Closed Solicitation · DEPARTMENT OF ENERGY

    OPEN SOURCE SOFTWARE: ICSNPP: ADVANCED INDUSTRIAL CONTROL SYSTEM PROTOCOL PARSING FOR ZEEK

    DEPARTMENT OF ENERGY
    Special NoticeIdaho Falls, ID
    Closed
    STATUS
    Closed
    closed Mar 15, 2026
    POSTED
    Oct 31, 2024
    Publication date
    NAICS CODE
    518210
    Primary industry classification
    PSC CODE
    DJ01
    Product & service classification

    AI Summary

    The Department of Energy has announced a special notice for the ICSNPP (Industrial Control System Network Protocol Parsers) project, which focuses on advanced industrial control system protocol parsing for the Zeek network security monitoring framework. This initiative, funded by DHS/CISA, aims to enhance the security of industrial environments increasingly targeted by cyber threats. The ICSNPP suite includes Zeek plugin protocol parsers specifically designed for four major ICS protocols: BACnet, DNP3, Ethernet/IP, and Modbus, with plans for further expansion. The project emphasizes detailed protocol analysis, providing in-depth insights into ICS communications for improved monitoring and incident

    Contract details

    Notice Type
    Special Notice
    Posted Date
    October 31, 2024
    Response Deadline
    March 15, 2026
    NAICS Code
    518210AI guide
    PSC / Class Code
    DJ01
    Contract Code
    8900
    Primary Contact
    Andrew Rankin
    State
    ID
    ZIP Code
    83415
    AI Product/Service
    service

    Description

    Open Source Software: ICSNPP: Advanced Industrial Control System Protocol Parsing for Zeek

    In an era where industrial control systems (ICS) are increasingly targeted by sophisticated threats, ensuring robust network security is paramount. ICSNPP (Industrial Control System Network Protocol Parsers) emerges as a critical solution, providing an advanced protocol parser suite that integrates seamlessly with the Zeek network security monitoring framework.

    The evolution of cyber threats targeting industrial environments necessitated the development of specialized tools capable of understanding and monitoring the unique protocols these systems use. DHS/CISA funded ICSNPP to address this gap, enhancing hunt and incident response capabilities within ICS environments. This project aims to bolster the security of CISA's network sensors and democratize access to this advanced technology by making it open-source on GitHub.

    ICSNPP is a collection of Zeek plugin protocol parsers tailored for the industrial control sector. It currently supports four major ICS protocols: BACnet, DNP3, Ethernet/IP, and Modbus, with expansion plans. Unlike general Zeek protocol parsers, ICSNPP delves into the intricacies of ICS communications, offering detailed insights into network activities. This enables more effective monitoring, threat detection, and incident response in critical infrastructure networks.

    Advantages:

    • Detailed Protocol Analysis: Unmatched depth in parsing ICS-specific protocols for comprehensive network visibility.
    • Quick and Easy Integration: Installs in less than 5 minutes, immediately enhancing security monitoring capabilities.
    • Open-Source Accessibility: Freely available for use and contribution, fostering a community-driven approach to ICS security.
    • Proactive Threat Hunting: Facilitates advanced threat detection and response tailored to the unique environments of industrial control systems.
    • CISA-Tested Reliability: Undergoing rigorous testing by CISA to ensure effectiveness and reliability in real-world scenarios.

    Applications:

    • Energy Sector: Optimize renewable energy integration with enhanced network security and monitoring.
    • Manufacturing: Secure manufacturing processes by ensuring the integrity and availability of ICS networks.
    • Water Treatment Facilities: Protect critical water treatment operations through advanced network threat detection.
    • Critical Infrastructure: Enhance the resilience of critical infrastructure by improving visibility into network activities and threats.

    Elevate your industrial control system's security posture with ICSNPP. Visit our GitHub page to download the plugin suite, contribute to its development, or learn how it can transform your network security and incident response capabilities.

    INL’s Technology Deployment department focuses exclusively on licensing intellectual property and partnering with industry collaborators capable of commercializing our innovations. Our goal is to commercialize the technologies developed by INL researchers. We do not engage in purchasing, manufacturing, procurement decisions, or providing funding. Additionally, this is not a call for external services to assist in the development of this technology.

    Key dates

    1. October 31, 2024Posted Date
    2. March 15, 2026Proposals / Responses Due

    AI search tags

    Frequently asked questions

    OPEN SOURCE SOFTWARE: ICSNPP: ADVANCED INDUSTRIAL CONTROL SYSTEM PROTOCOL PARSING FOR ZEEK is a federal acquisition solicitation issued by DEPARTMENT OF ENERGY. Review the full description, attachments, and submission requirements on SamSearch before the response deadline.

    SamSearch Platform

    Stop searching. Start winning.

    AI-powered intelligence for the right opportunities, the right leads, and the right time.