posture of existing, deployed assets without costly and disruptive upgrades. This extends the secure operational life of critical industrial equipment.
- Challenging Vendor Lock-in and Opacity: The research directly confronts the issue of "walled gardens" and undocumented proprietary protocols maintained by PLC vendors. While these practices protect vendor intellectual property, they inadvertently create security blind spots. Badgerboard, by reverse-engineering these systems, implicitly advocates for greater transparency and interoperability from vendors, or at least provides a means for end-users to gain necessary visibility independent of vendor support. This could empower asset owners to demand more secure and transparent systems.
- Integration with Existing Security Tools: The project's alignment with Snort signifies its potential to integrate with widely adopted security ecosystems. This means that the deep backplane visibility could feed into existing security information and event management (SIEM) systems, threat intelligence platforms, and security operations center (SOC) workflows, leveraging familiar tools and processes for OT security monitoring.
In essence, Badgerboard pushes the boundaries of OT security beyond passive network perimeters, offering a proactive and deep-seated approach to understanding and defending the very heart of industrial operations. It empowers defenders to move from simply detecting external attacks to understanding and mitigating threats that operate with surgical precision within the control system's core.
Key Takeaways
- Critical Visibility Gap: Current OT security tools, relying on asset inventories and passive network monitoring, lack crucial visibility into the internal communications of PLC backplanes, creating a significant blind spot for defenders.
- PLCs as Switched Networks: PLC backplanes operate as layer two switches, not simple hubs, meaning traffic is directed to specific modules. This complexity necessitates active interception techniques like ARP poisoning to gain comprehensive visibility.
- Badgerboard's Mission: The Badgerboard project, inspired by Sandia National Labs' Weasel Board, aims to develop a visibility module that can monitor and analyze internal PLC backplane traffic, extending the reach of tools like Snort.
- Proprietary Challenges: Gaining this deep visibility requires extensive reverse engineering of undocumented, proprietary protocols and physical interfaces, further complicated by vendor "walled gardens" and service contracts that restrict third-party access.
- Retrofit for Today's Systems: A core focus of Badgerboard is to provide a solution that can be "easily retrofit into current installations," addressing the security needs of the vast installed base of existing PLCs rather than solely focusing on future architectures.
- Enhanced Defensive Posture: By illuminating internal PLC communications, Badgerboard promises to enable earlier detection of sophisticated threats, improve incident response capabilities, and provide granular telemetry for forensic analysis, significantly strengthening the overall security posture of industrial control systems.
About the Speaker(s)
Carl Hurd is a Vulnerability Researcher at Talos, Cisco's threat intelligence group. Prior to his current role, Carl worked at Idaho National Lab, where he contributed significantly to the field of Industrial Control System (ICS) security. His earlier work included co-authoring a foundational paper six years ago on the general state of ICS security tooling, which served as a reference for understanding the nascent OT security landscape at the time. This background in both national lab research and commercial vulnerability analysis positions him uniquely to tackle complex challenges in critical infrastructure security.
Jared Riddle, Carl Hurd's co-worker at Talos, was also instrumental in the research presented in the "Badgerboard" talk. While not a primary presenter, his contributions to the project were acknowledged by Carl, highlighting the collaborative nature of the deep technical work involved in understanding and securing PLC backplanes.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Carl Hurd's presentation on Badgerboard tackles a critical, often-ignored blind spot in ICS security: the internal communications within PLC backplanes. This research proposes a technically ambitious and brutally honest approach to gain unprecedented visibility into these proprietary Layer 2 switched networks. While still an ongoing research effort without a live demonstration, the project's focus on deep reverse engineering, novel interception techniques like ARP poisoning, and its commitment to retrofitting existing infrastructure for enhanced threat detection makes it a highly valuable and pragmatic contribution to industrial defense. Hurd's directness about vendor 'walled gardens' and…
Heather Calloway (CISO) — STRONG ACCEPT
This research uncovers a critical and unacceptable blind spot in industrial control system security: the opaque internal communications within PLCs. By proposing a method to gain deep visibility into these proprietary backplanes, Badgerboard directly addresses a significant governance failure and offers a path to retroactively secure existing infrastructure. While still in development, the work highlights a fundamental business risk and provides clear implications for enhanced threat detection, incident response, and the imperative for asset owners to demand greater transparency from vendors.