Source-linked AI summary

Cybersecurity of Industrial Cyber-Physical Systems: A Review

Hakan Kayan, Matthew Nunes, Omer Rana, Pete Burnap, Charith Perera

arXiv:2101.03564v1cs.CR

TL;DR

ICPS cybersecurity research must address increasingly interconnected industrial systems whose security supports critical-infrastructure survivability, while existing literature remains fragmented. The paper defines and relates ICPS technologies, reviews protocols and vulnerabilities, proposes an adaptive attack taxonomy, evaluates real incidents, and identifies research shortcomings and directions.

  • Problem

    ICPS interconnectivity increases cybersecurity challenges, while fragmented literature and limited synthesis of industrial vulnerability reports hinder unified security research.

  • Method

    The paper defines ICPS-related technologies, reviews protocols, infrastructures, vulnerabilities, defenses, and edge security, and proposes an adaptive taxonomy for evaluating real incidents.

  • Results

    The incident evaluation finds manufacturing and electricity, gas, steam, and air-conditioning supply among the most targeted sectors; attacks are mostly active, organized by nation/state groups, and aimed at data integrity.

  • Takeaways & Limitations

    Weak IT–OT boundary protection is the most exploited case identified in ICPS incidents, and attackers commonly use phishing and multi-stage operations.

  • Takeaways & Limitations

    ICPS security evaluation is constrained by limited realistic testbed validation, simulation-heavy studies, outdated or unavailable datasets, and restricted public access to current industrial traffic.

Abstract

from arXiv · show

Industrial cyber-physical systems (ICPSs) manage critical infrastructures by controlling the processes based on the "physics" data gathered by edge sensor networks. Recent innovations in ubiquitous computing and communication technologies have prompted the rapid integration of highly interconnected systems to ICPSs. Hence, the "security by obscurity" principle provided by air-gapping is no longer followed. As the interconnectivity in ICPSs increases, so does the attack surface. Industrial vulnerability assessment reports have shown that a variety of new vulnerabilities have occurred due to this transition while the most common ones are related to weak boundary protection. Although there are existing surveys in this context, very little is mentioned regarding these reports. This paper bridges this gap by defining and reviewing ICPSs from a cybersecurity perspective. In particular, multi-dimensional adaptive attack taxonomy is presented and utilized for evaluating real-life ICPS cyber incidents. We also identify the general shortcomings and highlight the points that cause a gap in existing literature while defining future research directions.

1 Introduction

ICPSs support critical infrastructures whose compromise can have catastrophic consequences, but their rapid integration creates cybersecurity challenges and fragmented research. This review addresses the fragmentation by defining related systems, distinguishing industrial security requirements, and consolidating taxonomies, reports, and defenses.

  • Compromising critical infrastructures can produce catastrophic impacts, making ICPS security essential to infrastructure survivability.
  • ICPS security requires solutions tailored to harsh industrial environments rather than direct reuse of CPS security approaches.
  • Existing ICPS security literature is diverse in taxonomies, metrics, implementation techniques, and test environments, limiting unified discussion of research outputs.
  • The review defines ICPS-related systems, explains IT–OT differences, surveys protocols and infrastructures, and presents an adaptive attack taxonomy.
  • The paper also reviews industrial vulnerability reports, defenses for common vulnerabilities, ICPS security characteristics, and edge-network trends.

2 INDUSTRIAL SYSTEMS & INFRASTRUCTURES

Industrial systems have evolved from isolated control environments into interconnected ICPSs combining cyber and physical components across heterogeneous architectures. This evolution improves connectivity and capability while introducing distinct IT–OT security concerns and the need to clarify relationships among industrial technologies.

  • 2.1 Industrial System Definitions: IWSNs support industrial monitoring where availability is primary, while IIoT connects industrial devices, networks, and services through the internet.
  • 2.1 Industrial System Definitions: ICS evolved from air-gapped systems using proprietary protocols into systems integrated with IWSN, IIoT, and newer PLC technologies.
  • 2.1 Industrial System Definitions: ICPSs combine cyber and physical components and are deployed across manufacturing, transportation, healthcare, and energy domains.
  • 2.1 Industrial System Definitions: Sensors convert physical data into cyber data, while actuators convert cyber data into physical phenomena within industrial control processes.
  • 2.1 Industrial System Definitions: Modern ICPS architectures process sensor data at the edge, send it to PLCs over wireless channels, and expose stored data through corporate and outer networks.
  • 2.2 The Relationship Between Industrial Technologies: The paper argues that interchangeable use of industrial terms obscures their relationships and motivates a framework positioning complementary technologies.
  • 2.3 Information Technology vs Operational Technology: IT processes information, whereas OT monitors and controls physical phenomena and must operate in real time because industrial availability is paramount.

3 ICPS Communication Technologies & Protocols

ICPS communication technologies vary by protocol openness, transmission medium, data-flow direction, and network topology. Industrial networks increasingly combine wired and wireless technologies, with Ethernet gaining deployment share over Fieldbus.

  • Industrial communication protocols are classified by standard availability, communication type, and network topology.
  • Wired and wireless technologies differ in deployment characteristics, with wireless systems easier to deploy but vulnerable to interference in high-noise environments.
  • Industrial topologies include point-to-point, bus, ring, star, mesh, and hybrid arrangements, each involving distinct cost, robustness, and failure trade-offs.
  • Fieldbus, industrial Ethernet, and wireless are the main categories of currently available industrial communication technologies.
  • EtherNet/IP and Profinet led the industrial network market in 2019, with EtherNet/IP popular in the USA and Profinet widely accepted in Europe.
  • Industrial Ethernet deployment increased 5% while Fieldbus deployment decreased 5% from 2019 to 2020, indicating a transition toward Ethernet.
  • Modbus is an open protocol available in fieldbus and Ethernet variants and can integrate with PLCs from multiple vendors.
  • Profinet is an open Industrial Ethernet standard offering low response time, flexible Ethernet connectivity, and interaction with IoT infrastructure.

4 ICPS Cybersecurity Analysis

The paper surveys ICPS-related systems and identifies a need for a multi-dimensional adaptive attack taxonomy to support cybersecurity analysis.

  • 4 ICPS Cybersecurity Analysis: The section surveys ICPS, IWSN, IIoT, ICS, DCS, and SCADA security literature and introduces a multi-dimensional adaptive ICPS attack taxonomy.It also reviews real-life incidents, vulnerability assessment reports, security characteristics, and countermeasures.
  • 4 ICPS Cybersecurity Analysis: The paper compares communication protocols that can be deployed in ICPS.

4.1 ICPS Attack Taxonomy

The proposed ICPS attack taxonomy organizes incidents across multiple dimensions, combining established classifications to represent attack context, technique, scope, and security objectives.

  • 4.1 ICPS Attack Taxonomy: The taxonomy is designed to be mutually exclusive, exhaustive, unambiguous, repeatable, accepted, and useful, while incorporating vulnerabilities and countermeasures.
  • 4.1 ICPS Attack Taxonomy: Industrial sector uses the UK SIC classification, which is aligned with European Union and United Nations standardization.
  • 4.1 ICPS Attack Taxonomy: The taxonomy combines CAPEC for attack mechanism and domain, SIC for industrial sector, and NIST for threat source, but depends on CAPEC remaining updated.
  • 4.1 ICPS Attack Taxonomy: Threat source identifies who or what is behind an incident and uses NIST’s definition, including distinctions between attackers and compromised intermediaries.
  • 4.1 ICPS Attack Taxonomy: Attack scope distinguishes cyber, physical, and cyber-physical attacks according to whether the target and consequences involve cyber systems, physical systems, or both.
  • 4.1 ICPS Attack Taxonomy: Attack domain classifies patterns into software, hardware, communications, supply chain, social engineering, and physical security using CAPEC.
  • 4.1 ICPS Attack Taxonomy: Attack mechanism describes the technique used, and one attack may contain several mechanisms, as in advanced persistent threat attacks.
  • 4.1 ICPS Attack Taxonomy: Attack type separates active from passive attacks, while targeted principle covers confidentiality, availability, and integrity, with attacks potentially affecting multiple principles.

4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy

The paper evaluates 15 major ICPS incidents using its attack taxonomy and finds recurring patterns involving industrial sectors, threat sources, attack types, and targeted principles.

  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: The evaluation covers 15 significant ICPS incidents and presents their timeline and taxonomy-based assessment.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: The Maroochy Shire incident involved an insider manipulating 142 sewage pumping stations and causing around one million liters of sewage to spill.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: Stuxnet infected more than 100,000 hosts in 25 countries and targeted Microsoft operating systems and Siemens PLCs to generate physical anomalies.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: Manufacturing and electricity, gas, steam, and air conditioning supply are the most targeted industrial sectors.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: Most evaluated attacks are active, organized by nation/state-established groups, and aimed at disrupting data integrity; no major case is physical-only.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: The incidents commonly involved multi-stage attacks, with advanced attacks potentially executing the entire Cyber Kill Chain.
  • 4.2 Evaluation of Real-life ICPS Incidents Based on ICPS Attack Taxonomy: Weak boundary protection between integrated IT and OT networks was the most exploited case identified across the incidents.

4.3 ICPS Vulnerability Assessment Reports

The paper reviews vulnerability and breach reports to characterize risks introduced by IT–OT integration, emphasizing weak boundary protection and the potential impact of OT compromises.

  • 4.3 ICPS Vulnerability Assessment Reports: Risk assessment is required because ICPS assets differ across systems and rapidly evolve as new technologies are integrated.
  • 4.3 ICPS Vulnerability Assessment Reports: ICS-CERT reports for 2015 and 2016 found that integrating IT with OT caused new vulnerabilities, most commonly involving weak boundary protection.
  • 4.3 ICPS Vulnerability Assessment Reports: Weak boundaries between OT and enterprise IT networks may enable unauthorized access, and an industrial demilitarized zone is one mitigation approach.
  • 4.3 ICPS Vulnerability Assessment Reports: Verizon’s report found that 4% of confirmed breaches belonged to OT systems, although the paper notes that these breaches may have greater impact than IT-related breaches.
  • 4.3 ICPS Vulnerability Assessment Reports: Among 381 breaches against industrial systems, financial gain was the main reason behind 86% of attacks, and organized groups formed 55% of threat actors.

4.4 Countermeasures Against Most Common ICPS Vulnerabilities

The survey reviews countermeasures for common ICPS vulnerabilities, emphasizing boundary protection, least functionality, authentication, monitoring, password enforcement, access control, and resource allocation. These measures address risks introduced by integrating IT technologies with OT and expanding remote access.

  • 45.90% of total ICPS vulnerabilities in 2016 were represented by the top ten vulnerabilities, with boundary protection most common and weak authentication second.The vulnerabilities were identified by ICS-CERT using the NIST classification.
  • Boundary Protection: Boundary protection research strengthens fading IT–OT boundaries through DMZs, firewalls, defense-in-depth simulations, and intrusion detection.A DMZ is described as a first step, although DMZs themselves remain attackable.
  • Least Functionality: Least-functionality countermeasures restrict unnecessary ports, protocols, and services, including optimized multipath routing and node deployment.The reviewed approaches use random multipath routing and enhanced particle swarm optimization, with benchmarking and economic load-dispatch evaluation.
  • Authentication: Authentication mechanisms identify human-to-machine and machine-to-machine entities at the edge to prevent unauthorized actions and falsified sensor data.The passages also review touch-based, biometric, and continuous authentication for facility and computer access.
  • Audit Review and Analysis: SIEM systems centralize log management, while threat-level rating prioritizes alerts against decoy attacks and secure event detection validates edge data.The reviewed studies classify threats into four priority levels and evaluate schemes on balanced or real-world datasets.
  • Access Control and Password Enforcement: Password policies require changing vendor defaults, removing unnecessary passwords, and encrypting credentials; least privilege and temporary-account policies limit access.Security-resource allocation studies also apply authentication and least privilege before allocating resources, while emergency accounts should be disabled after use.
  • Remote Access: Cloud and wireless-sensor integration enables remote ICPS monitoring and management but adds access points that increase the attack surface.The expansion of remote substations and data forwarding requires additional security measures.

4.5 ICPS Cybersecurity Characteristics

The paper characterizes secure ICPSs through defense-in-depth and properties that account for industrial continuity and interconnection. Robustness, resilience, and redundancy address failure, recovery, and continued operation across system assets.

  • Defense-in-Depth: Defense-in-depth applies several security layers across all critical-infrastructure assets because sophisticated attacks target ICPS-managed infrastructures.Layers can differ for technical assets while sharing similarities for personnel-related protections.
  • Robustness: Robustness measures how much an industrial system can endure before failing, requiring testing after changes and periodic testing for component degradation.The property is especially significant because highly interconnected ICPSs can exhibit cascading effects.
  • Resilience: Resilience measures recovery time after anomalies, and unlike IT systems, OT systems supervising critical infrastructures must continue operating during intrusions.Software-defined networking is identified as one technique for routing models that increase ICPS resiliency.
  • Evaluation Characteristics: Table 7 evaluates proposed countermeasures using dataset availability, evaluation method, privacy, and AI/ML utilization.The table’s footnote states that “others” include benchmarking tests, simulations, or proof of concept.
  • Redundancy: Redundancy keeps production monitoring active by using backup sensors when a sensor fails.ICPS edge monitoring supervises assets including robotic arms, conveyor belts, gas tanks, and ovens.

4.6 Securing ICPS Edge Network

The paper links ICPS edge security to attacks that exploit weak boundaries or infiltrate industrial components to manipulate actuator behavior and falsify sensor readings. It also identifies evaluation, testbed, dataset, resource, and data-access challenges affecting edge anomaly detection research.

  • Securing ICPS Edge Network: Most evaluated ICPS incidents target edge networks by crossing weak IT–OT boundaries or infiltrating HMIs and PLCs to disrupt actuator behavior.After breaching systems, adversaries first fake sensor readings to bypass deployed protections.
  • Edge Anomaly Detection: Anomaly-detection surveys report inconsistent evaluation metrics, limited simultaneous use of simulation, testbed, and real-world data, and insufficient attention to adversaries in control.They recommend deploying monitoring at the edge rather than only in the central network.
  • ICPS Testbeds: Hardware-in-the-loop testbeds are considered better for simulating real-world cases because hardware is required to test cyber-physical components.Their increasing availability has supported vulnerability assessment.
  • ICPS Datasets: 24 of 28 surveyed CPS intrusion-detection papers used datasets, but 22 did not share them, while 6 used simulated rather than operational datasets.Physical-process monitoring is identified as a key aspect of intrusion detection.
  • Limitations and Research Gaps: Resource-constrained operation, non-adversarial anomalies, questionable access to realistic testbeds, outdated benchmark datasets, privacy, and undisclosed data limit current industrial anomaly-detection evaluation.The paper notes that many studies rely on simulation-only testbeds and that unreleased datasets make evaluation more difficult.

5 LESSONS LEARNED

The review identifies shortcomings in industrial cybersecurity evaluation, adaptability, classification, security-policy research, redundancy, and realistic testbed and dataset use.

  • Industrial cybersecurity remains early in development, with inadequate common evaluation frameworks and overlooked policy-based and redundant solutions.The review also identifies unclear relationships among emerging industrial technologies and inefficient use of realistic testbeds and current datasets.
  • Industrial terminology lacks a clear classification framework, limiting distinctions among ICPS, ICS, IIoT, IWSN, and related disciplines.The authors define selected terms but state that their relationships require further study.
  • Weak boundary protection is followed by policy-based weaknesses, but their evaluation is constrained because disrupting critical ICPS operations is unacceptable.Hardware extensions have been proposed, yet their efficiency remains questionable without a common evaluation framework.
  • Outdated security mechanisms are identified as a main reason for data breaches, while continuous industrial monitoring makes redeployment impractical.The review therefore calls for flexible, adaptive solutions requiring minimal human intervention.
  • Realistic testbed fidelity is rarely demonstrated, simulations often use only one testbed, and publicly available datasets with recent malware traffic are scarce.Limited dataset release also makes comparison with similar studies difficult.
  • Academic work emphasizes post-attack intrusion detection while comparatively neglecting pre-attack security policies and redundancy.The review notes that most studies focus on resilience and robustness while only slightly addressing redundancy.

6 Research Challenges and Directions

The paper derives research challenges from inadequate evaluation environments, outdated protection, and overlooked redundancy, then proposes adaptive, realistic, and safer evaluation directions for ICPS cybersecurity.

  • 6.1 Adaptability and Context Awareness: ICPS cybersecurity requires adaptive, autonomous, and non-stop protection because outdated mechanisms are prone to fail against newer attack methods.The paper proposes an adaptive ICPS attack taxonomy, whose validity depends on CAPEC and may not capture every industrial application.
  • 6 Research Challenges and Directions: Context-aware sensors and edge nodes support adaptability and redundancy in an ideal evaluation environment spanning four interconnected testbeds.The environment connects sensors to the main network, edge nodes to an isolated network and cloud, and testbeds to a control center.
  • 6.1 Adaptability and Context Awareness: Context-awareness is identified as a promising feature for future adaptive ICPS edge-security studies, while machine-learning workflows require precautions against adversarial attacks.The paper specifically mentions model exploration and data poisoning threats during training.
  • 6.2 Redundancy and Resilience: Redundancy is the most overlooked characteristic affecting ICPS security and resilience, but duplicating systems for every heterogeneous industrial process is often too costly.The German Steel Mill incident is presented as an example where an additional furnace shutdown system could have prevented the incident.
  • 6.3 Testbeds and Synthetic Datasets: Because real ICPS experimentation risks disrupting critical infrastructures, the paper recommends realistic testbeds and privacy-free synthetic datasets containing malicious and normal traffic.Advanced industrial simulation environments could generate robust synthetic datasets for machine-learning models, using attacks or honeypots.

7 Conclusions

The paper reviews ICPS cybersecurity comprehensively, from architecture and protocols to incidents, edge security, vulnerabilities, evaluation metrics, and future research needs.

  • The survey analyzes ICPS architecture, defining its components and emphasizing operational technology’s unique characteristics.
  • It examines ICPS communication protocols and proposes an adaptive attack taxonomy for evaluating real-life cyber incidents.
  • The paper reviews edge security trends and how academia addresses ICPS vulnerabilities through proposed security mechanisms.
  • It evaluates security studies using metrics aimed at maintaining ICPS continuity.
  • The authors identify datasets, testbeds, machine learning techniques, and security policies as directions shaping future ICPS security.
Loading 2101.03564v1…