Uppsats

A Framework for Evaluating Forensic Readiness in Zero Trust Architectures on Resource-Constrained Industrial IoT Edge Devices

Magister-uppsats

Högskolan i Halmstad/Akademin för informationsteknologi

Publicerad: 2026

Språk: Engelska

Sammanfattning

The increasing deployment of IIoT solutions has resulted in numer-ous problems related to effective operational monitoring, centralizedobservability, and communication management in constrained edge-computing environments. One of the widely employed types of con-strained edge devices is Raspberry Pi systems due to their affordabilityand ease of use for industrial purposes. However, such devices fre-quently have limited visibility in terms of monitoring capabilitiesand are not able to manage telemetry within segmented cybersecu-rity environments. As one of the recent cybersecurity models, theZero Trust Architecture model focuses on continuous authentication,least-privilege communication control, and deny-by-default accessenforcement principles. Simultaneously, current industrial solutionsdemand lightweight centralized monitoring frameworks capable offacilitating telemetry and workload monitoring within distributededge devices. This paper explores the implementation of a centralizedmonitoring system operating in the segmented Raspberry Pi ZeroTrust IIoT laboratory environment. Such a laboratory infrastructureincorporates Raspberry Pi edge devices, Role-Based Access Control(RBAC) and ZTA communication environment, Prometheus telemetrycollection, Grafana visualization dashboard, Syslog logging tool, andNode Exporter telemetry collection method. Experimental observa-tions were focused on workload visibility, telemetry collection, alertstate, node pressure behavior, CPU workload monitoring, and central-ized observability in cases when workload was created through thestress-ng application. It was shown that centralized monitoring infras-tructures could facilitate monitoring within segmented ZTA laboratoryenvironments operating under constrained computational resources.Additionally, Prometheus-Grafana monitoring infrastructures wereable to support visualization, alerts’ state detection, and monitoringwithin RBAC and segmented ZTA laboratory environments. At thesame time, the Syslog monitoring environment helped in aggregatingmonitoring data from multiple Raspberry Pi nodes while segmentedZero Trust firewall policies allowed maintaining constrained commu-nication with no restrictions on telemetry collection. Thus, this studycontributes a reusable monitoring and observability infrastructure thatcan be applied in IIoT constrained laboratory environments and showsimplementation observations of telemetry collection within segmentedZTA architecture. It is essential to emphasize that such observationscannot be viewed as forensically reliable or adversarial results.

Information

Lärosäte / institution
Högskolan i Halmstad/Akademin för informationsteknologi
Publiceringsdatum
2026
Uppsatstyp
Magister-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.