Iiot sensor node criticality ranked by data and security risks

Quantifying IIoT Sensor Node Criticality by Fusing its Data Criticality and Security Vulnerability

Cryptography and Security

Summary

Industrial sensors help factories run smoothly by constantly checking processes. But these sensors can be hacked or fail, which causes trouble. The authors made a way to figure out which sensors are most important by looking at both how their data affects the product and how vulnerable they are to cyberattacks. They tested their method using sensors in wine production and found some differences depending on the security scoring system used. This approach can be used in many factories to keep sensor networks more secure and reliable.

What this means in practice

Tested on one dataset.

Authors

Sachin K. Sen, Gour C. Karmakar, Shaoning Pang

Abstract

The integration of the Industrial Internet of Things (IIoT) into manufacturing has transformed industrial operations by optimising production management and ensuring product quality through smart industrial sensors that regulate processes based on real-time data. However, these sensor nodes are highly vulnerable to cyber threats, posing significant security risks that compromise their reliability and integrity. While existing research explores cybersecurity vulnerabilities and cyberattack-based methods for ranking critical nodes, some studies assess node criticality based on the impact of sensor data on product quality. However, a comprehensive approach that integrates both data criticality and cybersecurity vulnerability remains unexplored. To bridge this gap, this study introduces a novel framework that evaluates IIoT sensor node criticality by leveraging Dempster--Shafer (D-S) theory to fuse data criticality and cybersecurity vulnerabilities. The proposed method is validated using a dataset from red wine production, demonstrating its effectiveness in ranking sensor nodes based on both factors. The results show that criticality rankings based on security vulnerability scores computed using CVSS version 4.0 differ significantly from those obtained with CVSS version 3.1, highlighting the influence of enhanced vulnerability assessment methodologies. While initially applied to wine manufacturing, this framework is adaptable to broader industrial applications with minimal modifications, offering a robust approach to securing IIoT-enabled production systems.