ISIA-AF: Orchestrating Reproducible Attacks and Multi-Source Data Collection for OT Systems

arXiv:2609.18196 · cs.CR · Submitted 2026-09-16 · Read on arXiv

cs.CR

Submitted: 2026-09-16

Updated: 2026-09-16

Comments: 8 pages, 1 Figure, 1 Table, submitted version to Euromicro Software Engineering and Advanced Applications (SEAA)

Journal ref: The Version of Record of this contribution is published in Software Engineering and Advanced Applications, SEAA 2026. Lecture Notes in Computer Science, vol 16863

DOI: 10.1007/978-3-032-36590-3_2

Code: https://github.com/JRC-ISIA/isia-attack-framework

License: http://creativecommons.org/licenses/by/4.0/

The gist: Operational Technology (OT) environments require realistic, reproducible security datasets, yet existing approaches often lack automation, multi-source data capture, and sufficient documentation for

Terminology

Abstract

Operational Technology (OT) environments require realistic, reproducible security datasets, yet existing approaches often lack automation, multi-source data capture, and sufficient documentation for reuse. This paper presents ISIA-AF, a modular attack framework for orchestrating reproducible attack execution and automated dataset generation on industrial systems. The framework coordinates distributed attack clients, records network traffic and operational data, ultimately leading to a multi-source dataset. We derive functional and non-functional requirements from prior work and stakeholder discussions, and realise the framework following a design science research approach. A case study on the ISIA testbed, comprising a real industrial system and a simulated process, demonstrates how the framework supports centralised control, low communication overhead, and flexible deployment across network segments. The result is a practical basis for generating extensible, multi-source OT security datasets for intrusion detection research.

Related papers