Full stack industrial control systems security

Rinieri, Lorenzo (2026) Full stack industrial control systems security, [Dissertation thesis], Alma Mater Studiorum Università di Bologna. Dottorato di ricerca in Computer science and engineering, 38 Ciclo.
Documenti full-text disponibili:
[thumbnail of Rinieri_Lorenzo_tesi.pdf] Documento PDF (English) - Richiede un lettore di PDF come Xpdf o Adobe Acrobat Reader
Disponibile con Licenza: Creative Commons: Attribuzione 4.0 (CC BY 4.0) .
Download (29MB)

Abstract

Industrial Control Systems (ICS) constitute the operational backbone of modern critical infrastructures, orchestrating the interaction between cyber components and physical processes. Their increasing interconnection under the Industry 4.0 paradigm exposes them to a wide spectrum of cyber threats targeting control logic, communication, and trust mechanisms. This thesis addresses ICS security from a Full-Stack perspective, analyzing and mitigating vulnerabilities across the physical, communication, and application layers. At the physical layer, PLC-Defuser introduces a hybrid static–formal framework to detect Ladder Logic Bombs hidden within PLC control programs through Control Flow Graph analysis and model checking. At the communication layer, P4ICS leverages programmable data planes to provide in-network encryption and integrity verification for legacy industrial protocols, protecting devices unable to implement modern cryptographic suites. At the application layer, Pk-IOTA combines blockchain and P4-based programmable switches to enforce decentralized trust management for OPC UA deployments, ensuring consistent certificate validation even in resource-constrained environments. Building upon these contributions, the thesis defines a systematic methodology for deriving sound security metrics tailored to Industrial Cyber-Physical Systems, enabling reproducible and cross-layer security assessments. Experimental validation is performed on physical and virtualized testbeds aligned with the Purdue model, demonstrating the feasibility, scalability, and interoperability of the proposed solutions. Collectively, these results advance the state of ICS protection toward a unified, verifiable, and resilient security architecture spanning the entire industrial stack.

Abstract
Tipologia del documento
Tesi di dottorato
Autore
Rinieri, Lorenzo
Supervisore
Co-supervisore
Dottorato di ricerca
Ciclo
38
Coordinatore
Settore disciplinare
Settore concorsuale
Parole chiave
ICS, Cybersecurity, P4, SDN, PLC, Iota, Time Series
Data di discussione
25 Marzo 2026
URI

Altri metadati

Statistica sui download

Gestione del documento: Visualizza la tesi

^