Sicurezza informatica OT in tempo reale tramite modelli di apprendimento automatico
View/ Open
Author
Nouh, Mohamed Kamel Ahmed Mohamed <1997>
Date
2026-07-17Data available
2026-07-23Abstract
Nel contesto dell'attacco Stuxnet da parte di Israele, che è stato uno dei primi worm altamente sofisticati specificamente progettato per i PLC Siemens negli impianti nucleari dell'Iran, e dell'incidente Industroyer eseguito dalla Russia che ha preso di mira la rete elettrica dell'Ucraina, causando diffuse interruzioni, e di altri attacchi avvenuti nel corso di questi diversi anni, la cybersecurity OT è diventata una preoccupazione critica per le infrastrutture critiche globali. Questi incidenti hanno evidenziato la vulnerabilità dei sistemi di controllo industriale e l'urgente necessità di meccanismi di protezione in tempo reale più avanzati.
Con la continua evoluzione delle tecnologie ML e AI, la loro integrazione nei sistemi di cybersecurity è diventata sempre più consolidata, in particolare per il rilevamento in tempo reale di attacchi malevoli. Questa crescita ha dimostrato che queste tecnologie saranno essenziali in futuro.
Ho deciso di concentrare la mia tesi sull'integrazione della cybersecurity OT con il Machine Learning per migliorare l'efficacia del rilevamento delle minacce nei flussi di dati industriali, come le letture SCADA e delle sonde, impiegando tecniche di machine learning e visualizzando i risultati sulla dashboard OpenSearch. Applicando diverse tecniche di machine learning e testandole, inclusi i modelli di machine learning implementati in OpenSearch e quelli sviluppati in Python. In the wake of the Stuxnet attack by Israel, which was one of the
first highly sophisticated worms specifically aimed at Siemens PLCs
in Iran’s nuclear facilities, and the Industroyer incident executed by
Russia that targeted Ukraine’s power grid, causing wide spread out
ages, and more attacks that happened through these several years,
OT cybersecurity has become critical concern across global critical
infrastructure. These incidents highlighted the vulnerability of industrial control systems and the urgent need for more advanced real-time
protection mechanisms.
As ML and AI technologies continue to evolve, their integration into
cybersecurity systems has become increasingly integrated, particularly for the real-time detection of malicious attacks. This growth has
shown that these technologies will be essential in the future.
I decided to focus my thesis on the integration of OT cybersecurity
with Machine learning to enhance the efficacy of threat detection in
industrial data streams, such as SCADA and probe readings, by employing machine learning techniques and visualizing the results on the
OpenSearch dashboard. By applying several machine learning tech
niques and testing them, including the machine learning models that
are implemented in OpenSearch and those developed in Python.
Type
info:eu-repo/semantics/masterThesisCollections
- Laurea Magistrale [8032]

