The Most Dangerous IEC 104 Packet May Be Perfectly Valid

Where AI fits between IEC 62351, traditional IDS, and real-world power-grid security.

In enterprise networks, suspicious behavior is often relatively easy to describe. A user authenticates from an unusual location, a workstation suddenly communicates with hundreds of systems, or a server begins transferring an unexpected volume of data.

Operational Technology is different.

Consider an IEC 60870–5–104 environment. A packet may arrive from an approved HMI, over an expected TCP connection, using a completely valid IEC 104 ASDU. The firewall allows it. The protocol parser accepts it. A signature-based IDS sees nothing obviously malicious.

Yet the command may still be wrong.