scieee Open visual document viewer

Validation of Sensor Data Integrity in OT Environments Through Multisource Data Sensors

Simola, Jussi,Takala, Arttu,Lehkonen, Riku,Frantti, Tapio,Savola, Reijo

Full text

This is a sel -a chi ed e sion o an o iginal a icle. This e sion may di e om he o iginal in pagina ion and ypog aphic de ails. Au ho (s): Ti le: Yea : Ve sion: Copy igh : Righ s: Righ s u l: Please ci e he o iginal e sion: CC BY-NC-ND 4.0 h ps://c ea i ecommons.o g/licenses/by-nc-nd/4.0/ Valida ion o Senso Da a In eg i y in OT En i onmen s Th ough Mul isou ce Da a Senso s © 2024 Eu opean Con e ence on Cybe Wa a e and Secu i y Published e sion Simola, Jussi; Takala, A u; Lehkonen, Riku; F an i, Tapio; Sa ola, Reijo Simola, J., Takala, A., Lehkonen, R., F an i, T., & Sa ola, R. (2024). Valida ion o Senso Da a In eg i y in OT En i onmen s Th ough Mul isou ce Da a Senso s. In M. Leh o, & M. Ka jalainen (Eds.), P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y (23, pp. 487-495). Academic Con e ences In e na ional L d. P oceedings o he Eu opean Con e ence on Cybe Wa a e and Secu i y. h ps://doi.o g/10.34190/eccws.23.1.2335 2024 Valida ion o Senso Da a In eg i y in OT En i onmen s Th ough Mul isou ce Da a Senso s Jussi Simola, A u Takala, Riku Lehkonen, Tapio F an i and Reijo Sa ola Uni e si y o Jy äskylä, Finland Jussi.hm.simola@jyu. i a u.h. akala@jyu. i iku.p.lehko[email p o ec ed]i apio.k. an i@jyu. i eijo.m.sa ola@jyu. i Abs ac : This esea ch pape ocuses on de ec ing cybe h ea s om he OT en i onmen by combining da a om mul iple sou ces. Moni o ing cybe secu i y o hyb id h ea s in an indus ial OT en i onmen is di icul due o di e en equipmen , p o ocols, en i onmen s, pe sonnel managemen and aining, e c. Howe e , he OT en i onmen can also be obse ed wi h a mul isou ce senso sys em, which can be used o collec da a. By combining IT and OT da a, addi ional cybe h ea s can be ound. Especially conce ning he in eg i y o OT command-and-con ol da a. We deal wi h he key concep s and di e ences o he indus ial ope a ing en i onmen , which c ea e challenges compa ed o he adi ional IT en i onmen . This is impo an because he policies de ined a he Eu opean le el o he NIS2 egula ion a e coming o ouch all membe coun ies, ega dless o wha he na ional implemen a ion schedule is. The inc eased s anda ds o OT en i onmen cybe secu i y implemen a ion and de elopmen will also ha e an impac on he pe sonnel managemen and aining o suppo he onboa ding o he s anda ds in p ac ice. C i ical in as uc u e p o ec ion is impo an because, wi hou he p o ec ion o c i ical in as uc u e, i al unc ions cease o unc ion. Hos ile ac o s cause secu i y challenges among Wes e n ac o s. In his s udy, we del e in o whe he i is possible o ind h ea s conce ning OT command-and-con ol p ocess. The inc eased da a su ace collec ed om he IT/OT en i onmen imp o es he capabili ies o he sys em o de ec malicious a acks owa ds he OT sys em. Wi h he help o es equipmen , he goal is o demons a e ha i is possible o ind h ea s by combining da a om mul iple sou ces. Wi h he help o es equipmen , we ind ou IT and OT capabili ies, which we load wi h a ious a acks and anomalies. We p oduce added alue compa ed o adi ional moni o ing me hod es cases by compa ing da a ob ained om di e en sou ces. The esea ch pape shows he impo ance o de ec ing OT h ea s. By moni o ing IT and OT en i onmen s and combining hei da a, we can ind hidden h ea s. Only one es equipmen con igu a ion has been used in he s udy, bu he esul s can be gene alized and classi ied. The s udy also p o ides guidelines o how he de ec ion o cybe h ea capabili ies should be de eloped. Keywo ds: Tes bed En i onmen , Senso In eg a ion, Senso Da a In eg i y, Ope a ional Technology, Cybe secu i y 1. In oduc ion The pu pose o he CSG (Cybe secu i y Go e nance o Ope a ional Technology in he Sma Ene gy) p ojec is o de elop a go e nance model o ope a ional echnology ecosys ems o minimize Ope a ional Technology isks and c ea e a new s anda dized ope a ing en i onmen o he indus ial en i onmen . The main aim o he CSG p ojec is o de elop a Go e nance model o he Ope a ional echnology- ela ed en i onmen s. The s udy's esul s will be used o design p ocesses o he go e nance model in he OT-SOC en i onmen whe e he Indus ial Con ol Sys em (ICS) is a c ucial ope a i e ac o in an indus ial en i onmen . EU's cybe secu i y s a egy se he amewo k o he o ma ion o na ional-le el cybe secu i y (Eu opean Commission, 2020, 2022; ENISA, 2023). The NIS2 di ec i e by he Eu opean Commission (2022) s a es ha e e y Eu opean Union membe s a e mus adop a Na ional Cybe secu i y S a egy (NCSS) and es ablish a cybe secu i y go e nance model. The Eu opean S a egic Ene gy Technology plan aims o boos he ansi ion owa ds a clima e-neu al ene gy sys em (Eu opean Pa liamen 2023). A a gene al le el, as a pa o co po a e go e nance, se e al elemen s a e ela ed o he o ma ion o cybe secu i y go e nance. The amewo ks a e essen ially connec ed o each o he . C ucial ulne abili y elemen s o secu i y and cybe secu i y consis o people, p ocesses, and echnical aspec s (Eu opean Commission 2022, 2023). The ope a ional echnology en i onmen , especially he ene gy sec o , is c i ical o e e y i al unc ion. I cybe a acks dis up ene gy supply chain sys ems, all connec ed ope a ional echnology sys ems will shu down soon o la e . The e o e, i is impo an also o apply cybe secu i y supply chain isk managemen guides (GSA, 2014). The esea ch concen a es on moni o ing p ocess con ol a he ope a ional and echnical le els. I is impo an o enhance de ec ion capabili ies because o he digi aliza ion o he OT en i onmen . NIS2 (2023) equi es enhanced in o ma ion sha ing ega ding cybe h ea s and inciden s because i has been seen ha 487 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al c i ical in as uc u e p o ec ion is no possible o main ain wi hou new egula ions. The isibili y o he cybe h ea con ol mechanism and he capabili y o de ec and sha e h ea in o ma ion a e impo an pa s o con inui y managemen , which depends on he con inui y o business ope a ions. The pape concen a es on compa ing da a om di e en places in he es bed en i onmen . The da a will be used o e i y he in eg i y o he ope a ional echnology p ocess. We will use se e al da a moni o ing poin s. The ocus is on how o see e en s in di e en places. We compa e he ou pu da a o he h ea in o ma ion. 2. Impo ance o C i ical In as uc u e P o ec ion 2.1 Ope a ional Technologies in a ious indus ies and connec ions. Ne wo king and In o ma ion Sys ems di ec i e NIS2 se s equi emen s o he companies and hei s a egic, ope a ional, and echnical unc ions (Eu opean Pa liamen , 2022). In addi ion, he Cybe Resilience Ac (Eu opean Commission, 2022) suppo s he goals o he NIS2, and i endo ses he aims o he CER Cybe Resilience di ec i e. CRA consis s o equi emen s o he manu ac u ing p ocess o digi alized p oduc s, indus ial companies, and cybe secu i y aining me hods o he pe sonnel and managemen o secu i y ope a ions (Eu opean Commission, 2022). The Cybe secu i y and In as uc u e Secu i y Agency CISA (2020) lis s c i ical in as uc u e in 16 sec o s which a e Chemical Sec o , Comme cial Facili ies Sec o , Communica ions Sec o , C i ical Manu ac u ing Sec o , Dams Sec o , De ense Indus ial Base Sec o , Eme gency Se ices Sec o , Ene gy Sec o , Financial Se ices Sec o , Food and Ag icul u e Sec o , Go e nmen Facili ies Sec o , Heal hca e and Public Heal h Sec o , In o ma ion Technology Sec o , Nuclea Reac o s, Ma e ials, and Was e Sec o , T anspo a ion Sys ems Sec o , Wa e and Was ewa e Sys ems Sec o . Ope a ional echnology is i al o c i ical in as uc u es because o he in e connec ed and mu ually dependen physical sys ems and a hos o in o ma ion and communica ions echnologies (Pee enboom, 2001). C i ical in as uc u es a e called a “sys em o sys ems” because o he in e dependencies ha exis be ween a ious indus ial sec o s and he in e connec ions be ween business pa ne s (Pee enboom, 2001; Rinaldi, 2001). An inciden in one sec o o he c ucial in as uc u e can, di ec ly and indi ec ly, a ec o he in as uc u es h ough cascading and escala ing ailu es. The e o e, isibili y in o ne wo k a ic and de ice beha io s in OT ne wo ks is impo an . I is less han adequa e ac oss he sec o ega dless o he capabili y o a pa icula o ganiza ion (U.S. Depa men o Ene gy (2021). By be e unde s anding he o ganiza ion's OT en i onmen , hey may be able o co ela e a mo e mino anomaly o a po en ial a ack, mo ing he asse owne ’s h ea de ec ion capabili y ea lie in o an a ack campaign and p e en ing mo e signi ican impac s on ope a ions (U.S. Depa men o Ene gy, 2021). 2.2 Vulne abili ies in G id Powe Sys ems Acco ding o he NIST (2023), he elec ical powe ansmission and dis ibu ion g id indus ies use geog aphically dis ibu ed SCADA con ol echnology ha ope a es highly in e connec ed and dynamic sys ems ha consis o coun less public and p i a e u ili ies and u al coope a i es o supplying elec ici y o end use s NIST (2023). Rega ding E o e al. (2016), he elec ic powe sys em is a complex ne wo k o elec ic componen s designed o gene a e, anspo , and deli e elec ici y ac oss wo dis inc ye in eg a ed sys ems, bu is no clea ly de ined he in e up ions due o ac o s a ec ing he bulk powe sys em and ac o s a ec ing he dis ibu ion sys em. The same ype o undamen al p oblems is mos ly ela ed o he ulne abili ies agains cybe -a acks and lack o s anda diza ion. Acco ding o he IDAHO (2016), dis ibu ion and local deli e y o elec ici y a e gene ally no conside ed pa o he U.S. bulk Elec ic Sys em and a e o e seen by s a e public u ili y commissions. Implemen ing cybe secu i y s anda ds a ies in he b ead h o p o ec ions and backup measu es o dis ibu ion u ili ies. Cybe -a acks on dis ibu ion elemen s can ha e consequences ha each he Bulk Elec ic Sys em. The i s known hack o a ec a powe g id occu ed in Uk aine in 2015 when a dis ibu ion sys em se ed as he a ack plane. Ad e sa ies used malwa e o access IT in as uc u e and hen hijacked he SCADA dis ibu ion managemen sys em o cause changed s a es o he dis ibu ion elec ici y in as uc u e and a emp o delay es o a ion by wiping SCADA se e s a e hey caused he ou age, while simul aneously p e en ing calls epo ing powe ou ages om eaching cus ome se ice cen e s, esul ing in a couple o hou s ou age. The a acke s conduc ed mon hs o econnaissance be o e he a ack, planning o execu e he a acks ha ook mul iple subs a ions o line and disabled backup powe om wo dis ibu ion cen e s simul aneously (IDAHO, 2016; Ze e , 2016). Ope a ional echnology- ela ed Ene gy dis ibu ion sys ems a e ulne able because 488 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al he ad e sa ies unde s and how impo an he ene gy supply chain is o all ope a ional en i onmen s. Enemy na ions ha e an in e es in manipula ing wo kable sys ems. In he connec ion o Ope a ional Technology, se e al indus ial con ol sys em de ices include emo e access capabili ies, and indus ial con ol sys ems a e inc easingly connec ed o co po a e business ne wo ks (GAO, 2018). Acco ding o he GAO (2018), a acke s' emo e access is an inc easingly po en ial cybe h ea a ge o manipula ing ICS de ices. Because unc ionali ies depend on he ene gy supply, he e is a need o de elop OT en i onmen s ha a e mo e p o ec ed agains cybe -a acks. Cybe h ea de ec ion capabili ies a e a c ucial pa o o e all cybe secu i y. The pape concen a es on he equi emen s o he cybe h ea / e en de ec ion capabili ies. 2.3 Enhancing Cybe Secu i y Si ua ional Awa eness a he Ope a ional Le el The ENISA (2022), Go e nance model has been di ided in o ou le els. Poli ical, s a egic, ope a ional, and echnical le els. The echnical le el o adminis a ion aims o link he implemen a ion s a egy so ha echnical and echnological de elopmen akes place simul aneously, which is essen ial in cybe space, a apidly de eloping ield whe e new h ea s and challenges a ise simul aneously as new echnological oppo uni ies and solu ions. The ope a ional/ echnical le el is c ucial o he o ma ion o si ua ional awa eness. Technical, ne wo k and so wa e-based da a-sha ing capabili ies a e c ucial, and human in e ac ion a ec s he g ound- le el ans o med in o ma ion. De ense in Dep h is based on he mili a y concep ha p o ides ba ie s o impede he p og ess o in ude s om a aining hei goals while moni o ing hei p og ess and de eloping and implemen ing esponses o he inciden o epel hem (Homeland Secu i y, 2016). As Homeland Secu i y (2016) s a es, an o ganiza ion mus ecognize he ela ionship be ween in ude s and ulne abili ies o he con ols (s anda ds and coun e measu es) pu in place o p o ec ope a ions, pe sonnel, and echnologies. Acco ding o he De ense- in-Dep h P o ec ion o Indus ial Con ol Sys ems, he connec ion be ween In o ma ion Technology and Con ol Sys ems in an o ganiza ion's secu i y unc ions is c ucial. The de ense-in-dep h s a egy consis s o he ollowing elemen s, as Table 1 illus a es (Homeland Secu i y, 2016). Table 1: The elemen s o he de ense-in-dep h s a egy (Homeland Secu i y, 2016) De ense-In-Dep h S a egy Elemen s Risk Managemen P og am • Iden i y Th ea s • Cha ac e ize Risk • Main ain Asse In en o y Cybe secu i y A chi ec u e • S anda ds/ Recommenda ions • Policy • P ocedu es Physical Secu i y • Field Elec onics Locked Down • Con ol Cen e Access Con ols • Remo e Si e Video, Access Con ols, Ba ie s ICS Ne wo k A chi ec u e • Common A chi ec u al Zones • Demili a ized Zones (DMZ) • Vi ual LANs ICS Ne wo k Pe ime e Secu i y • Fi ewalls/ One-Way Diodes • Remo e Access & Au hen ica ion • Jump Se e s/ Hos s Hos Secu i y • Pa ch and Vulne abili y Managemen • Field De ices • Vi ual Machines Secu i y Moni o ing • In usion De ec ion Sys ems • Secu i y Audi Logging 489 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al De ense-In-Dep h S a egy Elemen s • Secu i y Inciden and E en Moni o ing Vendo Managemen • Supply Chain Managemen • Managed Se ices/ Ou sou cing • Le e aging Cloud Se ices The Human Elemen • Policies • P ocedu es • T aining and Awa eness Acco ding o (Homeland Secu i y, 2016), o ganiza ions can use i e p inciples o coun e measu es o d i e ac i i ies in ICS en i onmen s. The ollowing s eps will pa e he way owa d a mo e obus secu i y en i onmen and signi ican ly educe he isk o ope a ional sys ems. • Iden i y, minimize, and secu e all ne wo k connec ions o he ICS. • Ha den he ICS and suppo ing sys ems by disabling unnecessa y se ices, po s, and p o ocols, enable a ailable secu i y ea u es and implemen obus con igu a ion managemen p ac ices. • Con inually moni o and assess he secu i y o he ICS, ne wo ks, and in e connec ions. • Implemen a isk-based de ense-in-dep h app oach o secu ing ICS sys ems and ne wo ks. • Manage he human—clea ly iden i y equi emen s o ICS; es ablish expec a ions o pe o mance; hold indi iduals accoun able o hei pe o mance; es ablish policies; and p o ide ICS secu i y aining o all ope a o s and adminis a o s. 3. Da a In eg i y Valida ion and P ocess In eg i y 3.1 Managing In o ma ion Secu i y in IT and OT En i onmen s 3.1.1 CIA and AIC T iad Con iden iali y, In eg i y, and A ailabili y (CIA) iad is a o m o ep esen a ion o he undamen al elemen s o secu i y objec i es in in o ma ion sys ems (NIST, 2020a,2020b). Con iden iali y is ocused on he es ic ions on he use and s o age o da a, which may be los in cases such as du ing insecu e da a ansmission o access con ol (Ka &e .a., 2021) On he o he hand, in eg i y o e s gua an ees ha da a has no been ampe ed wi h. One way o a emp o secu e da a du ing ansmission is o use checksums o alida e he in eg i y o he ans e ed da a be ween he sende and he ecei e (Ka and Zolkipli, 2021). A ailabili y in in o ma ion sys ems ensu es ha he au ho ized use s ha e imely and unin e up ed access o necessa y in o ma ion, esou ces, and componen s. In OT en i onmen , a ailabili y includes being able o use he de ices ha a e pa o he sys em, which could be c ucial o he en i onmen hey’ e in (Ka and Zolkipli, 2021). The impac o a ailabili y is exace ba ed in c i ical in as uc u e, whe e he loss o a ailabili y would ha e cascading impac on socie y. Al hough CIA iad implemen s hea y ocus on echnical secu i y con ols, when socio- echnical elemen s a e impo an in sys em secu i y, i is a aluable and s aigh o wa d way o unde s and and sol e issues ha a e ele an in in o ma ion secu i y (Samonas and Coss, 2014). Fo example, i is especially ele an in Common Vulne abili y Sco ing Sys em (CVSS) sco ing when sys em impac o a ulne abili y is es ima ed, which a e used in es ima ing se e i y o Common Vulne abili ies and Exposu es (CVE) e en s. CIA iad has i s oo s in mili a y secu i y mindse , whe e he p o ec ion is pe ime e ocused agains ex e nal h ea s (Samonas and Coss, 2014). Addi ionally, loss o CIA o in o ma ion o in o ma ion sys ems is used as basis in de elopmen o ele an secu i y con ols (NIST, 2020)b. 3.1.2 On he Aspec s o CIA/AIC T iad in IT/OT CIA iad o igina es om IT domain, whe e he secu i y ea u es aim o p o ide sa e y by p o ec ing i sel agains cybe a acks. T adi ional OT domain’s sa e y aims o ensu e unc ional esilience and sa e y o p o ec he en i onmen and humans agains unwan ed ope a ions ha could lead o physical damage o inju ies (Holle e & e .al, 2022). Addi ionally, p io i ies conside ing he CIA iad a e in e se be ween adi ional IT and OT en i onmen s, whe e IT en i onmen s p io i ise con iden iali y i s (CIA) and OT en i onmen s a ailabili y i s (AIC)5. Wi h he OT 4.0 shi o in eg a ing IT capabili ies and in e acing OT de ices in o IT in as uc u e, he di e ence be ween IT and OT is diminished, since i opens OT en i onmen s as a ge s agains cybe a acks. Fo 490 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al example, cybe a acks may a ge OT en i onmen s o p e en he a ailabili y o sa e y unc ion o an OT de ice, which may lead o unde mined sa e y o he en i onmen . Howe e , while loss o a ailabili y migh be he majo h ea in OT en i onmen s, loss o con iden iali y and in eg i y may be used o cause loss o a ailabili y wi h cybe a acks. In an au oma ed sys em, he loss o in eg i y can lead o a highe loss o a ailabili y. This is due o he po en ial o sys em shu down igge ed by cascading adjus men s. These adjus men s a e based on he alsi ied da a and a e in ended o s ee he sys em owa ds co ec unc ion. Fo example, i da a ou es ha e hei in eg i y los (manipula ed de ice s a us epo ), he au oma ed sa e y sys em shu down may be used as he a ack ec o o damage he equipmen , leading o loss o a ailabili y, which in u n impac s he secu i y (Den lze &e .al,.2021). Simila ly, loss o con iden iali y on highe p i ileges and de ice da a may lead o hem being used o aid in a acks agains he OT en i onmen 's a ailabili y. The e o e, while a ailabili y is he mos impo an a ge o de end, con iden iali y and in eg i y a e inhe en ly connec ed o o e all a ailabili y in OT 4.0 en i onmen s. This leads o he need o balance all aspec s o he CIA iad o ensu e sa e y when designing sys em con ols a he han p io i izing con iden iali y i s . 4. Backg ound Theo y We ha e applied a design science esea ch me hodology, which is used adi ionally in sys em de elopmen (He ne & e .al., 2004). As pa o he design science p ocess, he mul iple case s udy esea ch-based s a egy by Yin (2004) and he knowledge base o he case s udies c ea e a co e amewo k o he go e nance model and gene a e an added knowledge base. This i e a i e design science p ocess ou pu mus be di e en om he p esen sys em. The MITRE A &ck (2023) amewo k has o med he common base o analyzing cybe -a acks, ac ics, and scena ios. I has i s own weaknesses ela ed o indus y-based h ea classi ica ion, bu i is e y sui able o apply o almos all kinds o companies. Ope a ional Technology-based ulne abili ies a e nowadays he main a ge when he aim is o de elop a cohe en cybe secu i y en i onmen . The MITRE A ack amewo k (2023) is an impo an elemen o he es ing p ocess. We ha e used da a om i in se e al cases. The pape concen a es on da a in eg i y alida ion and i s p ocess. The p ocess will be alida ed using da a om a ious poin s du ing execu ion. Ano he esea ch ocus concen a es on enhancing he isibili y o sec o - based h ea in o ma ion. Two main aspec s mus be conside ed: • Da a in eg i y alida ion may be done wi h da a senso s a a ious poin s, whe e he alues o he da a may be compa ed o ensu e hei co ec ness. The a ious da a senso s may also be used o ack p ocess s eps h oughou he sys em. This way he p ocess in eg i y may be a a ge o alida ion ins ead, o ensu e i has no been ampe ed wi h. Fo example, wi h a ious da a senso s, he sys em wa den may see ha he command sequence is manipula ed hal way h ough he p ocess, leading o a di e en ou come han ini ially eques ed. This may be included wi h addi ional sys em-speci ic in o ma ion, such as so wa e e sions, ha dwa e equipmen , and ne wo k p o ocols. • When a sys em ulne abili y o malicious a ack is de ec ed, he addi ional sys em in o ma ion aids in h ea in el and secu i y b each epo ing o he ele an s akeholde s. These companies may wo k in simila o adjacen sec o s, whe e iden ical ha dwa e o so wa e is used. In summa y, he p ocess alida ion may be used o p o ide con ex o h ea in el. Addi ionally, he NIS2 (2022) di ec i e manda es sec o -based h ea in el epo ing, whe e companies a e obliga ed o epo o he ele an go e nmen body abou possible secu i y b eaches. Using a ious da a senso s o p ocess alida ion imp o es he isibili y o he secu i y p ocesses, which in u n aids in p o iding in o ma ion o go e nmen al bodies. This, in u n, p o es ha he company is upholding i s obliga ions. 4.1 Poin o P ocess Moni o ing Moni o ing a p ocess and i s da a a ic in OT en i onmen s aids in c ea ing a holis ic si ua ional awa eness, in addi ion o p ocess awa eness, which includes elemen s such as s eps aken, ans e ed da a, used de ices, and so wa e e sions. I a cybe a ack uses speci ic p ocess as an a ack ec o , p ocess-based moni o ing aids in o ensics due o documen ed and moni o ed con en . Addi ionally, moni o ing a singula p ocess h ough a ious da a senso s aids in audi ing p ocess unc ion e en s. Fo example, i a cybe a ack manipula es da a a a pa icula s ep o a p ocess, such as du ing a log eques o SCADA command, i may be analysed in o ensics owa ds a speci ic sec ion in in e ne in as uc u e whe e he s ep would occu . This p o ides addi ional in o ma ion, which may be used in u he o ensics, such as he de ices (e.g., swi ch and IED) used in his speci ic s ep, hei so wa e e sions, and p o ocols used in communica ion. This addi ional in o ma ion needs o be manually managed in cases whe e he moni o ing ocuses on speci ic da a alues wi hou including p ocess as a 491 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al amewo k o con ex . Addi ionally, p ocess moni o ing enables analysis o causal ela ionship be ween s eps and o he p ocesses. I a da a alue doesn’ change as expec ed a e a ce ain p ocess s ep is pe o med, i could signal a po en ial comp omise. 4.2 Tes bed En i onmen The es bed en i onmen de eloped by he Uni e si y o Jy äskylä is a unique pla o m o es ing di e en kinds o ulne abili ies and h ea scena ios. Tes ing sepa a e so wa e, de ices, and ne wo k combina ions in many ways is possible. Collabo a ion wi h business companies is essen ial and gene a es new da a o p o ec ing c i ical in as uc u e. We ha e es ed how o de ec and see h ea da a a di e en poin s. The used labo a o y en i onmen consis s o a p ocess plan wi h i s OT de ices and he con ol and moni o ing ne wo k, as Figu e 1 illus a es. The plan can be con olled wi h local and emo e SCADA sys em. Remo e con ol is implemen ed wi h an LTE connec ion. A sepa a e moni o ing ne wo k is connec ed o he p ocess plan . Moni o ing is implemen ed by mi o ing he ne wo k a ic om he cen al swi ch and OT de ice log in o ma ion om he cen al logging poin s o he p ocess plan and he con ol cen e (O ice). Figu e 1: Tes bed en i onmen The Man-In-The-Middle (MITM, man = pe son, de ice) scena io is indica ed in ed, which is used o alida e he p ocess-based da a in eg i y e i ica ion me hod. PITM da a comp omise is ca ied ou wi h an addi ional de ice which is added o he connec ion be ween he p ocess plan and he o ice. Comp omised OT logs a e also highligh ed in ed. The de ices u ilized in he scena io a e highligh ed in blue. 4.3 Use Case 4.3.1 En i onmen and Scena io As Figu e 2 illus a es, he use case is depic ed wi h a eal-wo ld coun e pa . Sepa a e o ice space con ains he plan 's con ol sys em, which is connec ed o he plan 's in e nal swi ch. The da a ans e be ween he p oduc ion plan and he o ice space is emo ely moni o ed wi h a sepa a e SOC. Fu he mo e, one dis inc isola ed ne wo k is employed o he su eillance o OT de ice logs, while a di e en ne wo k is used o di ec ly eques OT de ice logs om he de ice i sel . In his scena io, he a acke has access (physical o ne wo k) o he p ocess plan con ol ne wo k. The a acke modi ies he da a ans e ed be ween he OT de ice and he cen al swi ch. By modi ying his da a, he a acke can comp omise he si ua ional awa eness o he con ol sys em and SOC, e ade ins alled de ense mechanisms, and disguise oo p in s le in he sys em. MITRE ATT&CK (2023) classi ies he a ack as a Man-In-The-Middle (MITM, Pe son-In-The-Middle) echnique and a de ense e asion ac ic. 492 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al Figu e 2: Desc ip ion o he use case 4.3.2 Pe o med Use Case Du ing he execu ed log eques p ocess, moni o ing occu s ia da a links a he cen al logging de ice, swi ch, and IED. The IED epo s wi hin he in e nal ne wo k h ough he swi ch o he logging de ice, while ex e nal epo ing is done ia an isola ed cable. Speci ically, he p ocess in ol es a log eques om he cen al logging de ice o he IED h ough he swi ch, suppo ed by an addi ional ex e nal eques om he SOC. The MITM a ack unde mines he in eg i y o he esponse o he cen al logging by manipula ing he sen da a. This leads o cen al logging and swi ch da a links o epo inco ec s a us. F om he SOCs pe spec i e, he e is a disc epancy in he s a us logs e u ned in esponse o he e en log eques : he swi ch and cen al logging indica e a ‘local con ol’ s a us, while he IED epo s a ‘ emo e con ol’ s a us. This de ia ion is an anomaly, p omp ing u he in es iga ion o iden i y po en ial mal unc ions o Indica o s o Comp omise (IoCs). By analyzing he causal ela ionships o p ocess s eps and examining his o ical logs, we can de e mine whe he his IED should be in a ‘ emo e con ol’ o ‘local con ol’ s a e based on p e ious s a e-change commands. This e i ica ion p ocess helps pinpoin he loca ion o po en ial IoCs wi hin he in e ne in as uc u e. 5. Findings The upcoming NIS 2 di ec i e equi es c i ical in as uc u e ope a o s o moni o hei sys ems o cybe - h ea s. Ope a o s mus be able o epo any po en ial h ea s and in e p e he epo s o o he ope a o s. To make he mos e ec i e use o po en ial h ea epo s, hey mus also include in o ma ion on he cause-and- e ec ela ionship o which he h ea is ela ed. The capabili y o moni o , log, and epo one's own beha io is i al o he OT de ice. Addi ionally, cen alized moni o ing is c ucial o ensu e he co ec unc ionali y o he en i e sys em. Howe e , in OT en i onmen s, he e a e ha dwa e limi a ions o moni o ing he in eg i y o he command-and-con ol p ocess. Fo his eason, i is possible o add a sepa a e moni o ing ne wo k o he old sys ems. The moni o ing ne wo k moni o s possible IT h ea s o he OT ne wo k, as well as h ea s ela ed o he in eg i y o he OT p ocess. The h ea in o ma ion abou OT sys ems mus especially be able o be sha ed wi h ope a o s in he same sec o . A he hea o he moni o ing ne wo k is a SOC, whe e IT and OT da a om he ne wo k a e collec ed. The SOC mus be able o handle adi ional IT- ela ed cybe h ea s and OT- ela ed h ea s. These also include h ea s ela ed o he in eg i y o he OT p ocess. The e o e, when collec ing and sha ing h ea in o ma ion om OT sys ems, i is essen ial o include in o ma ion abou he en i onmen in which he h ea was de ec ed, including de ices and p o ocols. The in o ma ion mus be s uc u ed so ha an ope a o in he same sec o can use he h ea in o ma ion in hei own sys em. Also, Po en ial con iden ial business sec e s mus be conside ed when 493 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024 A u Takala e al h ea in o ma ion is sha ed. The speci ic in o ma ion o be sha ed mus be ag eed upon sepa a ely, as he de ailed analysis o i could po en ially expose hese sec e s. The cu en si ua ion in OT en i onmen s ocuses on moni o ing ope a ing en i onmen s' pe o mance and s a us o ensu e sa e y and eliabili y. Howe e , con e gence o IT and OT has led o a si ua ion whe e ans e ed da a and ope a ion unc ions may be maliciously manipula ed h ough he IT in e acing elemen s. In OT one me hod o e i y such manipula ion is based upon checksums, bu i o igina es om inding co up ed packe s, no in en ional manipula ion. The majo i y o OT moni o ing is he e o e ocused upon whe he he machine o unc ion is mechanically b oken o ha someone has unin en ionally con igu ed he de ice w ong. Acco ding o p ocess con ol, an isola ed ne wo k and ha dwa e a e good o moni o ing he p ocess in a way ha many senso s a e used. I is impo an o di ide wha is moni o ed and in wha con ex ; in he case o he man-in- he-middle a ack, he en i e log epo ing p ocess is needed. Many checkpoin s show whe e he p ocess wen w ong. I is impo an o analyze wha his can mean o he en i e sys em's ope a ion. A cause-and-e ec ela ionship can be ound in he p ocess da a. We moni o p ocesses; in p ac ice, we moni o he ope a ion o he elec ici y dis ibu ion ne wo k wi h ce ain de ices. Sec o -speci ic in o ma ion is dis ibu ed upwa ds. The pu pose is o sha e and ecei e da a abou po en ial h ea s iden i ied in one's own sec o . 6. Conclusion The e is a need o enhance he ma u i y le el o moni o ing e en s in he ope a ional echnology en i onmen . Resea ched e en s om he IT and OT en i onmen s a e c ucial when he pu pose is o p oduce cohe en si ua ional awa eness o he indus y en i onmen s. Wi hou he abili y o see he equi ed hings om he IT/OT en i onmen , unde s anding he business si ua ion may disappea . The isibili y o cybe secu i y p ocesses is c i ical o ul illing he equi emen s o Eu opean Union egula ions. Se e al OT- ela ed s anda ds and special publica ions a e impo an in s ee ing he supply chain. Valida ion is a se o ac ions ega ding he sys em equi emen , and i is impo an o ensu e hey a e ul illed. NIS2 (Eu opean Pa liamen , 2022) equi es collabo a ion be ween he indus y sec o s and wi hin i . The in o ma ion mus low, so he connec ion be ween he s a egic, ope a ional, and echnical le els is a c ucial ac o ha enhances he o e all si ua ional awa eness wi hin sec o -based indus ies and a he en e p ise le el. As ENISA (2023) s a es and NIS2 sugges , he e mus be unde s andable mechanisms whe e ope a ional echnology- ela ed e en s a e ansmi ed and ans o med in o a o m ha gene a es added alue o he decision-make s. I is no enough o achie e a epo ha indica es e en s. The e should be in o ma ion abou he ype o ulne abili ies and a desc ip ion o he whole p ocess, including he sou ce o he h ea and po en ial consequences. Because many a emp s o he ad e sa ies’ a acks a e being ied again, ja, unin en ional e en s o inciden s a e o en epea ed. Decision-make s should be able o make decisions ega ding business con inui y and in o ma ion-sha ing capabili ies depending on he secu i y ope a ion cen e 's ma u i y o de ec ope a ional echnology- ela ed h ea s deep enough. Tha is impossible wi hou ga he ing and combining di e en kinds o da a om he physical and ne wo ked senso s. So, he amewo k o he p ocess con ol mechanism ha ga he s da a and sha es da a om he Ope a ional Technology en i onmen o he SOC is c ucial o enhance ope a ional echnology cybe secu i y a he g ound le el. The de eloped axonomy has i s own ole in o ming si ua ional awa eness (NIS Coope a ion G oup, 2018), bu i mus be kep up o da e mo e e icien ly because o he de elopmen o po en ial inciden s. The CSG p ojec concen a es on de eloping he go e nance model o he OT en i onmen s. All esea ch da a om he es bed en i onmen suppo he de elopmen p ocess o he go e nance model. Acknowledgmen s The esea ch was suppo ed by Business Finland (g an numbe 10/31/2022) and he Uni e si y o Jy äskylä. Re e ences CISA (2020) C i ical In as uc u e Sec o s. h ps://www.cisa.go / opics/c i ical-in as uc u e-secu i y-and- esilience/c i ical-in as uc u e-sec o s Denzle P., Holle e S., F ühwi h T., and Kas ne W. (2021) Iden i ica ion o secu i y h ea s, sa e y haza ds, and in e dependencies in indus ial edge compu ing. In The Six h ACM/IEEE Symposium on Edge Compu ing (SEC' 21), Decembe 14–17, 2021, San Jose, CA, USA. ACM, New Yo k, NY, USA. 494 P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024