Malmö University Publications
4546474849505148 of 825
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Development of a Wireshark Plugin for Analyzing Traffic of a Proprietary Industrial Automation Protocol
Malmö University, Faculty of Technology and Society (TS), Department of Computer Science and Media Technology (DVMT).
Malmö University, Faculty of Technology and Society (TS), Department of Computer Science and Media Technology (DVMT).
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In industrial automation, the ability to analyze and troubleshoot proprietary communication protocols is critical for ensuring system reliability and efficiency. This thesis addresses the lack of protocol analysis tooling for ABB’s proprietary Inter-Application Communication (IAC) protocol, which is used within the ABB Ability System 800xA. As Wireshark, a widely adopted network packet analysis tool, does not offer native support for the IAC protocol, manual interpretation of raw UDP data has previously been required, leading to inefficiencies and increased risk of human error. 

This work presents the design, implementation and evaluation of a custom Wireshark dissector written in Lua, capable of parsing and visualizing IAC traffic. The project followed the Design Science Research Methodology by Peffers et al., including iterative prototyping, testing with real-world network captures and interviews with protocol developers, engineers and customer support personnel at ABB. The artifact was developed under the constraints of lacking public documentation, relying only on partial internal documentation and required significant reverse engineering of source code with expert guidance. 

The results demonstrate that even proprietary, partially documented protocols can be effectively supported with Wireshark through hands-on experimentation, iterative prototyping, reverse engineering efforts, expert feedback and collaborative development practices. The dissector significantly improved IAC traffic analysis by making packet content more accessible, reducing analysis time and minimizing errors. In addition to its practical value for ABB, the thesis contributes generalizable strategies and knowledge for developing protocol dissectors under similar industrial conditions.

Place, publisher, year, edition, pages
2025.
National Category
Information Systems
Identifiers
URN: urn:nbn:se:mau:diva-78519OAI: oai:DiVA.org:mau-78519DiVA, id: diva2:1981266
External cooperation
ABB
Educational program
TS Systemutvecklare
Supervisors
Examiners
Available from: 2025-07-04 Created: 2025-07-03 Last updated: 2025-07-04Bibliographically approved

Open Access in DiVA

fulltext(2395 kB)10 downloads
File information
File name FULLTEXT02.pdfFile size 2395 kBChecksum SHA-512
9849f7197dbf64cf1d58d681e5479b71755a04cf238c18f5f5dc4af93da1472d65e9a3130574aa0abc36d5ee94602d0cf49ba149c1c147945aa9920ca2215e9b
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Giheden, AlexanderSandell, Anton
By organisation
Department of Computer Science and Media Technology (DVMT)
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 10 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 53 hits
4546474849505148 of 825
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf