A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

2026-08-31Cryptography and Security

Cryptography and Security
AI summary

The authors explain that Industrial Control Systems (ICS), which manage important infrastructure, face increasing cybersecurity risks due to their growing connection to IT networks and new technologies. They review existing resources like datasets, test environments, and digital models used to study and improve ICS security. Their analysis highlights ongoing challenges such as the lack of standard data for testing, realistic attack scenarios, and proper validation of AI-based security tools. They also point out gaps in research and suggest ways to develop better tools to protect these systems.

Industrial Control SystemsOperational TechnologyInformation TechnologyIndustry 4.0Intrusion DetectionAnomaly DetectionThreat IntelligenceDigital TwinsCybersecurity DatasetsTestbeds
Authors
Ebtesam J. Alqahtani, Mohammad Hammoudeh
Abstract
Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along with the deployment of Industry 4.0 technologies increases the attack surface of ICS environments, which in turn makes them more vulnerable to advanced cyber threats. Therefore, many researchers have shown interest in the field of cybersecurity of ICS. The topics of intrusion detection, anomaly detection, threat intelligence, attack simulation and resilience assessment of ICS have received much attention. Nevertheless, the development and testing of cybersecurity solutions for ICS remains to be challenging due to the lack of appropriate datasets and experimental environment. The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins. This paper presents various taxonomies along with systematic analysis of architecture, characteristics, capabilities, pros and cons of these tools. The results of the analysis demonstrate the presence of persistent problems such as lack of standardized benchmarking datasets, lack of modern attack scenarios, insufficient number of datasets based on real operational traffic and difficulty in validating artificial intelligence-driven cybersecurity solutions. In addition to summarizing current research on ICS cybersecurity datasets and testbeds, this roadmap provides the identification of research gaps and recommendations on creation of new tools.