Skip to content

Industrial Detection and Protection

L2Proxy evaluates the industrial meaning of traffic, not only the existence of a network connection. Protection can be applied to one message or to a sequence of operations that develops over time.

Purpose and expected outcome

This section explains what L2Proxy can evaluate and protect. After reading it, the customer should understand the difference between single-operation and stateful protection, the available outcomes, how protocol portfolios are organized, and what must be qualified before blocking production traffic.

Two complementary protection models

Model Best suited to Example
Stateless rule A decision that can be made from the current message and equipment context Block a setpoint outside the approved engineering range
Stateful protection A decision that depends on sequence, prior authorization, timing, feedback, or role Accept Operate only after a matching Select and consume the authorization once

Raymon stateful protection model for industrial protocol and context awareness

Figure — Stateful protection overview: protocol state, context, sequence validation, and evidenced decisions.

Both models use explicit, ordered, reviewable policies and can record, accept, or block the observed operation.

What can be evaluated

  • protocol function and operation;
  • source, destination, device, equipment, and point;
  • measurement, state, control code, or requested setpoint;
  • approved ranges, states, commands, and prerequisites;
  • command sequence and timing;
  • prior authorization and one-time consumption;
  • feedback after command;
  • authenticated user, access domain, and live session when L2Proxy Connect is used;
  • equipment role, maintenance state, and recovery context;
  • repeated events, bursts, and timeouts.

Industrial protection outcomes

Outcome Purpose
Record Preserve an observation or deviation without interrupting traffic
Allow Explicitly permit an operation that satisfies the approved policy
Block Stop an operation that violates the approved policy
Track state Remember bounded, time-limited context needed for the next decision

Representative industrial cases

  • breaker and recloser command restrictions;
  • transformer and regulator setpoint protection;
  • DNP3 Select-Before-Operate enforcement;
  • command-to-feedback verification;
  • protection trip, acknowledge, clear, and reset sequence;
  • controlled maintenance authorization;
  • active and standby master enforcement;
  • device restart and recovery monitoring;
  • alarm lifecycle and chattering detection;
  • process interlocks across valves, pumps, or related assets.

Controlled adoption

Candidate protections can first record deviations during commissioning or be evaluated against recorded traffic. Blocking is enabled after representative normal, abnormal, timeout, replay, and recovery cases have been reviewed and approved.

Protocol protection portfolios

The Rule Engine, stateful framework, evidence model, and deployment paths are shared platform capabilities. Each industrial protocol can therefore be presented as its own customer portfolio containing:

  • protocol-aware operations and equipment context;
  • supported stateless and stateful protection patterns;
  • representative industrial use cases;
  • complete, reviewed policy examples;
  • event and decision examples;
  • protocol-specific qualification guidance.

DNP3 is the first protocol portfolio presented in depth in this catalog. Additional protocol portfolios can be added as peers without changing the product structure or creating separate policy engines.

Continue with the Industrial Rule Engine, L2Proxy Connect, or Stateful Detection.