A formally verified implementation of a bolt-on security device for ICS networks. Designed with TLA+ and written/proved in F*