Published 03 Mar 2021

Parallel Reference Monitoring

HMI’s Can be Fooled!
Detect anomalies before they damage your critical assets. SIGA’s Parallel Reference Monitor (PRM) provides multi-level real-time monitoring, revealing otherwise undetectable Level-0 attacks

BACKGROUND
Current security methods for industrial control systems are beginning to evolve and include network-level security, some use of firewalls, unidirectional diodes and protected gateways. This vulnerability and common operational constraints lead to very limited solutions, at best. Therefore, the SCADA’s controller level, or Level 1 as it is called in the Purdue Model (e.g., PLC, RTU, etc.) can be compromised in various scenarios.

 

An attacker has taken control of a critical process while a perfectly normal operational status is reflected on the HMI and other levels. The attack is allowed to continue undetected because the control system’s Level 1 (and above) monitoring devices are blind to what is happening at Level 0 (the physical layer).

THE SOLUTION: PRM

SIGA’s Parallel Reference Monitoring (PRM) product augments SIGA’s critical process monitoring solution by comparing on one screen what operators are seeing at the HMI and other layers with what’s actually happening at the end-device layer — and alerting the operators to any discrepancies.

Any inconsistency between the Level-0 status and that of the network levels is a red flag that a hacker may be spoofing the HMI and that an attack is already underway—unbeknownst to the operator.

How does PRM Work?

SIGA’s algorithmic engine continually compares SIGA’s Level-0 sensor/actuator measurements with the values transferred between the PLC and the HMI, while factoring in synchronization issues like delays in communication, differing sampling rates, etc. SIGA generates an alert when it detects any deviation between the two values for the same I/O at the same time.

Once there is a deviation between the values, an alert will be triggered and displayed on the SIGA alerts screens.


Protecting the Process Layer of Critical Infrastructure with an unhackable source of truth
Our blog

Lastest blog posts

Tools and strategies to keep your infrastructure safe.

A Process Oriented Upgrade to Obsolete Incident Response Plabyooks

18 June 2026

In Operational Technology (OT) environments, Incident Response (IR) timelines are measured against operational uncertainty. The longer it takes to determine whether cyber...

Data Centers Harden IT. CPS Remains Soft

04 June 2026

Data center infrastructure is built for resilience. Power, cooling, and physical security systems are tightly engineered to keep operations running, even under...

Recent Lesson from Warfare: Process Integrity Part of the Battleground

16 April 2026

As documented in Advisory AA26-097A, kinetic warfare now extends to critical infrastructure. When adversaries can manipulate the very data operators use to...