<p>Industrial Internet of Things (IIoT) systems introduce significant cybersecurity challenges due to their complex and highly interconnected nature. Static control mechanisms are often inadequate to detect or mitigate illegal information flows in such dynamic environments. This paper presents INFFLOW-RT, a real-time, adaptive methodology designed to control information flows within business processes by assessing their risk. Business processes are modeled as directed graphs, enabling the identification of both direct and indirect dependencies. Our approach applies Bayesian inference with Laplace smoothing for dynamic risk estimation and introduces risk-weighted centrality metrics to identify the objects that may contribute to high-risk flows, even if they are not structurally central. To evaluate the methodology, we created an enriched dataset based on smart grid use cases, including over 4,000 transactions with various types of legal and unauthorized transactions. Our results show that INFFLOW-RT effectively identifies high-risk objects, adapts to evolving data transfers, and provides actionable insights for improving information flow security in complex IIoT infrastructures.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

INFFLOW-RT: A real-rime, adaptive methodology for risk-based information flow control in IIoT

  • Argiro Anagnostopoulou,
  • Nikolaos Tsinganos,
  • Jason Chatzopoulos,
  • Ioannis Mavridis,
  • Dimitris Gritzalis

摘要

Industrial Internet of Things (IIoT) systems introduce significant cybersecurity challenges due to their complex and highly interconnected nature. Static control mechanisms are often inadequate to detect or mitigate illegal information flows in such dynamic environments. This paper presents INFFLOW-RT, a real-time, adaptive methodology designed to control information flows within business processes by assessing their risk. Business processes are modeled as directed graphs, enabling the identification of both direct and indirect dependencies. Our approach applies Bayesian inference with Laplace smoothing for dynamic risk estimation and introduces risk-weighted centrality metrics to identify the objects that may contribute to high-risk flows, even if they are not structurally central. To evaluate the methodology, we created an enriched dataset based on smart grid use cases, including over 4,000 transactions with various types of legal and unauthorized transactions. Our results show that INFFLOW-RT effectively identifies high-risk objects, adapts to evolving data transfers, and provides actionable insights for improving information flow security in complex IIoT infrastructures.