One of the main current challenges for Security Information and Event Management (SIEM) platforms is to integrate data generated by Industrial Control Systems (ICS). This paper analyzes the issue in an energy-utility company, and it proposes a possible reference architectural scheme for the cyber-security monitoring of Operational Technology (OT) networks, making use of probes and dedicated Intrusion Detection Systems (IDS) to integrate OT logs. The paper presents some examples from real use cases and discusses future improvements of the SIEM technology to integrate heterogeneous data sources (Information Technology (IT) and OT) to develop proper correlation rules.

Integrating OT data in SIEM platforms: an Energy Utility Perspective

Alessandro Armellin;Giovanni Battista Gaggero;Mario Marchese
2023-01-01

Abstract

One of the main current challenges for Security Information and Event Management (SIEM) platforms is to integrate data generated by Industrial Control Systems (ICS). This paper analyzes the issue in an energy-utility company, and it proposes a possible reference architectural scheme for the cyber-security monitoring of Operational Technology (OT) networks, making use of probes and dedicated Intrusion Detection Systems (IDS) to integrate OT logs. The paper presents some examples from real use cases and discusses future improvements of the SIEM technology to integrate heterogeneous data sources (Information Technology (IT) and OT) to develop proper correlation rules.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1213359
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? ND
social impact