Fortifying industrial cybersecurity: a novel industrial internet of things architecture enhanced by honeypot integration
Abstract
The industrial internet of things (IIoT) has significantly transformed the industrial sectors by connecting devices, machines, and systems to enhance automation, efficiency, and decision-making. However, the increased interconnectivity also poses significant security challenges because IIoT devices control critical infrastructures and processes. Our work presents an implementation of a robust industrial cybersecurity strategy with a segmented network architecture, collaborative efforts between information technology (IT) and operational technology (OT) teams for enhanced resilience and effectiveness, and vertical honeypots across all Industry 4.0 levels integrated with Wazuh for log transmission and proactive threat response, alongside Snort intrusion detection system (IDS) monitoring network traffic. Additionally, we reinforce our architecture by Wazuh with Elasticsearch and Kibana as a security information and event management solution, facilitating data analysis and compliance enforcement through custom rulesets and cybersecurity threat intelligence (CTI) integration, with automatic updates for continuous adaptation against emerging threats.
Keywords
Cyber-attacks; Honeypot; Industrial internet of things; Industry 4.0; Intrusion detection system; Threat intelligence
Full Text:
PDFDOI: http://doi.org/10.11591/ijece.v15i1.pp1089-1098
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
International Journal of Electrical and Computer Engineering (IJECE)
p-ISSN 2088-8708, e-ISSN 2722-2578
This journal is published by the Institute of Advanced Engineering and Science (IAES) in collaboration with Intelektual Pustaka Media Utama (IPMU).