Uppsats

INDUSTRIAL KNOWLEDGE GRAPHS FOR OPERATIONAL TECHNOLOGY DEFENCE: FROM NETWORK FLOWS TO TRACEABLE SECURITY ANALYSIS

Master-uppsats

Mälardalens universitet/Institutionen för datavetenskap och datateknik

Publicerad: 2026

Språk: Engelska

Nyckelord

klicka för att söka

Sammanfattning

Operational technology (OT) environments in industrial manufacturing rely on hundreds of networked devices whose security-relevant data such as network topology, asset identity, firmware, vulnerability, network traffic and regulatory requirements are distributed across multiple isolated systems with no standard integration mechanism.This fragmentation prevents security analysts from obtaining a complete, consistent, and auditable view of which assets are present, which are exposed to known vulnerabilities, and how a compromise could propagate through the network. This thesis investigates how heterogeneous OT data sources can be systematically integrated into a multi-layer knowledge graph to provide asset visibility that is (i) unified, with all data sources queryable in a single graph; (ii) measurable, through enrichment coverage metrics of each layer; and (iii) traceable, with every finding linked through explicit graph relationships to its underlying evidence. The thesis further investigates whether this representation enables effective blast-radius analysis by combining structural topology and behaviour-driven communication analysis into a unified and traceable security analysis framework. Three main contributions distinguish this work. First, a multi-layer architecture implemented in Neo4j, integrates topology, machine abstraction, asset identity, vulnerability intelligence, Net Flow behaviour, IEC~62443-inspired zones and conduits, and policy risk analysis through a pipeline of Python ingestion scripts. Second, a conservative, evidence-based asset classification model assigns observed devices to explicit scope categories ranging from confirmed machine association to deliberately unresolved, reducing over-classification errors and producing an auditable and reversible inventory. Third, a behaviour-driven zone and conduit model derives IEC~62443-inspired security zones automatically from asset classification output and generates conduits from observed Net Flow communication rather than manually defined architectural assumptions, enabling blast-radius analysis that reflects actual network behaviour rather than assumed design intent. The system was evaluated using real industrial switch data from a manufacturing environment spanning eight Cisco Catalyst switches. Evaluation is performed using four dimensions: (i) enrichment coverage per layer, (ii) blast-radius query completeness and response time,(iii) false-positive reduction through vulnerability verification, and (iv) traceability through graph-path evidence. The resulting graph contains 18,677 nodes and 34,834 relationships representing 152 OT assets, with 100\% zone assignment coverage. A single Cypher query traces from switch port to confirmed CVE in 641\,ms. The vulnerability verification process eliminated 68 false-positive associations and identified 11 priority findings, including 6 confirmed and 5 unverifiable findings, while preserving the remaining uncertain cases for manual review. The results demonstrate that knowledge graph can support industrial OT defence by transforming fragmented security-relevant data into a unified and traceable representation, enabling faster assets visibility, vulnerability assessment, and blast-radius analysis in manufacturing environment.

Information

Lärosäte / institution
Mälardalens universitet/Institutionen för datavetenskap och datateknik
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.