The digital transformation of industrial environments increasingly relies on resource-constrained Industrial Internet of Things (IIoT) devices, which must operate securely despite limited computational capabilities and hostile deployment conditions. Ensuring their trustworthiness is essential for complying with emerging regulations such as the EU Cyber-Resilience Act and for achieving certification under standards such as IEC 62443. This paper presents mu TEE, a lightweight Trusted Execution Environment for RISC-V microcontroller-class platforms, explicitly designed to support certification-ready lifecycle security in ultra-lightweight IIoT nodes. mu TEE combines hardware-enforced isolation, a secure root of trust, and enclave-based modularity for trusted system services, with an efficient symmetric-cryptography framework tailored to constrained devices. Beyond the architectural contribution, we perform a detailed IEC 62443 Security Level 3 compliance analysis, providing one of the first systematic demonstrations of how a constrained IIoT platform can be evaluated against this standard. The full compliance checklist is released as supplementary material, offering a practical methodology for applying IEC 62443 in novel IIoT contexts. We further illustrate mu TEE's integration into lifecycle management flows and demonstrate its deployment in a PLC-based smart metering scenario. A prototypical FPGA implementation on an AMD-Xilinx Artix-7 platform shows modest area and performance costs, with limited overhead on application throughput. Comparative evaluation highlights mu TEE's advantages over software-only TEEs, Arm TrustZone-M, and baseline RISC-V PMP approaches. The results confirm that mu TEE delivers a certifiable, open-hardware trust anchor for IIoT, and that it serves as a replicable case study of IEC 62443 compliance evaluation, advancing the secure deployment of Industry 4.0 infrastructures.
The rapid digitalization of industrial environments and the increasing convergence of Information Technology (IT) and Operational Technology (OT) have transformed traditional Industrial Control Systems (ICS) into complex Cyber-Physical Systems (CPS). While this evolution enables unprecedented levels of efficiency and automation, it exposes critical infrastructures to a sophisticated and heterogeneous threat landscape where attacks can propagate beyond digital assets to cause production disruptions. Despite the sector's criticality, current literature suffers from methodological fragmentation; most studies rely on empirical enumeration or ad-hoc processes, lacking structured frameworks for threat identification. This paper addresses this gap by presenting a Systematic Literature Review (SLR) designed to establish a formalized knowledge base for ICS threat modelling. Through a rigorous search of 913 scientific publications, we identified the most relevant contributions to threat definition. The primary contribution of this work is the development of a comprehensive ICS Threat Catalogue, which systematically classifies 87 distinct threats. These threats are mapped to specific assets and communication protocols, aligned with the Purdue Enterprise Reference Architecture. By integrating these findings into a graph-based modelling approach, we leveraged an automated methodology for generating threat models and penetration testing plans. The effectiveness of the catalogue was validated through a Smart Manufacturing case study, where the approach successfully identified 481 potential threats and generated 319 attack plans, demonstrating the practical impact of threat analysis and operational security assessment.
Structural Health Monitoring systems play a critical role in ensuring the safety and longevity of infrastructure by continuously assessing the structural integrity in a timely manner. Effective monitoring relies heavily on the optimal placement of accelerometer sensors, as too many sensors increase costs while insufficient sensors may compromise anomaly detection. The final goal is to provide reliable, high-resolution insights into the health of complex infrastructures, and a standardized methodology to guide future structural health monitoring projects in developing cost-effective and accurate sensor layouts for critical infrastructure, considering both the type of structure and the environmental conditions. This paper presents a data-driven methodology structured around the Deming cycle (Plan-Do-Check-Act) to optimise sensor placement. The proposal aims to minimise the number of accelerometers while maintaining high detection accuracy and spatial coverage for structural anomaly identification. The validation is conducted by applying the proposal to the Z24 bridge dataset, a well-known benchmark from a box girder bridge in Switzerland, which contains detailed vibration responses under progressive damage conditions. The proposed approach results in a sensor reduction of over 89.61
Security assessments are essential to ensure that Industrial Control Systems (ICS) comply with cybersecurity standards and remain resilient to evolving cyber threats. While standards such as IEC 62443 and NIST provide structured guidance for securing industrial systems, translating these highlevel requirements into concrete and executable security tests remains a largely manual process. In practice, analysts must interpret heterogeneous standards, derive security controls, identify relevant adversarial behaviors, and design testing procedures for the target environment. This limits the repeatability and scalability of security assessments across industrial contexts. This paper presents a standards-driven approach that transforms cybersecurity requirements into executable adversary emulation procedures for ICS security assessment. The proposed framework extracts security controls from standards, aligns them with adversarial behaviors described in the MITRE ATT&CK knowledge base for ICS, and generates environment-aware test actions executable through the MITRE CALDERA adversary emulation platform. An AIassisted pipeline supports the interpretation of requirements and the generation of test procedures while preserving human oversight and process traceability. By leveraging CALDERA as the execution layer, the approach decouples the assessment methodology from the target system, enabling the same adversary procedures to be applied across different environments such as virtual testbeds, digital twins, and operational systems. The approach is validated through two industrial case studies, demonstrating how standards-driven adversary emulation supports repeatable security assessments in heterogeneous ICS environments.
As Industrial Control Systems (ICS) shift toward cloud–edge continuums, a single breach can trigger cascading failures across the entire infrastructure. Current research lacks a unified method to establish end-to-end verifiable trust across heterogeneous devices and platforms. This paper proposes a reference architecture to bridge this gap, deriving security requirements from NIST, ENISA, and MITRE ATT CK frameworks. The architecture integrates hardware-rooted trust, secure networking, and cloud-based attestation. It is designed for diverse environments—ranging from TEE-enabled devices to bare-metal controllers—allowing for incremental deployment and clear security-performance trade-offs. By unifying siloed defenses into a holistic framework, this work provides systematic guidance for managing risks and ensuring deployability in real-world industrial settings.
Traditional cloud monitoring often relies on static remediation procedures that are difficult to adapt to dynamic and heterogeneous infrastructures. This paper proposes an agentic LLM-based architecture for adaptive remediation planning from confirmed cloud anomalies. The goal is not to replace anomaly detectors, but to transform confirmed anomaly events into structured, policy-constrained remediation artifacts suitable for human-supervised operational workflows.The proposed workflow combines anomaly intake, contextual validation, playbook retrieval, and constrained playbook generation through a message-driven Multi-Agent System. Retrieval-Augmented Generation is used to correlate current incidents with historical knowledge and existing procedures, while deterministic guardrails enforce schema validation, policy constraints, command allow/deny lists, critical-resource checks, and human approval for high-impact or previously unseen actions.A containerised Proof of Concept demonstrates that confirmed anomalies can be transformed into CACAO-compatible remediation drafts within operationally reasonable time bounds. The evaluation focuses on generating and validating remediation plans under explicit operational constraints, rather than on anomaly detection benchmarking or on production-scale autonomous execution.
Asset discovery in critical infrastructures, and in particular within industrial control systems, constitutes a fundamental cybersecurity function. Ensuring accurate and comprehensive asset visibility while maintaining operational continuity represents an ongoing challenge. Existing methodologies rely on deterministic tools that apply fixed fingerprinting strategies and lack the capacity for contextual reasoning. Such approaches often fail to adapt to the heterogeneous architectures and dynamic configurations characteristic of modern critical infrastructures. This work introduces an architecture based on a Mixture of Experts model designed to overcome these limitations. The proposed framework combines multiple specialized modules to perform automated asset discovery, integrating passive and active software probes with physical sensors. This design enables the system to adapt to different operational scenarios and to classify discovered assets according to functional and security-relevant attributes. A proof-of-concept implementation is also presented, along with experimental results that demonstrate the feasibility of the proposed approach. The outcomes indicate that our LLM-based approach can support the development of non-intrusive asset management solutions, strengthening the cybersecurity posture of critical infrastructure systems.
The evolution from traditional power grids to modern smart grids marks a significant advancement in energy management and efficiency. This transition—driven by the implementation of bidirectional energy and information flows—results in a dramatic increase in infrastructure vulnerability since new entry points are introduced on the attack surface. In particular, prosumers represent a brand new—and, thus, largely unexplored—attack vector, for which a thorough re-evaluation of the existing security measures is very much needed. This article proposes a novel approach to security monitoring, which exploits business process knowledge to effectively identify and mitigate prosumer-specific advanced persistent threats in smart grids. To validate the approach, an experimental campaign is done in a real setup, specifically the power grid of the Berchidda municipality, in Italy. Impact evaluation covers technical as well as business aspects since the analysis includes potential economic consequences of the attacks.
This paper proposes a cybersecurity monitoring framework tailored to multi-plant Flexible Manufacturing Systems. The framework combines Digital Twin technology, hierarchical SIEM and SOAR systems, and AI-based incident response. Addressing the limitations of traditional cybersecurity methods in distributed manufacturing scenarios, the proposed solution enables real-time threat detection, cross-facility correlation of events, automated incident responses, and an integrated threat-sharing platform. Initial evaluations indicate that the approach improves early anomaly detection and reduces false positives in threat detection. Ongoing and future research steps include incorporating advanced AI agents for automated mitigation, expanding simulations to more sophisticated attack vectors, optimizing system performance, minimizing false positives, and conducting comprehensive validation using various industrial protocols to ensure compliance with cybersecurity standards.
Cyber-Physical Systems heavily rely on accurate and timely anomaly detection to ensure safety, security, and resilience, while maintaining low operational costs. However, traditional anomaly detection methods often depend on extensive datasets and heavy computational resources, limiting their practical implementation. This paper introduces a multilayer statistically based architecture designed specifically for real-time anomaly detection in CPS environments, without requiring large training datasets. Leveraging an edge-cloud paradigm, the approach combines lightweight statistical analysis performed locally at the edge with advanced centralised correlation analysis in the cloud. Our methodology dynamically adapts anomaly detection thresholds using Free Probability Theory (FPT), integrating real-time external data sources such as traffic information to significantly reduce false positives. A practical validation through a real-world structural health monitoring case study on a bridge in Caserta, Italy, demonstrates the effectiveness and robustness of our system in detecting anomalies, offering a scalable, adaptive, and efficient solution aligned with European data-sharing directives and standards.
Prosumers - i.e. end-points with a dual role of producer and consumer - have become a fundamental element of the Power Grid. As their interaction with the infrastructure becomes more and more dynamic, the attack surface increases significantly. Evidence is, demonstrating that prosumer installations can serve as entry points for high-impact attacks, including blackouts, cascading failures, malicious alterations of demand forecasts, and market manipulation in general. Working side by side with industries, including both transmission and distribution operators, we have come to the conclusion that a major cause of this exposure is the lack of technically sound and enforceable security regulations for the "edge-side" of the power infrastructure. In this work, we analyze the European cybersecurity legislation and identify six specific gaps in the existing framework, specifically: 1) prosumers' ambiguous classification despite recognition as "producers" under the Electricity Directive; 2) inadequate monitoring requirements for high-wattage devices; 3) insufficient certification standards for prosumer equipment; 4) risks from extraterritorial cloud management systems; 5) absence of clear accountability frameworks for attacks originating from prosumer devices; 6) and unresolved data protection responsibilities. For each weakness, we provide actionable takeaways, which can be used as a compass for addressing key deficiencies of the current regulation.
The technological evolution of embedded devices over the last decades has revolutionized our way of interacting with the world, and, at the same time, brought significant cybersecurity challenges in managing digital products. One of the paradigms that has had the most impact on our daily lives is the Internet of Things (IoT), whose number is estimated to reach 74.44 billion by 2025 according to Gartner. Regulations and standards have been approved at both European and global level emphasizing the importance of managing the security of devices throughout their lifecycle. The CERTIFY framework architecture emerges as a solution to implement security management during the lifecycle of an IoT device, including mechanisms for secure design and deployment, threat monitoring and mitigation, and secure upgrading. This article describes the CERTIFY architecture, highlights its key technologies and shows how it operates to protect each phase of the device lifecycle.
This paper provides an overview of the main results achieved within the Horizon 2020 Shift2Rail project named RAILS (Roadmaps for Artificial Intelligence Integration in the Rail Sector). The RAILS roadmapping process provided state-of-the-art, taxonomy, future research directions, and recommendations in three macro areas: Railway Safety and Automation, Predictive Maintenance and Defect Detection, and Traffic Planning and Management. RAILS findings shed light on the potential of intelligent technologies and provided essential guidelines for integrating machine learning into next-generation smart railways.
Enabling multi-tenancy on edge devices is crucial for maximizing resource utilization, enhancing scalability, and reducing costs. However, it introduces the challenge of maintaining tenant isolation, preventing adverse inter-tenant effects and unauthorized resource access. Traditional multi-tenant solutions often struggle in embedded systems due to resource constraints, and current lightweight approaches suffer from performance, portability, and tenant density issues. We propose WASMBOX , a novel solution for sandboxing applications in multi-tenant embedded systems. It leverages WebAssembly to offer strong isolation, small attack surface, high portability, efficient resource usage, and near-native performance. Our system ensures both attack prevention and detection, using a patched WebAssembly System Interface for safe system call execution, and a monitoring layer for anomaly detection. Additionally, WASMBOX uses a Trusted Execution Environment for further isolating applications against escaping tenants and attesting to the integrity of WebAssembly applications. We validated our solution in a real-world case study with the SpaceApplications company, aiming to adopt a multi-tenant model for its ISS-based micro-gravity research facility. The experimental evaluation compared WASMBOX with approaches relying on VMs, containers, and microkernel-based VMs. The obtained results show that WASMBOX has the lowest resource usage, the highest tenant density, the second lowest startup (preceded by microkernels), and execution time (preceded by containers).
Current monitoring procedures for critical infrastructure, especially in structural health, primarily rely on manual inspections, which require physical contact and are often laborintensive, time-consuming, and costly. Visual observations dominate these inspections. Smart and secure sensing solutions based on the Internet of Things can significantly improve monitoring for critical infrastructures like bridges, roads, and smart grids.The DOSSIER framework aims to enhance health monitoring of critical infrastructures through non-invasive, advanced sensor networks and heterogeneous data sources to evaluate infrastructure conditions and detect anomalies. The framework’s objectives include data acquisition from multiple and heterogeneous sources, adopting predictive models to provide early warnings, and implementing rule-based processing of acquired information. Additionally, DOSSIER aims to extend the service life of existing infrastructures by reducing the impact of anomalies, including those resulting from attacks.
In the evolving transportation domain, efficient and seamless data exchange across different transport modalities-road and rail mobility, shipping, aviation, and multimodal transport-is crucial for enhancing efficiency and sustainability. This paper analyses the application of Data Space in smart transportation, emphasizing their key role in facilitating secure and private data sharing among different infrastructures. It introduces a novel architecture that overcomes the legal and technical challenges specific to this field. In particular, the first application of our analysis is the enhancement of the booking system for refuelling and recharging slots, which serves as a key example of a smart mobility application. By employing Data Spaces, transportation stakeholders can achieve a more coordinated and efficient scheduling process, reducing waiting times and enhancing user experience across all transport modes. This work highlights the significant potential of Data Spaces in creating a more integrated and interconnected transport ecosystem.
Partnerships among stakeholders involved with connected devices often need to exchange sensitive data, raising significant security and privacy concerns. Traditional methods reliant solely on platforms such as the Malware Information Sharing Platform may pose limitations in addressing these challenges. This paper introduces a novel framework supporting secure data sharing among connected IoT devices, leveraging data spaces and data provenance concepts. The proposed framework integrates data spaces to facilitate secure data exchange and incorporates data provenance to trace the origins and transformations of shared data, ensuring accountability and transparency. The framework has practical applications in contexts such as structural health monitoring, where managing data from IoT devices, sensors, and data feeds enables data and threat sharing among different structures. Our approach aims to mitigate security risks and privacy breaches while increasing trust among participating entities.
The interest in Self-Sovereign Identity (SSI) in research, industry, and governments is rapidly increasing. SSI is a paradigm where users hold their identity and credentials issued by authorized entities. SSI is revolutionizing the concept of digital identity and enabling the definition of a trust framework wherein a service provider (verifier) validates the claims presented by a user (holder) for accessing services. However, current SSI solutions primarily focus on the presentation and verification of claims, overlooking a dual aspect: ensuring that the verifier is authorized to access the holder's claims. Addressing this gap, this paper introduces an innovative SSI-based solution that integrates decentralized wallets with Ciphertext-Policy Attribute-Based Proxy Re-Encryption (CP-ABPRE). This combination effectively addresses the challenge of verifier authorization. Our solution, implemented on the Ethereum platform, enhances accountability by notarizing key operations through a smart contract. This paper also offers a prototype demonstrating the practicality of the proposed approach. Furthermore, it provides an extensive evaluation of the solution's performance, emphasizing its feasibility and efficiency in real-world applications.
Simona Bernardi合作论文数Universita degli Studi di Torino
Dipartimento di Informatica4
Jose Merseguer合作论文数Department of Computer Science and Systems Engineering, School of Engineering and Architecture, University of Zaragoza3
Mauro Iacono合作论文数DEM, Seconda Universiti degli Studi di Napoli, Belvedere Reale di San Leucio, 81100 Caserta (Italy)2