The Modbus protocol and its variants are widely used in industrial control applications,
especially for pipeline operations in the oil and gas sector. This paper describes the
principal attacks on the Modbus Serial and Modbus TCP protocols and presents the
corresponding attack taxonomies. The attacks are summarized according to their threat
categories, targets and impact on control system assets. The attack taxonomies facilitate
formal risk analysis efforts by clarifying the nature and scope of the security threats on
Modbus control systems and networks. Also, they provide insights into potential mitigation
strategies and the relative costs and benefits of implementing these strategies.