Real-Time Threat Detection using SIEM for Industrial IoT Protocols

dc.contributor.authorHeino, Timi
dc.contributor.departmentfi=Tietotekniikan laitos|en=Department of Computing|
dc.contributor.facultyfi=Teknillinen tiedekunta|en=Faculty of Technology|
dc.contributor.studysubjectfi=Tietotekniikka|en=Information and Communication Technology|
dc.date.accessioned2025-06-30T21:05:40Z
dc.date.available2025-06-30T21:05:40Z
dc.date.issued2025-06-25
dc.description.abstractThe increasing integration of smart devices into industrial environments has led to the rapid growth of the Industrial Internet of Things, which introduces significant cybersecurity challenges due to the scale, heterogeneity, and limited security of many connected devices. Traditional security tools often fail to detect protocol-specific threats within IIoT networks, particularly in resource-constrained or legacy environments. To address this, the thesis investigates whether open-source technologies can offer a cost-effective yet capable solution for monitoring and securing IIoT communications. A virtualized test environment is constructed using VMware, in which an open-source SIEM system is deployed. The platform was enhanced with custom Suricata rules designed to detect anomalies in MQTT-based traffic, one of the most commonly used IIoT protocols. A packet crafting tool is used to simulate realistic attack scenarios, including Denial-of-Service, Brute Force, and Sybil attacks targeting MQTT communication. Traffic is monitored and analysed using features of the SIEM system. The results demonstrate that the SIEM solution is capable of accurately detecting and visualizing malicious IIoT traffic. Alerts are triggered in real time, and the system maintains stable performance under test conditions. However, limitations are observed in handling encrypted traffic, writing scalable and generalizable detection rules, and validating performance in more complex real-world environments. The findings confirm that open-source platforms can be configured into effective SIEM systems for IIoT use cases. Although more work is required to improve detection in encrypted or large-scale scenarios, this study highlights the practical viability of low-cost, open-source SIEM solutions in addressing emerging industrial cybersecurity threats.
dc.format.extent88
dc.identifier.olddbid199507
dc.identifier.oldhandle10024/182538
dc.identifier.urihttps://www.utupub.fi/handle/11111/12495
dc.identifier.urnURN:NBN:fi-fe2025063075881
dc.language.isoeng
dc.rightsfi=Julkaisu on tekijänoikeussäännösten alainen. Teosta voi lukea ja tulostaa henkilökohtaista käyttöä varten. Käyttö kaupallisiin tarkoituksiin on kielletty.|en=This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.|
dc.rights.accessrightsavoin
dc.source.identifierhttps://www.utupub.fi/handle/10024/182538
dc.subjectIIoT, MQTT, SIEM, SELKS, Scapy
dc.titleReal-Time Threat Detection using SIEM for Industrial IoT Protocols
dc.type.ontasotfi=Diplomityö|en=Master's thesis|

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
Heino_Timi_thesis.pdf
Size:
605.72 KB
Format:
Adobe Portable Document Format