Fortifying industrial cybersecurity: a novel industrial internet of things architecture enhanced by honeypot integration

Oumaima El Kouari, Saiida Lazaar, Tarik Achoughi

Abstract


The industrial internet of things (IIoT) has significantly transformed the industrial sectors by connecting devices, machines, and systems to enhance automation, efficiency, and decision-making. However, the increased interconnectivity also poses significant security challenges because IIoT devices control critical infrastructures and processes. Our work presents an implementation of a robust industrial cybersecurity strategy with a segmented network architecture, collaborative efforts between information technology (IT) and operational technology (OT) teams for enhanced resilience and effectiveness, and vertical honeypots across all Industry 4.0 levels integrated with Wazuh for log transmission and proactive threat response, alongside Snort intrusion detection system (IDS) monitoring network traffic. Additionally, we reinforce our architecture by Wazuh with Elasticsearch and Kibana as a security information and event management solution, facilitating data analysis and compliance enforcement through custom rulesets and cybersecurity threat intelligence (CTI) integration, with automatic updates for continuous adaptation against emerging threats.

Keywords


Cyber-attacks; Honeypot; Industrial internet of things; Industry 4.0; Intrusion detection system; Threat intelligence

Full Text:

PDF


DOI: http://doi.org/10.11591/ijece.v15i1.pp1089-1098

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

International Journal of Electrical and Computer Engineering (IJECE)
p-ISSN 2088-8708, e-ISSN 2722-2578

This journal is published by the Institute of Advanced Engineering and Science (IAES) in collaboration with Intelektual Pustaka Media Utama (IPMU).