A security analyst is reviewing network traffic logs from a SCADA network and notices a series of Modbus Function Code 16 (Write Multiple Registers) commands sent from an HMI to a PLC that controls a critical pumping station. The commands occur outside of the normal operational schedule and target registers that are not typically modified by this HMI. Which type of network anomaly does this activity represent?
-
A
A volumetric anomaly, indicating a denial-of-service attack.
-
B
A protocol anomaly, where the Modbus packet structure is malformed.
-
C
A behavioral anomaly, where the communication pattern deviates from the established baseline.
-
D
A signature-based anomaly, matching a known malware communication pattern.