This thesis analyzes the security challenges posed by the growing convergence between Information Technology (IT) and Operational Technology (OT) within the context of Industry 4.0. The transition toward interconnected systems has shattered the historical physical isolation (air-gap) of industrial networks, exposing critical assets and insecure legacy protocols, such as Modbus TCP, to cyber threats capable of producing real physical and kinetic impacts. The experimental activity documents a complete attack simulation structured according to the Cyber Kill Chain phases, executed on a realistic testbed integrating Windows 11 workstations, legacy Windows 7 systems, a Siemens S7-1200 PLC, and a Universal Robots UR5e cobot. Through a spear phishing campaign and the exploitation of the MS17-010 vulnerability on obsolete systems, it is demonstrated how an attacker can perform lateral movements (pivoting) within a non-segmented ("flat") network to directly manipulate robot registers, resulting in an operational shutdown. In the remedial section, the paper presents a theoretical and conceptual resilient architecture (Scenario B) in compliance with the IEC 62443 international standard and the Purdue model. The proposed hardening solution is based on logical segmentation through VLANs, the use of the pfSense open-source firewall, and the integration of the Suricata IDS for Deep Packet Inspection (DPI) of industrial protocols. The study concludes by framing these strategies within the new European regulatory landscape (NIS2, GDPR, and the Cyber Resilience Act), highlighting how cybersecurity is now an essential pillar for the operational resilience of Small and Medium-Sized Enterprises (SMEs).
Il presente lavoro di tesi analizza le sfide di sicurezza poste dalla crescente convergenza tra Information Technology (IT) e Operational Technology (OT) nel contesto dell'Industria 4.0. La transizione verso sistemi interconnessi ha infranto lo storico isolamento fisico (air-gap) delle reti industriali, esponendo asset critici e protocolli legacy insicuri, come il Modbus TCP, a minacce informatiche capaci di produrre impatti fisici e cinetici reali. L'attività sperimentale documenta una simulazione completa di attacco strutturata secondo le fasi della Cyber Kill Chain, eseguita su un banco di prova realistico che integra workstation Windows 11 e Windows 7 legacy, un PLC Siemens S7-1200 e un cobot Universal Robots UR5e. Attraverso una campagna di spear phishing e lo sfruttamento della vulnerabilità MS17-010 su sistemi obsoleti, viene dimostrato come un attaccante possa eseguire movimenti laterali (pivoting) all'interno di una rete non segmentata ("flat network") fino a manipolare direttamente i registri del robot, causandone il blocco operativo. Nella sezione propositiva, l'elaborato presenta un modello di architettura resiliente (Scenario B) conforme allo standard internazionale IEC 62443 e al modello Purdue. La soluzione di hardening proposta si basa sulla segmentazione logica tramite VLAN, l'impiego del firewall open-source pfSense e l'integrazione dell'IDS Suricata per l'ispezione profonda dei pacchetti (DPI). Lo studio si conclude inquadrando tali strategie nel nuovo panorama normativo europeo (NIS2, GDPR e Cyber Resilience Act), evidenziando come la sicurezza informatica sia oggi un pilastro imprescindibile per la continuità operativa delle Piccole e Medie Imprese (PMI).
CONVERGENZA IT/OT: ANALISI DELLE VULNERABILITÀ DEI PROTOCOLLI INDUSTRIALI E STRATEGIE DI DIFESA STRUTTURALI APPLICABILI IN UN CONTESTO REALISTICO SIMULATO
NAPOLETANO, ALESSANDRO
2025/2026
Abstract
This thesis analyzes the security challenges posed by the growing convergence between Information Technology (IT) and Operational Technology (OT) within the context of Industry 4.0. The transition toward interconnected systems has shattered the historical physical isolation (air-gap) of industrial networks, exposing critical assets and insecure legacy protocols, such as Modbus TCP, to cyber threats capable of producing real physical and kinetic impacts. The experimental activity documents a complete attack simulation structured according to the Cyber Kill Chain phases, executed on a realistic testbed integrating Windows 11 workstations, legacy Windows 7 systems, a Siemens S7-1200 PLC, and a Universal Robots UR5e cobot. Through a spear phishing campaign and the exploitation of the MS17-010 vulnerability on obsolete systems, it is demonstrated how an attacker can perform lateral movements (pivoting) within a non-segmented ("flat") network to directly manipulate robot registers, resulting in an operational shutdown. In the remedial section, the paper presents a theoretical and conceptual resilient architecture (Scenario B) in compliance with the IEC 62443 international standard and the Purdue model. The proposed hardening solution is based on logical segmentation through VLANs, the use of the pfSense open-source firewall, and the integration of the Suricata IDS for Deep Packet Inspection (DPI) of industrial protocols. The study concludes by framing these strategies within the new European regulatory landscape (NIS2, GDPR, and the Cyber Resilience Act), highlighting how cybersecurity is now an essential pillar for the operational resilience of Small and Medium-Sized Enterprises (SMEs).| File | Dimensione | Formato | |
|---|---|---|---|
|
Convergenza_ITOT_analisi_delle_vulnerabilità_dei_protocolli_industriali_e_strategie_di_difesa_strutturali_applicabili_in_un_contesto_rea.pdf
accesso aperto
Dimensione
10.97 MB
Formato
Adobe PDF
|
10.97 MB | Adobe PDF | Visualizza/Apri |
I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/20.500.12075/27288