Axowl.com
000
%

Stuxnet-class manipulation, structurally eliminated.

Stuxnet showed the world that attackers can tell a PLC "open the valve" while telling the operator "the valve is closed." DPSM binds every actuator command to a PUF-rooted identity and seals each transition; what the operator sees and what the actuator does become cryptographically identical.

Where Industrial ICS / SCADA breaks today

Command spoofing on the OT bus

PLC protocols (Modbus, S7, DNP3) were not designed for authenticated commands. A foothold on the engineering workstation lets an attacker rewrite recipe parameters silently.

$260K / hr — average OT downtime cost · ABI Research, 2024

Recipe and trajectory tampering

Pharma batch parameters and robot trajectories can be modified without detection in conventional historians; "safe" output certificates are then auto-generated.

21 CFR Part 11 — requires cryptographic audit trails for regulated production

Engineering-workstation hijack

A single compromised engineering laptop with USB-stick deployment privileges represents catastrophic risk across an entire plant.

Stuxnet — remains the canonical case — repeated by Triton, CrashOverride, Industroyer2

Three patents, deployed against this industry's threat model

Each of Axowl's three filed patents maps to a specific structural failure mode in Industrial ICS / SCADA. Together they form a single, end-to-end defense.

Hierarchical Distributed Trust Fabric — PLC (L1) · Historian (L2) · Corporate quorum (L3)

Each PLC, drive, and IO module carries a PUF identity at L1. Plant historians and SCADA servers serve as L2. Corporate engineering and the regulator-readable archive serve as L3. A swapped or counterfeit PLC cannot enter the trust fabric — the hardware itself is the credential.

Transition-Sealed Integrity System — What the operator sees = what the actuator does

Every recipe change, every trajectory waypoint, every safety-limit override is sealed at the moment it crosses to the actuator. The Stuxnet-style "display one thing, do another" attack is no longer possible because the actuator's executed sequence is independently sealed and auditable against the operator's HMI.

Pre-grant LLM Conflict Verification — Engineer permissions auto-screened for toxic combos

An engineer grant of "modify centrifuge speed + disable vibration interlock" is detected as a known catastrophic combination and refused at grant time. The LLM gate surfaces the conflict to safety officers before the grant is ever issued.

Deployment that fits the threat model

The Defense tier (TPM attestation, software watchdog, server sealer) maps cleanly onto modern industrial PCs and edge gateways without requiring custom silicon in early deployments.

Recommended tier: T2 · Defense

Deployment path: AWS F2 for plant gateway · Embedded sealer on industrial PC

Operational detail: An F2-class gateway is deployed at the L2 plant boundary within 72 hours. Embedded sealers run on the operator's industrial PCs (Siemens IPC, Rockwell ControlLogix, Mitsubishi MELIPC). Custom ASIC is the production target for greenfield smart factories.

Three concrete deployments

Pharmaceutical batch integrity

Every recipe parameter from raw-material lot through final QC is sealed. Regulators query a single chain to verify a batch's complete provenance — eliminating multi-week PIC/S audits.

Automotive assembly trajectories

Robot path edits are sealed; an attacker who substitutes a trajectory file cannot mask the change because the PLC verifies the seal on each motion command.

Refinery safety interlocks

Critical setpoints (overpressure trip, temperature limit) require k-of-n authorization. A single compromised engineer cannot disable a SIS function.

Versus what's deployed today

Today — OT firewall + USB whitelist

Defenses focus on perimeter; once an attacker is on the engineering workstation, the OT bus trusts whatever it hears.

With DPSM — Axowl DPSM

Trust moves from the network perimeter to the actuator itself. Even a fully compromised engineering workstation cannot make a PLC act on an unsigned command.

Standards & regulatory frameworks aligned

  • IEC 62443-3-3 SL3 / SL4
  • ISA-99
  • NIST SP 800-82
  • 21 CFR Part 11
  • NIS2 (industrial sector)
  • ENISA Good Practices for IoT in CII