One of the main current challenges for Security Information and Event Management (SIEM) platforms is to integrate data generated by Industrial Control Systems (ICS). This paper analyzes the issue in an energy-utility company, and it proposes a possible reference architectural scheme for the cyber-security monitoring of Operational Technology (OT) networks, making use of probes and dedicated Intrusion Detection Systems (IDS) to integrate OT logs. The paper presents some examples from real use cases and discusses future improvements of the SIEM technology to integrate heterogeneous data sources (Information Technology (IT) and OT) to develop proper correlation rules.

Integrating OT data in SIEM platforms: an Energy Utility Perspective

Alessandro Armellin;Giovanni Battista Gaggero;Mario Marchese
2023-01-01

Abstract

One of the main current challenges for Security Information and Event Management (SIEM) platforms is to integrate data generated by Industrial Control Systems (ICS). This paper analyzes the issue in an energy-utility company, and it proposes a possible reference architectural scheme for the cyber-security monitoring of Operational Technology (OT) networks, making use of probes and dedicated Intrusion Detection Systems (IDS) to integrate OT logs. The paper presents some examples from real use cases and discusses future improvements of the SIEM technology to integrate heterogeneous data sources (Information Technology (IT) and OT) to develop proper correlation rules.
File in questo prodotto:
File Dimensione Formato  
Integrating_OT_data_in_SIEM_platforms_an_Energy_Utility_Perspective.pdf

accesso chiuso

Tipologia: Documento in versione editoriale
Dimensione 1.94 MB
Formato Adobe PDF
1.94 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1213359
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 4
  • ???jsp.display-item.citation.isi??? ND
social impact