Carol Lo Carol.Lo@uwe.ac.uk
TSU Business support coordinator NOM
TRIST: Towards a container-based ICS testbed for cyber threat simulation and anomaly detection
Lo, Carol; Christie, Jack; Win, Thu Yein; Rezaeifar, Zeinab; Khan, Zaheer; Legg, Phil
Authors
Jack Christie
Thu Yein Win
Zeinab Rezaeifar
Zaheer Khan Zaheer2.Khan@uwe.ac.uk
Professor in Computer Science
Professor Phil Legg Phil.Legg@uwe.ac.uk
Professor in Cyber Security
Abstract
Cyber-attacks on Industrial Control Systems (ICS), as exemplified by the incidents at the Maroochy water treatment plant and the Ukraine's electric power grid, have demonstrated that cyber threats can inflict significant physical impacts. These incidents caused widespread service disruptions and substantial economic losses, underscoring the urgent need for an in-depth understanding of cyber threats in industrial environments. Industrial security research is usually conducted on physical testbeds to avoid safety issues, production interruptions and other operational constraints in industrial processes. Nevertheless, security defenders often encounter obstacles in developing or accessing physical testbeds due to associated costs and complexities. These factors hinder research progress to devise early detection mechanisms for cyber threats-essential for effective incident response. To overcome these obstacles, this paper presents a container-based virtual testbed. Its lightweight architecture enables replicable and efficient deployment of testbeds at low cost for simulating cyber threats on Cyber-Physical Systems (CPS)-the cornerstone of industrial automation and control systems. Also, the container-based virtual testbed provides a cost-effective option for producing datasets for training, testing and optimization of unsupervised anomaly detection models. Besides, an evaluation on resource consumption is conducted. The paper also discusses the benefits and limitations of proposed container-based ICS testbeds and suggests future research areas.
Presentation Conference Type | Conference Paper (published) |
---|---|
Conference Name | Cyber Science 2024 |
Start Date | Jun 27, 2024 |
End Date | Jun 28, 2024 |
Acceptance Date | Apr 30, 2024 |
Deposit Date | Jun 4, 2024 |
Book Title | Springer Proceedings in Complexity book series |
Keywords | Cybersecurity; Testbeds; Industrial Control Systems; Cyber-Physi- cal Systems; Container; Threat Simulation; Datasets; Anomaly Detection |
Public URL | https://uwe-repository.worktribe.com/output/12034510 |
This file is under embargo due to copyright reasons.
Contact Carol.Lo@uwe.ac.uk to request a copy for personal use.
You might also like
Digital twins in industry 4.0 cyber security
(2024)
Presentation / Conference Contribution
Digital twins of cyber physical systems in smart manufacturing for threat simulation and detection with deep learning for time series classification
(2024)
Presentation / Conference Contribution
PROTECT: Container process isolation using system call interception
(2017)
Presentation / Conference Contribution
Detection of malware and kernel-level rootkits in cloud computing environments
(2016)
Presentation / Conference Contribution
Downloadable Citations
About UWE Bristol Research Repository
Administrator e-mail: repository@uwe.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2024
Advanced Search