scieee Science in your language
[en] (orig)

Validation of Sensor Data Integrity in OT Environments Through Multisource Data Sensors

Read accessible full text

Validation of Sensor Data Integrity in OT Environments Through Multisource Data Sensors

Author: Simola, Jussi,Takala, Arttu,Lehkonen, Riku,Frantti, Tapio,Savola, Reijo
Publisher: Academic Conferences International Ltd
Year: 2024
Source: https://jyx.jyu.fi/bitstream/123456789/96211/1/EWS-Simola-048.pdf
This is a sel -a chi ed e sion o an o iginal a icle. This e sion
may di e om he o iginal in pagina ion and ypog aphic de ails.
Au ho (s):
Ti le:
Yea :
Ve sion:
Copy igh :
Righ s:
Righ s u l:
Please ci e he o iginal e sion:
CC BY-NC-ND 4.0
h ps://c ea i ecommons.o g/licenses/by-nc-nd/4.0/
Valida ion o Senso Da a In eg i y in OT En i onmen s Th ough Mul isou ce Da a
Senso s
© 2024 Eu opean Con e ence on Cybe Wa a e and Secu i y
Published e sion
Simola, Jussi; Takala, A u; Lehkonen, Riku; F an i, Tapio; Sa ola, Reijo
Simola, J., Takala, A., Lehkonen, R., F an i, T., & Sa ola, R. (2024). Valida ion o Senso Da a
In eg i y in OT En i onmen s Th ough Mul isou ce Da a Senso s. In M. Leh o, & M. Ka jalainen
(Eds.), P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y (23, pp.
487-495). Academic Con e ences In e na ional L d. P oceedings o he Eu opean Con e ence on
Cybe Wa a e and Secu i y. h ps://doi.o g/10.34190/eccws.23.1.2335
2024
Valida ion o Senso Da a In eg i y in OT En i onmen s Th ough
Mul isou ce Da a Senso s
Jussi Simola, A u Takala, Riku Lehkonen, Tapio F an i and Reijo Sa ola
Uni e si y o Jy äskylä, Finland
Jussi.hm.simola@jyu. i
a u.h. akala@jyu. i
iku.p.lehko[email p o ec ed]i
apio.k. an i@jyu. i
eijo.m.sa ola@jyu. i
Abs ac : This esea ch pape ocuses on de ec ing cybe h ea s om he OT en i onmen by combining da a om mul iple
sou ces. Moni o ing cybe secu i y o hyb id h ea s in an indus ial OT en i onmen is di icul due o di e en equipmen ,
p o ocols, en i onmen s, pe sonnel managemen and aining, e c. Howe e , he OT en i onmen can also be obse ed wi h
a mul isou ce senso sys em, which can be used o collec da a. By combining IT and OT da a, addi ional cybe h ea s can
be ound. Especially conce ning he in eg i y o OT command-and-con ol da a. We deal wi h he key concep s and
di e ences o he indus ial ope a ing en i onmen , which c ea e challenges compa ed o he adi ional IT en i onmen .
This is impo an because he policies de ined a he Eu opean le el o he NIS2 egula ion a e coming o ouch all membe
coun ies, ega dless o wha he na ional implemen a ion schedule is. The inc eased s anda ds o OT en i onmen cybe
secu i y implemen a ion and de elopmen will also ha e an impac on he pe sonnel managemen and aining o suppo
he onboa ding o he s anda ds in p ac ice. C i ical in as uc u e p o ec ion is impo an because, wi hou he p o ec ion
o c i ical in as uc u e, i al unc ions cease o unc ion. Hos ile ac o s cause secu i y challenges among Wes e n ac o s. In
his s udy, we del e in o whe he i is possible o ind h ea s conce ning OT command-and-con ol p ocess. The inc eased
da a su ace collec ed om he IT/OT en i onmen imp o es he capabili ies o he sys em o de ec malicious a acks
owa ds he OT sys em. Wi h he help o es equipmen , he goal is o demons a e ha i is possible o ind h ea s by
combining da a om mul iple sou ces. Wi h he help o es equipmen , we ind ou IT and OT capabili ies, which we load
wi h a ious a acks and anomalies. We p oduce added alue compa ed o adi ional moni o ing me hod es cases by
compa ing da a ob ained om di e en sou ces. The esea ch pape shows he impo ance o de ec ing OT h ea s. By
moni o ing IT and OT en i onmen s and combining hei da a, we can ind hidden h ea s. Only one es equipmen
con igu a ion has been used in he s udy, bu he esul s can be gene alized and classi ied. The s udy also p o ides guidelines
o how he de ec ion o cybe h ea capabili ies should be de eloped.
Keywo ds: Tes bed En i onmen , Senso In eg a ion, Senso Da a In eg i y, Ope a ional Technology, Cybe secu i y
1. In oduc ion
The pu pose o he CSG (Cybe secu i y Go e nance o Ope a ional Technology in he Sma Ene gy) p ojec is o
de elop a go e nance model o ope a ional echnology ecosys ems o minimize Ope a ional Technology isks
and c ea e a new s anda dized ope a ing en i onmen o he indus ial en i onmen . The main aim o he CSG
p ojec is o de elop a Go e nance model o he Ope a ional echnology- ela ed en i onmen s. The s udy's
esul s will be used o design p ocesses o he go e nance model in he OT-SOC en i onmen whe e he
Indus ial Con ol Sys em (ICS) is a c ucial ope a i e ac o in an indus ial en i onmen .
EU's cybe secu i y s a egy se he amewo k o he o ma ion o na ional-le el cybe secu i y (Eu opean
Commission, 2020, 2022; ENISA, 2023). The NIS2 di ec i e by he Eu opean Commission (2022) s a es ha e e y
Eu opean Union membe s a e mus adop a Na ional Cybe secu i y S a egy (NCSS) and es ablish a cybe
secu i y go e nance model. The Eu opean S a egic Ene gy Technology plan aims o boos he ansi ion owa ds
a clima e-neu al ene gy sys em (Eu opean Pa liamen 2023).
A a gene al le el, as a pa o co po a e go e nance, se e al elemen s a e ela ed o he o ma ion o
cybe secu i y go e nance. The amewo ks a e essen ially connec ed o each o he . C ucial ulne abili y
elemen s o secu i y and cybe secu i y consis o people, p ocesses, and echnical aspec s (Eu opean
Commission 2022, 2023).
The ope a ional echnology en i onmen , especially he ene gy sec o , is c i ical o e e y i al unc ion. I
cybe a acks dis up ene gy supply chain sys ems, all connec ed ope a ional echnology sys ems will shu down
soon o la e . The e o e, i is impo an also o apply cybe secu i y supply chain isk managemen guides (GSA,
2014). The esea ch concen a es on moni o ing p ocess con ol a he ope a ional and echnical le els. I is
impo an o enhance de ec ion capabili ies because o he digi aliza ion o he OT en i onmen . NIS2 (2023)
equi es enhanced in o ma ion sha ing ega ding cybe h ea s and inciden s because i has been seen ha
487
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
c i ical in as uc u e p o ec ion is no possible o main ain wi hou new egula ions. The isibili y o he cybe
h ea con ol mechanism and he capabili y o de ec and sha e h ea in o ma ion a e impo an pa s o
con inui y managemen , which depends on he con inui y o business ope a ions.
The pape concen a es on compa ing da a om di e en places in he es bed en i onmen . The da a will be
used o e i y he in eg i y o he ope a ional echnology p ocess. We will use se e al da a moni o ing poin s.
The ocus is on how o see e en s in di e en places. We compa e he ou pu da a o he h ea in o ma ion.
2. Impo ance o C i ical In as uc u e P o ec ion
2.1 Ope a ional Technologies in a ious indus ies and connec ions.
Ne wo king and In o ma ion Sys ems di ec i e NIS2 se s equi emen s o he companies and hei s a egic,
ope a ional, and echnical unc ions (Eu opean Pa liamen , 2022). In addi ion, he Cybe Resilience Ac
(Eu opean Commission, 2022) suppo s he goals o he NIS2, and i endo ses he aims o he CER Cybe
Resilience di ec i e. CRA consis s o equi emen s o he manu ac u ing p ocess o digi alized p oduc s,
indus ial companies, and cybe secu i y aining me hods o he pe sonnel and managemen o secu i y
ope a ions (Eu opean Commission, 2022).
The Cybe secu i y and In as uc u e Secu i y Agency CISA (2020) lis s c i ical in as uc u e in 16 sec o s which
a e Chemical Sec o , Comme cial Facili ies Sec o , Communica ions Sec o , C i ical Manu ac u ing Sec o , Dams
Sec o , De ense Indus ial Base Sec o , Eme gency Se ices Sec o , Ene gy Sec o , Financial Se ices Sec o , Food
and Ag icul u e Sec o , Go e nmen Facili ies Sec o , Heal hca e and Public Heal h Sec o , In o ma ion
Technology Sec o , Nuclea Reac o s, Ma e ials, and Was e Sec o , T anspo a ion Sys ems Sec o , Wa e and
Was ewa e Sys ems Sec o .
Ope a ional echnology is i al o c i ical in as uc u es because o he in e connec ed and mu ually dependen
physical sys ems and a hos o in o ma ion and communica ions echnologies (Pee enboom, 2001). C i ical
in as uc u es a e called a “sys em o sys ems” because o he in e dependencies ha exis be ween a ious
indus ial sec o s and he in e connec ions be ween business pa ne s (Pee enboom, 2001; Rinaldi, 2001). An
inciden in one sec o o he c ucial in as uc u e can, di ec ly and indi ec ly, a ec o he in as uc u es
h ough cascading and escala ing ailu es. The e o e, isibili y in o ne wo k a ic and de ice beha io s in OT
ne wo ks is impo an . I is less han adequa e ac oss he sec o ega dless o he capabili y o a pa icula
o ganiza ion (U.S. Depa men o Ene gy (2021). By be e unde s anding he o ganiza ion's OT en i onmen ,
hey may be able o co ela e a mo e mino anomaly o a po en ial a ack, mo ing he asse owne ’s h ea
de ec ion capabili y ea lie in o an a ack campaign and p e en ing mo e signi ican impac s on ope a ions (U.S.
Depa men o Ene gy, 2021).
2.2 Vulne abili ies in G id Powe Sys ems
Acco ding o he NIST (2023), he elec ical powe ansmission and dis ibu ion g id indus ies use
geog aphically dis ibu ed SCADA con ol echnology ha ope a es highly in e connec ed and dynamic sys ems
ha consis o coun less public and p i a e u ili ies and u al coope a i es o supplying elec ici y o end use s
NIST (2023). Rega ding E o e al. (2016), he elec ic powe sys em is a complex ne wo k o elec ic componen s
designed o gene a e, anspo , and deli e elec ici y ac oss wo dis inc ye in eg a ed sys ems, bu is no
clea ly de ined he in e up ions due o ac o s a ec ing he bulk powe sys em and ac o s a ec ing he
dis ibu ion sys em. The same ype o undamen al p oblems is mos ly ela ed o he ulne abili ies agains
cybe -a acks and lack o s anda diza ion. Acco ding o he IDAHO (2016), dis ibu ion and local deli e y o
elec ici y a e gene ally no conside ed pa o he U.S. bulk Elec ic Sys em and a e o e seen by s a e public
u ili y commissions. Implemen ing cybe secu i y s anda ds a ies in he b ead h o p o ec ions and backup
measu es o dis ibu ion u ili ies. Cybe -a acks on dis ibu ion elemen s can ha e consequences ha each he
Bulk Elec ic Sys em. The i s known hack o a ec a powe g id occu ed in Uk aine in 2015 when a dis ibu ion
sys em se ed as he a ack plane. Ad e sa ies used malwa e o access IT in as uc u e and hen hijacked he
SCADA dis ibu ion managemen sys em o cause changed s a es o he dis ibu ion elec ici y in as uc u e
and a emp o delay es o a ion by wiping SCADA se e s a e hey caused he ou age, while simul aneously
p e en ing calls epo ing powe ou ages om eaching cus ome se ice cen e s, esul ing in a couple o hou s
ou age. The a acke s conduc ed mon hs o econnaissance be o e he a ack, planning o execu e he a acks
ha ook mul iple subs a ions o line and disabled backup powe om wo dis ibu ion cen e s simul aneously
(IDAHO, 2016; Ze e , 2016). Ope a ional echnology- ela ed Ene gy dis ibu ion sys ems a e ulne able because
488
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
he ad e sa ies unde s and how impo an he ene gy supply chain is o all ope a ional en i onmen s. Enemy
na ions ha e an in e es in manipula ing wo kable sys ems.
In he connec ion o Ope a ional Technology, se e al indus ial con ol sys em de ices include emo e access
capabili ies, and indus ial con ol sys ems a e inc easingly connec ed o co po a e business ne wo ks (GAO,
2018). Acco ding o he GAO (2018), a acke s' emo e access is an inc easingly po en ial cybe h ea a ge o
manipula ing ICS de ices. Because unc ionali ies depend on he ene gy supply, he e is a need o de elop OT
en i onmen s ha a e mo e p o ec ed agains cybe -a acks. Cybe h ea de ec ion capabili ies a e a c ucial
pa o o e all cybe secu i y. The pape concen a es on he equi emen s o he cybe h ea / e en de ec ion
capabili ies.
2.3 Enhancing Cybe Secu i y Si ua ional Awa eness a he Ope a ional Le el
The ENISA (2022), Go e nance model has been di ided in o ou le els. Poli ical, s a egic, ope a ional, and
echnical le els. The echnical le el o adminis a ion aims o link he implemen a ion s a egy so ha echnical
and echnological de elopmen akes place simul aneously, which is essen ial in cybe space, a apidly
de eloping ield whe e new h ea s and challenges a ise simul aneously as new echnological oppo uni ies and
solu ions. The ope a ional/ echnical le el is c ucial o he o ma ion o si ua ional awa eness. Technical,
ne wo k and so wa e-based da a-sha ing capabili ies a e c ucial, and human in e ac ion a ec s he g ound-
le el ans o med in o ma ion.
De ense in Dep h is based on he mili a y concep ha p o ides ba ie s o impede he p og ess o in ude s
om a aining hei goals while moni o ing hei p og ess and de eloping and implemen ing esponses o he
inciden o epel hem (Homeland Secu i y, 2016). As Homeland Secu i y (2016) s a es, an o ganiza ion mus
ecognize he ela ionship be ween in ude s and ulne abili ies o he con ols (s anda ds and
coun e measu es) pu in place o p o ec ope a ions, pe sonnel, and echnologies. Acco ding o he De ense-
in-Dep h P o ec ion o Indus ial Con ol Sys ems, he connec ion be ween In o ma ion Technology and Con ol
Sys ems in an o ganiza ion's secu i y unc ions is c ucial. The de ense-in-dep h s a egy consis s o he ollowing
elemen s, as Table 1 illus a es (Homeland Secu i y, 2016).
Table 1: The elemen s o he de ense-in-dep h s a egy (Homeland Secu i y, 2016)
De ense-In-Dep h S a egy Elemen s
Risk Managemen P og am
• Iden i y Th ea s
• Cha ac e ize Risk
• Main ain Asse In en o y
Cybe secu i y A chi ec u e
• S anda ds/ Recommenda ions
• Policy
• P ocedu es
Physical Secu i y
• Field Elec onics Locked Down
• Con ol Cen e Access Con ols
• Remo e Si e Video, Access Con ols, Ba ie s
ICS Ne wo k A chi ec u e
• Common A chi ec u al Zones
• Demili a ized Zones (DMZ)
• Vi ual LANs
ICS Ne wo k Pe ime e Secu i y
• Fi ewalls/ One-Way Diodes
• Remo e Access & Au hen ica ion
• Jump Se e s/ Hos s
Hos Secu i y
• Pa ch and Vulne abili y Managemen
• Field De ices
• Vi ual Machines
Secu i y Moni o ing
• In usion De ec ion Sys ems
• Secu i y Audi Logging
489
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
De ense-In-Dep h S a egy Elemen s
• Secu i y Inciden and E en Moni o ing
Vendo Managemen
• Supply Chain Managemen
• Managed Se ices/ Ou sou cing
• Le e aging Cloud Se ices
The Human Elemen
• Policies
• P ocedu es
• T aining and Awa eness
Acco ding o (Homeland Secu i y, 2016), o ganiza ions can use i e p inciples o coun e measu es o d i e
ac i i ies in ICS en i onmen s. The ollowing s eps will pa e he way owa d a mo e obus secu i y en i onmen
and signi ican ly educe he isk o ope a ional sys ems.
• Iden i y, minimize, and secu e all ne wo k connec ions o he ICS.
• Ha den he ICS and suppo ing sys ems by disabling unnecessa y se ices, po s, and p o ocols, enable
a ailable secu i y ea u es and implemen obus con igu a ion managemen p ac ices.
• Con inually moni o and assess he secu i y o he ICS, ne wo ks, and in e connec ions.
• Implemen a isk-based de ense-in-dep h app oach o secu ing ICS sys ems and ne wo ks.
• Manage he human—clea ly iden i y equi emen s o ICS; es ablish expec a ions o pe o mance;
hold indi iduals accoun able o hei pe o mance; es ablish policies; and p o ide ICS secu i y aining
o all ope a o s and adminis a o s.
3. Da a In eg i y Valida ion and P ocess In eg i y
3.1 Managing In o ma ion Secu i y in IT and OT En i onmen s
3.1.1 CIA and AIC T iad
Con iden iali y, In eg i y, and A ailabili y (CIA) iad is a o m o ep esen a ion o he undamen al elemen s o
secu i y objec i es in in o ma ion sys ems (NIST, 2020a,2020b). Con iden iali y is ocused on he es ic ions on
he use and s o age o da a, which may be los in cases such as du ing insecu e da a ansmission o access
con ol (Ka &e .a., 2021) On he o he hand, in eg i y o e s gua an ees ha da a has no been ampe ed wi h.
One way o a emp o secu e da a du ing ansmission is o use checksums o alida e he in eg i y o he
ans e ed da a be ween he sende and he ecei e (Ka and Zolkipli, 2021). A ailabili y in in o ma ion sys ems
ensu es ha he au ho ized use s ha e imely and unin e up ed access o necessa y in o ma ion, esou ces,
and componen s. In OT en i onmen , a ailabili y includes being able o use he de ices ha a e pa o he
sys em, which could be c ucial o he en i onmen hey’ e in (Ka and Zolkipli, 2021). The impac o a ailabili y
is exace ba ed in c i ical in as uc u e, whe e he loss o a ailabili y would ha e cascading impac on socie y.
Al hough CIA iad implemen s hea y ocus on echnical secu i y con ols, when socio- echnical elemen s a e
impo an in sys em secu i y, i is a aluable and s aigh o wa d way o unde s and and sol e issues ha a e
ele an in in o ma ion secu i y (Samonas and Coss, 2014). Fo example, i is especially ele an in Common
Vulne abili y Sco ing Sys em (CVSS) sco ing when sys em impac o a ulne abili y is es ima ed, which a e used
in es ima ing se e i y o Common Vulne abili ies and Exposu es (CVE) e en s. CIA iad has i s oo s in mili a y
secu i y mindse , whe e he p o ec ion is pe ime e ocused agains ex e nal h ea s (Samonas and Coss, 2014).
Addi ionally, loss o CIA o in o ma ion o in o ma ion sys ems is used as basis in de elopmen o ele an
secu i y con ols (NIST, 2020)b.
3.1.2 On he Aspec s o CIA/AIC T iad in IT/OT
CIA iad o igina es om IT domain, whe e he secu i y ea u es aim o p o ide sa e y by p o ec ing i sel agains
cybe a acks. T adi ional OT domain’s sa e y aims o ensu e unc ional esilience and sa e y o p o ec he
en i onmen and humans agains unwan ed ope a ions ha could lead o physical damage o inju ies (Holle e
& e .al, 2022). Addi ionally, p io i ies conside ing he CIA iad a e in e se be ween adi ional IT and OT
en i onmen s, whe e IT en i onmen s p io i ise con iden iali y i s (CIA) and OT en i onmen s a ailabili y i s
(AIC)5. Wi h he OT 4.0 shi o in eg a ing IT capabili ies and in e acing OT de ices in o IT in as uc u e, he
di e ence be ween IT and OT is diminished, since i opens OT en i onmen s as a ge s agains cybe a acks. Fo
490
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024

A u Takala e al
example, cybe a acks may a ge OT en i onmen s o p e en he a ailabili y o sa e y unc ion o an OT de ice,
which may lead o unde mined sa e y o he en i onmen . Howe e , while loss o a ailabili y migh be he majo
h ea in OT en i onmen s, loss o con iden iali y and in eg i y may be used o cause loss o a ailabili y wi h
cybe a acks. In an au oma ed sys em, he loss o in eg i y can lead o a highe loss o a ailabili y. This is due o
he po en ial o sys em shu down igge ed by cascading adjus men s. These adjus men s a e based on he
alsi ied da a and a e in ended o s ee he sys em owa ds co ec unc ion. Fo example, i da a ou es ha e
hei in eg i y los (manipula ed de ice s a us epo ), he au oma ed sa e y sys em shu down may be used as
he a ack ec o o damage he equipmen , leading o loss o a ailabili y, which in u n impac s he secu i y
(Den lze &e .al,.2021). Simila ly, loss o con iden iali y on highe p i ileges and de ice da a may lead o hem
being used o aid in a acks agains he OT en i onmen 's a ailabili y. The e o e, while a ailabili y is he mos
impo an a ge o de end, con iden iali y and in eg i y a e inhe en ly connec ed o o e all a ailabili y in OT
4.0 en i onmen s. This leads o he need o balance all aspec s o he CIA iad o ensu e sa e y when designing
sys em con ols a he han p io i izing con iden iali y i s .
4. Backg ound Theo y
We ha e applied a design science esea ch me hodology, which is used adi ionally in sys em de elopmen
(He ne & e .al., 2004). As pa o he design science p ocess, he mul iple case s udy esea ch-based s a egy
by Yin (2004) and he knowledge base o he case s udies c ea e a co e amewo k o he go e nance model
and gene a e an added knowledge base. This i e a i e design science p ocess ou pu mus be di e en om he
p esen sys em. The MITRE A &ck (2023) amewo k has o med he common base o analyzing cybe -a acks,
ac ics, and scena ios. I has i s own weaknesses ela ed o indus y-based h ea classi ica ion, bu i is e y
sui able o apply o almos all kinds o companies. Ope a ional Technology-based ulne abili ies a e nowadays
he main a ge when he aim is o de elop a cohe en cybe secu i y en i onmen . The MITRE A ack amewo k
(2023) is an impo an elemen o he es ing p ocess. We ha e used da a om i in se e al cases.
The pape concen a es on da a in eg i y alida ion and i s p ocess. The p ocess will be alida ed using da a
om a ious poin s du ing execu ion. Ano he esea ch ocus concen a es on enhancing he isibili y o sec o -
based h ea in o ma ion. Two main aspec s mus be conside ed:
• Da a in eg i y alida ion may be done wi h da a senso s a a ious poin s, whe e he alues o he da a
may be compa ed o ensu e hei co ec ness. The a ious da a senso s may also be used o ack
p ocess s eps h oughou he sys em. This way he p ocess in eg i y may be a a ge o alida ion
ins ead, o ensu e i has no been ampe ed wi h. Fo example, wi h a ious da a senso s, he sys em
wa den may see ha he command sequence is manipula ed hal way h ough he p ocess, leading o
a di e en ou come han ini ially eques ed. This may be included wi h addi ional sys em-speci ic
in o ma ion, such as so wa e e sions, ha dwa e equipmen , and ne wo k p o ocols.
• When a sys em ulne abili y o malicious a ack is de ec ed, he addi ional sys em in o ma ion aids in
h ea in el and secu i y b each epo ing o he ele an s akeholde s. These companies may wo k in
simila o adjacen sec o s, whe e iden ical ha dwa e o so wa e is used. In summa y, he p ocess
alida ion may be used o p o ide con ex o h ea in el. Addi ionally, he NIS2 (2022) di ec i e
manda es sec o -based h ea in el epo ing, whe e companies a e obliga ed o epo o he ele an
go e nmen body abou possible secu i y b eaches. Using a ious da a senso s o p ocess alida ion
imp o es he isibili y o he secu i y p ocesses, which in u n aids in p o iding in o ma ion o
go e nmen al bodies. This, in u n, p o es ha he company is upholding i s obliga ions.
4.1 Poin o P ocess Moni o ing
Moni o ing a p ocess and i s da a a ic in OT en i onmen s aids in c ea ing a holis ic si ua ional awa eness, in
addi ion o p ocess awa eness, which includes elemen s such as s eps aken, ans e ed da a, used de ices, and
so wa e e sions. I a cybe a ack uses speci ic p ocess as an a ack ec o , p ocess-based moni o ing aids in
o ensics due o documen ed and moni o ed con en . Addi ionally, moni o ing a singula p ocess h ough
a ious da a senso s aids in audi ing p ocess unc ion e en s. Fo example, i a cybe a ack manipula es da a a
a pa icula s ep o a p ocess, such as du ing a log eques o SCADA command, i may be analysed in o ensics
owa ds a speci ic sec ion in in e ne in as uc u e whe e he s ep would occu . This p o ides addi ional
in o ma ion, which may be used in u he o ensics, such as he de ices (e.g., swi ch and IED) used in his speci ic
s ep, hei so wa e e sions, and p o ocols used in communica ion. This addi ional in o ma ion needs o be
manually managed in cases whe e he moni o ing ocuses on speci ic da a alues wi hou including p ocess as a
491
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
amewo k o con ex . Addi ionally, p ocess moni o ing enables analysis o causal ela ionship be ween s eps
and o he p ocesses. I a da a alue doesn’ change as expec ed a e a ce ain p ocess s ep is pe o med, i
could signal a po en ial comp omise.
4.2 Tes bed En i onmen
The es bed en i onmen de eloped by he Uni e si y o Jy äskylä is a unique pla o m o es ing di e en kinds
o ulne abili ies and h ea scena ios. Tes ing sepa a e so wa e, de ices, and ne wo k combina ions in many
ways is possible. Collabo a ion wi h business companies is essen ial and gene a es new da a o p o ec ing
c i ical in as uc u e.
We ha e es ed how o de ec and see h ea da a a di e en poin s. The used labo a o y en i onmen consis s
o a p ocess plan wi h i s OT de ices and he con ol and moni o ing ne wo k, as Figu e 1 illus a es. The plan
can be con olled wi h local and emo e SCADA sys em. Remo e con ol is implemen ed wi h an LTE connec ion.
A sepa a e moni o ing ne wo k is connec ed o he p ocess plan . Moni o ing is implemen ed by mi o ing he
ne wo k a ic om he cen al swi ch and OT de ice log in o ma ion om he cen al logging poin s o he
p ocess plan and he con ol cen e (O ice).
Figu e 1: Tes bed en i onmen
The Man-In-The-Middle (MITM, man = pe son, de ice) scena io is indica ed in ed, which is used o alida e he
p ocess-based da a in eg i y e i ica ion me hod. PITM da a comp omise is ca ied ou wi h an addi ional de ice
which is added o he connec ion be ween he p ocess plan and he o ice. Comp omised OT logs a e also
highligh ed in ed. The de ices u ilized in he scena io a e highligh ed in blue.
4.3 Use Case
4.3.1 En i onmen and Scena io
As Figu e 2 illus a es, he use case is depic ed wi h a eal-wo ld coun e pa . Sepa a e o ice space con ains
he plan 's con ol sys em, which is connec ed o he plan 's in e nal swi ch. The da a ans e be ween he
p oduc ion plan and he o ice space is emo ely moni o ed wi h a sepa a e SOC. Fu he mo e, one dis inc
isola ed ne wo k is employed o he su eillance o OT de ice logs, while a di e en ne wo k is used o di ec ly
eques OT de ice logs om he de ice i sel .
In his scena io, he a acke has access (physical o ne wo k) o he p ocess plan con ol ne wo k. The a acke
modi ies he da a ans e ed be ween he OT de ice and he cen al swi ch. By modi ying his da a, he a acke
can comp omise he si ua ional awa eness o he con ol sys em and SOC, e ade ins alled de ense mechanisms,
and disguise oo p in s le in he sys em. MITRE ATT&CK (2023) classi ies he a ack as a Man-In-The-Middle
(MITM, Pe son-In-The-Middle) echnique and a de ense e asion ac ic.
492
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
Figu e 2: Desc ip ion o he use case
4.3.2 Pe o med Use Case
Du ing he execu ed log eques p ocess, moni o ing occu s ia da a links a he cen al logging de ice, swi ch,
and IED. The IED epo s wi hin he in e nal ne wo k h ough he swi ch o he logging de ice, while ex e nal
epo ing is done ia an isola ed cable. Speci ically, he p ocess in ol es a log eques om he cen al logging
de ice o he IED h ough he swi ch, suppo ed by an addi ional ex e nal eques om he SOC.
The MITM a ack unde mines he in eg i y o he esponse o he cen al logging by manipula ing he sen da a.
This leads o cen al logging and swi ch da a links o epo inco ec s a us. F om he SOCs pe spec i e, he e is
a disc epancy in he s a us logs e u ned in esponse o he e en log eques : he swi ch and cen al logging
indica e a ‘local con ol’ s a us, while he IED epo s a ‘ emo e con ol’ s a us. This de ia ion is an anomaly,
p omp ing u he in es iga ion o iden i y po en ial mal unc ions o Indica o s o Comp omise (IoCs). By
analyzing he causal ela ionships o p ocess s eps and examining his o ical logs, we can de e mine whe he his
IED should be in a ‘ emo e con ol’ o ‘local con ol’ s a e based on p e ious s a e-change commands. This
e i ica ion p ocess helps pinpoin he loca ion o po en ial IoCs wi hin he in e ne in as uc u e.
5. Findings
The upcoming NIS 2 di ec i e equi es c i ical in as uc u e ope a o s o moni o hei sys ems o cybe -
h ea s. Ope a o s mus be able o epo any po en ial h ea s and in e p e he epo s o o he ope a o s. To
make he mos e ec i e use o po en ial h ea epo s, hey mus also include in o ma ion on he cause-and-
e ec ela ionship o which he h ea is ela ed.
The capabili y o moni o , log, and epo one's own beha io is i al o he OT de ice. Addi ionally, cen alized
moni o ing is c ucial o ensu e he co ec unc ionali y o he en i e sys em. Howe e , in OT en i onmen s,
he e a e ha dwa e limi a ions o moni o ing he in eg i y o he command-and-con ol p ocess. Fo his eason,
i is possible o add a sepa a e moni o ing ne wo k o he old sys ems. The moni o ing ne wo k moni o s
possible IT h ea s o he OT ne wo k, as well as h ea s ela ed o he in eg i y o he OT p ocess. The h ea
in o ma ion abou OT sys ems mus especially be able o be sha ed wi h ope a o s in he same sec o .
A he hea o he moni o ing ne wo k is a SOC, whe e IT and OT da a om he ne wo k a e collec ed. The SOC
mus be able o handle adi ional IT- ela ed cybe h ea s and OT- ela ed h ea s. These also include h ea s
ela ed o he in eg i y o he OT p ocess. The e o e, when collec ing and sha ing h ea in o ma ion om OT
sys ems, i is essen ial o include in o ma ion abou he en i onmen in which he h ea was de ec ed, including
de ices and p o ocols. The in o ma ion mus be s uc u ed so ha an ope a o in he same sec o can use he
h ea in o ma ion in hei own sys em. Also, Po en ial con iden ial business sec e s mus be conside ed when
493
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024
A u Takala e al
h ea in o ma ion is sha ed. The speci ic in o ma ion o be sha ed mus be ag eed upon sepa a ely, as he
de ailed analysis o i could po en ially expose hese sec e s.
The cu en si ua ion in OT en i onmen s ocuses on moni o ing ope a ing en i onmen s' pe o mance and
s a us o ensu e sa e y and eliabili y. Howe e , con e gence o IT and OT has led o a si ua ion whe e
ans e ed da a and ope a ion unc ions may be maliciously manipula ed h ough he IT in e acing elemen s.
In OT one me hod o e i y such manipula ion is based upon checksums, bu i o igina es om inding co up ed
packe s, no in en ional manipula ion. The majo i y o OT moni o ing is he e o e ocused upon whe he he
machine o unc ion is mechanically b oken o ha someone has unin en ionally con igu ed he de ice w ong.
Acco ding o p ocess con ol, an isola ed ne wo k and ha dwa e a e good o moni o ing he p ocess in a way
ha many senso s a e used. I is impo an o di ide wha is moni o ed and in wha con ex ; in he case o he
man-in- he-middle a ack, he en i e log epo ing p ocess is needed. Many checkpoin s show whe e he p ocess
wen w ong. I is impo an o analyze wha his can mean o he en i e sys em's ope a ion. A cause-and-e ec
ela ionship can be ound in he p ocess da a. We moni o p ocesses; in p ac ice, we moni o he ope a ion o
he elec ici y dis ibu ion ne wo k wi h ce ain de ices. Sec o -speci ic in o ma ion is dis ibu ed upwa ds. The
pu pose is o sha e and ecei e da a abou po en ial h ea s iden i ied in one's own sec o .
6. Conclusion
The e is a need o enhance he ma u i y le el o moni o ing e en s in he ope a ional echnology en i onmen .
Resea ched e en s om he IT and OT en i onmen s a e c ucial when he pu pose is o p oduce cohe en
si ua ional awa eness o he indus y en i onmen s. Wi hou he abili y o see he equi ed hings om he
IT/OT en i onmen , unde s anding he business si ua ion may disappea .
The isibili y o cybe secu i y p ocesses is c i ical o ul illing he equi emen s o Eu opean Union egula ions.
Se e al OT- ela ed s anda ds and special publica ions a e impo an in s ee ing he supply chain. Valida ion is a
se o ac ions ega ding he sys em equi emen , and i is impo an o ensu e hey a e ul illed.
NIS2 (Eu opean Pa liamen , 2022) equi es collabo a ion be ween he indus y sec o s and wi hin i . The
in o ma ion mus low, so he connec ion be ween he s a egic, ope a ional, and echnical le els is a c ucial
ac o ha enhances he o e all si ua ional awa eness wi hin sec o -based indus ies and a he en e p ise le el.
As ENISA (2023) s a es and NIS2 sugges , he e mus be unde s andable mechanisms whe e ope a ional
echnology- ela ed e en s a e ansmi ed and ans o med in o a o m ha gene a es added alue o he
decision-make s. I is no enough o achie e a epo ha indica es e en s. The e should be in o ma ion abou
he ype o ulne abili ies and a desc ip ion o he whole p ocess, including he sou ce o he h ea and po en ial
consequences. Because many a emp s o he ad e sa ies’ a acks a e being ied again, ja, unin en ional e en s
o inciden s a e o en epea ed. Decision-make s should be able o make decisions ega ding business con inui y
and in o ma ion-sha ing capabili ies depending on he secu i y ope a ion cen e 's ma u i y o de ec ope a ional
echnology- ela ed h ea s deep enough. Tha is impossible wi hou ga he ing and combining di e en kinds o
da a om he physical and ne wo ked senso s. So, he amewo k o he p ocess con ol mechanism ha ga he s
da a and sha es da a om he Ope a ional Technology en i onmen o he SOC is c ucial o enhance ope a ional
echnology cybe secu i y a he g ound le el. The de eloped axonomy has i s own ole in o ming si ua ional
awa eness (NIS Coope a ion G oup, 2018), bu i mus be kep up o da e mo e e icien ly because o he
de elopmen o po en ial inciden s.
The CSG p ojec concen a es on de eloping he go e nance model o he OT en i onmen s. All esea ch da a
om he es bed en i onmen suppo he de elopmen p ocess o he go e nance model.
Acknowledgmen s
The esea ch was suppo ed by Business Finland (g an numbe 10/31/2022) and he Uni e si y o Jy äskylä.
Re e ences
CISA (2020) C i ical In as uc u e Sec o s. h ps://www.cisa.go / opics/c i ical-in as uc u e-secu i y-and-
esilience/c i ical-in as uc u e-sec o s
Denzle P., Holle e S., F ühwi h T., and Kas ne W. (2021) Iden i ica ion o secu i y h ea s, sa e y haza ds, and
in e dependencies in indus ial edge compu ing. In The Six h
ACM/IEEE Symposium on Edge Compu ing (SEC' 21), Decembe 14–17, 2021, San Jose, CA, USA. ACM, New Yo k, NY, USA.
494
P oceedings o he 23 d Eu opean Con e ence on Cybe Wa a e and Secu i y, ECCWS 2024