Defending industrial internet of things against Modbus/TCP threats: A combined AI-based detection and SDN-based mitigation solution


연구 분야: Networking



학회: International Journal of Information Security


초록

Industrial Internet of Things (IIoT) environments are ushering in new avenues for connectivity and intelligent control, yet their integration with legacy systems poses substantial security challenges. Present cybersecurity frameworks are insufficient for safeguarding protocols like Modbus/TCP, widely employed in critical infrastructures such as smart grids and healthcare. This protocol’s inherent vulnerabilities-specifically, the lack of robust authentication and authorisation mechanisms-render industrial networks susceptible to a spectrum of cyberattacks with potentially cascading effects. The research motivation stems from the urgent need for an adaptive, robust security solution that bridges this gap. To address these issues, we propose an integrated approach that combines advanced threat modeling with state-of-the-art detection and mitigation techniques. First, we develop a comprehensive Modbus/TCP threat model by integrating STRIDE-per-element analysis, Attack Defence Trees (ADT), and risk assessment frameworks (CVSS and OWASP-RR) to quantitatively and qualitatively evaluate 14 distinct cyber threats. Next, we introduce a novel Intrusion Detection and Prevention System (IDPS) that leverages an Active ResNet50-based Convolutional Neural Network enhanced with Transfer Learning and Active Learning. This enables automated detection and classification of cyberattacks through continuous re-training based on human verification. Finally, our system employs a Software Defined Networking (SDN)-based mitigation strategy, using Thompson Sampling for adaptive, cost-effective decision-making. Experimental evaluation on a custom Modbus/TCP dataset demonstrates improved accuracy, higher True Positive Rates, and reduced False Positive Rates compared to conventional methods. These outcomes substantiate that integrating AI-driven detection with SDN-based mitigation offers a viable and robust framework to minimize cyberattack impacts on critical IIoT infrastructures.


Author Profile
Thanasis Kotsiopoulos

Department of Electrical and Computer Engineering University of Western Macedonia Campus ZEP Kozani 50100 Kozani Greece

Andorra
Author Profile
Panagiotis Radoglou-Grammatikis

Department of Electrical and Computer Engineering University of Western Macedonia Campus ZEP Kozani 50100 Kozani Greece

Andorra
Author Profile
Zacharenia Lekka

K3Y Ltd Studentski District Vitosha Quarter Bl. 9 1700 Sofia Bulgaria

Bulgaria

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Bulgaria, Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (79건)