The integration of cyber-physical systems into critical infrastructures, such as power grids and manufacturing plants, necessitates robust security measures to safeguard Industrial Control Systems from malicious threats. Due to the unique operational demands of ICS environments, traditional IT security measures are often unsuitable. To address these challenges, we present our approach for enhancing cybersecurity in energy generation plants by correlating and consolidating alerts and logs from various monitoring devices, thereby providing real-time dashboards for anomaly and threat detection. The approach is based on the development of a platform that aids Security Operation Center (SOC) teams in monitoring operational technology within industrial networks. The paper outlines the functionalities of the platform, that will be developed within the "SOC OT Impianti Generazione Energia" (SOC-OT IGE) project.

Toward a Security Operation Center for Operational Technology in Industrial Networks

Gaggero G. B.;Caviglia R.;Girdinio P.;Marchese M.
2024-01-01

Abstract

The integration of cyber-physical systems into critical infrastructures, such as power grids and manufacturing plants, necessitates robust security measures to safeguard Industrial Control Systems from malicious threats. Due to the unique operational demands of ICS environments, traditional IT security measures are often unsuitable. To address these challenges, we present our approach for enhancing cybersecurity in energy generation plants by correlating and consolidating alerts and logs from various monitoring devices, thereby providing real-time dashboards for anomaly and threat detection. The approach is based on the development of a platform that aids Security Operation Center (SOC) teams in monitoring operational technology within industrial networks. The paper outlines the functionalities of the platform, that will be developed within the "SOC OT Impianti Generazione Energia" (SOC-OT IGE) project.
2024
9798331505585
File in questo prodotto:
File Dimensione Formato  
Toward_a_Security_Operation_Center_for_Operational_Technology_in_Industrial_Networks.pdf

accesso chiuso

Tipologia: Documento in versione editoriale
Dimensione 589.4 kB
Formato Adobe PDF
589.4 kB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1273076
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 2
social impact