A Big Data Fusion to Profile CPS Security Threats Against Operational Technology
Karl Biron, Wael Bazzaza, Khalid Yaqoob, Amjad Gawanmeh, Claude Fachkha · 2020
Internet security measurements are fundamental techniques to detect cyber attacks and generate intelligence. However, such methods are limited in terms of relevancy, scalability, and data availability when it comes to Operational Technology (OT). Therefore, in this paper, we build cyber security capabilities to collect, detect, analyze, and visualize in near real-time cyberattacks targeting Cyber-Physical Systems (CPS). The latter is a critical component for Industry 4.0 and smart technologies. In order to achieve our tasks, we propose a big data fusion model, which correlates among two trap-based monitoring systems, namely, darknet and honeypot. With approximately hundred deployed sensors (monitors) over a six-month period, we have been able to collect several unauthorized and malicious activities originating from 226 countries. Furthermore, our investigation has revealed various scanning strategies such as CPS-focused scans, in addition to real exploits used by external sources to infiltrate our network. Finally, this study highlighted the importance of such monitoring systems and compare the efficiency among them with an aim to complement existing CPS and on-premise OT security solutions.