Data Gateway

Data Gateway is a device that supports the communication and exchange of data between different systems, networks, or protocols within the ICS. Different types of data gateways are used to perform various functions, including:

  • Protocol Translation: Enable communication to devices that support different or incompatible protocols by translating information from one protocol to another.
  • Media Converter: Convert data across different Layer 1 and 2 network protocols / mediums, for example, converting from Serial to Ethernet.
  • Data Aggregation: Collect and combine data from different devices into one consistent format and protocol interface.
  • Data Mirroring: Create a real-time, exact copy of data streams from devices to a separate destination for redundancy, monitoring, or backup purposes.

Data gateways are often critical to the forwarding/transmission of critical control or monitoring data within the ICS. Further, these devices often have remote various network services that are used to communicate across different zones or networks.

These assets may focus on a single function listed below or combinations of these functions to best fit the industry use-case.

ID: A0009
Platforms: Embedded, Linux, Network, Windows
Sectors: General
Version: 2.1
Created: 28 September 2023
Last Modified: 27 April 2026

Related Assets

Name Sectors Description
Data Acquisition Server (DAS) General

A Data Acquisition Server (DAS) a system or software platform that is used to collect, aggregate, and store data/telemetry from field devices using various SCADA/Automation protocols.

Serial to Ethernet Gateway Electric, General

A Serial to Ethernet gateway is a device that is used to connect field devices that only support serial-based communication (e.g., RS-232) with more modern Ethernet-based networks.

Industrial Edge General

Devices that may house a cellular or other type of communication stack that is outside the normal network path. May be bi-directional access by outside parties or unidirectional by design to allow for feeding of data to outside areas such as corporate, vendor, or cloud.

Techniques

Domain ID Name
ICS T0800 Activate Firmware Update Mode
ICS T0830 Adversary-in-the-Middle
ICS T0878 Alarm Suppression
ICS T1695 Block Communications
.001 Serial COM
.002 Ethernet
.003 Wi-Fi
ICS T1691 .002 Block Operational Technology Message: Reporting Message
ICS T0892 Change Credential
ICS T0807 Command-Line Interface
ICS T0885 Commonly Used Port
ICS T0884 Connection Proxy
ICS T0809 Data Destruction
ICS T0814 Denial of Service
ICS T0816 Device Restart/Shutdown
ICS T0871 Execution through API
ICS T0820 Exploitation for Evasion
ICS T0890 Exploitation for Privilege Escalation
ICS T0866 Exploitation of Remote Services
ICS T0822 External Remote Services
ICS T0823 Graphical User Interface
ICS T0874 Hooking
ICS T0872 Indicator Removal on Host
ICS T1694 Insecure Credentials
.001 Default Credentials
ICS T0849 Masquerading
ICS T0838 Modify Alarm Settings
ICS T1693 .001 Modify Firmware: System Firmware
ICS T0801 Monitor Process State
ICS T0834 Native API
ICS T0840 Network Connection Enumeration
ICS T0842 Network Sniffing
ICS T0861 Point & Tag Identification
ICS T0886 Remote Services
ICS T0846 Remote System Discovery
.001 Port Scan
.002 Broadcast Discovery
.003 Multicast Discovery
ICS T0888 Remote System Information Discovery
ICS T0847 Replication Through Removable Media
ICS T0848 Rogue Master
ICS T0851 Rootkit
ICS T0853 Scripting
ICS T0881 Service Stop
ICS T0869 Standard Application Layer Protocol
ICS T0862 Supply Chain Compromise
ICS T1692 .002 Unauthorized Message: Reporting Message
ICS T0859 Valid Accounts