ISIA-AF: Orchestrating Reproducible Attacks and Multi-Source Data Collection for OT Systems
cs.CR
Submitted: 2026-09-16
Updated: 2026-09-16
Comments: 8 pages, 1 Figure, 1 Table, submitted version to Euromicro Software Engineering and Advanced Applications (SEAA)
Journal ref: The Version of Record of this contribution is published in Software Engineering and Advanced Applications, SEAA 2026. Lecture Notes in Computer Science, vol 16863
DOI: 10.1007/978-3-032-36590-3_2
Code: https://github.com/JRC-ISIA/isia-attack-framework
License: http://creativecommons.org/licenses/by/4.0/
The gist: Operational Technology (OT) environments require realistic, reproducible security datasets, yet existing approaches often lack automation, multi-source data capture, and sufficient documentation for
Terminology
Abstract
Operational Technology (OT) environments require realistic, reproducible security datasets, yet existing approaches often lack automation, multi-source data capture, and sufficient documentation for reuse. This paper presents ISIA-AF, a modular attack framework for orchestrating reproducible attack execution and automated dataset generation on industrial systems. The framework coordinates distributed attack clients, records network traffic and operational data, ultimately leading to a multi-source dataset. We derive functional and non-functional requirements from prior work and stakeholder discussions, and realise the framework following a design science research approach. A case study on the ISIA testbed, comprising a real industrial system and a simulated process, demonstrates how the framework supports centralised control, low communication overhead, and flexible deployment across network segments. The result is a practical basis for generating extensible, multi-source OT security datasets for intrusion detection research.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs