arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

面向网络安全研究的可用工业控制系统(ICS)数据集与测试床路线图

A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

Ebtesam J. Alqahtani, Mohammad Hammoudeh

arXiv 2608.30332首次发表:更新:

发表机构

King Fahd University of Petroleum and Minerals(阿卜杜拉国王科技大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文梳理现有ICS网络安全数据集、测试床及数字孪生,分析其优缺点,指出相关研究缺口并提出建议,为该领域研究提供路线图。

AI 中文摘要

工业控制系统(ICS)是众多关键基础设施领域的核心支柱,然而其日益提升的连接性、较长的生命周期以及与信息技术(IT)环境的融合,带来了诸多网络安全挑战。运营技术(OT)与IT的融合,加上工业4.0技术的部署,扩大了ICS环境的攻击面,进而使其更易受到高级网络威胁。因此,众多研究人员对ICS网络安全领域产生了兴趣,ICS的入侵检测、异常检测、威胁情报、攻击模拟及弹性评估等主题已受到大量关注。尽管如此,由于缺乏合适的数据集和实验环境,ICS网络安全解决方案的开发与测试仍颇具挑战性。本文的主要目标是提供现有ICS网络安全数据集、测试床及数字孪生的路线图,呈现各类分类法,并对这些工具的架构、特征、能力、优缺点进行系统分析。分析结果表明存在诸多持续问题,如缺乏标准化基准数据集、缺乏现代攻击场景、基于真实运营流量的数据集数量不足、难以验证人工智能驱动的网络安全解决方案。除总结当前关于ICS网络安全数据集与测试床的研究外,该路线图还明确了研究缺口,并就创建新工具提出建议。

英文摘要

Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along with the deployment of Industry 4.0 technologies increases the attack surface of ICS environments, which in turn makes them more vulnerable to advanced cyber threats. Therefore, many researchers have shown interest in the field of cybersecurity of ICS. The topics of intrusion detection, anomaly detection, threat intelligence, attack simulation and resilience assessment of ICS have received much attention. Nevertheless, the development and testing of cybersecurity solutions for ICS remains to be challenging due to the lack of appropriate datasets and experimental environment. The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins. This paper presents various taxonomies along with systematic analysis of architecture, characteristics, capabilities, pros and cons of these tools. The results of the analysis demonstrate the presence of persistent problems such as lack of standardized benchmarking datasets, lack of modern attack scenarios, insufficient number of datasets based on real operational traffic and difficulty in validating artificial intelligence-driven cybersecurity solutions. In addition to summarizing current research on ICS cybersecurity datasets and testbeds, this roadmap provides the identification of research gaps and recommendations on creation of new tools.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑