Rasyid Muhammad, Nashwan (2026) A Labeled Dataset of Cyberattacks for Solar Panel Industrial Control Systems. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5025221004-Undergraduate_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (4MB) |
Abstract
Seiring berkembangnya infrastruktur Energi Baru Terbarukan (EBT), khususnya sistem PLTS berbasis Photo Voltaic (PV), muncul kerentanan keamanan siber yang kritis. Sistem Kendali Industri (ICS) yang mengelola jaringan ini sering kali bergantung pada protokol lama seperti Modbus TCP, yang tidak memiliki mekanisme keamanan bawaan sehingga rentan terhadap ancaman siber. Pengembangan IDS yang efektif untuk memitigasi risiko ini masih terhambat oleh minimnya ketersediaan dataset yang realistis dan berkualitas tinggi yang berasal dari lingkungan surya fisik. Untuk mengatasi celah tersebut, tesis ini mengembangkan dataset berlabel dari serangan siber yang menargetkan ICS panel surya, yang dihasilkan melalui metodologi tiga fase. Fase 1 memvalidasi permukaan serangan (attack surface) pada Simulasi Software, sebuah testbed SCADA virtual. Fase 2 mengintegrasikan perangkat keras PLC, memanfaatkan kerangka kerja MITRE Caldera untuk secara sistematis mengemulasi rantai serangan (killchain) sambil merekam telemetri komprehensif di seluruh lapisan jaringan, endpoint, dan sumber daya host (Zeek, Sysmon, atop, Wireshark). Terakhir, Fase 3 mengadaptasi serangan-serangan ini untuk jaringan fisik nyata, menerapkan orkestrator otomatis kustom pada dua penerapan di fasilitas PLTS REIDI dengan menggunakan arsitektur perekaman jaringan (network capture) dual-node yang non-intrusif guna mematuhi batasan keselamatan operasional yang ketat. Serangan yang dieksekusi mencakup seluruh killchain ICS, mulai dari pengintaian dan pengumpulan data hingga eksfiltrasi (HTTP, HTTPS, SCP) dan teknik manipulasi dampak (ARP poisoning, False Data Injection). Dataset testbed REIDI memuat lebih dari 6,1 juta baris data lalu lintas normal (benign) dan 6,2 juta baris data serangan. Disusun dalam format CSV, data tersebut mencakup lalu lintas IT (49 kolom) dan fitur modbus hasil rekayasa dari pcapng (14 kolom), yang dilabeli secara komprehensif menggunakan kerangka kerja MITRE ATT&CK for ICS. Penelitian ini menunjukkan bahwa pemantauan forensik menyeluruh terhadap killchain yang dieksekusi dapat menghasilkan dataset yang terstruktur dan realistis, yang sangat ideal untuk melatih model supervised machine learning dan menjadi tolok ukur IDS di masa mendatang.
=================================================================================================================================
The rapid expansion of renewable energy infrastructure, particularly solar photovoltaic (PV) systems, has introduced critical cybersecurity vulnerabilities. Industrial Control Systems (ICS) managing these grids often rely on legacy protocols like Modbus TCP, which lack intrinsic security mechanisms and leave them susceptible to cyber threats. The development of effective Intrusion Detection Systems (IDS) to mitigate these risks is currently hindered by a lack of high-quality, realistic datasets derived from physical solar environments. To address this gap, this thesis presents a labeled dataset of cyberattacks targeting solar panel ICS, generated through a progressive three-stage methodology. Stage 1 validates the attack surface on a purely virtual SCADA testbed. Stage 2 integrates physical PLC hardware, utilizing the MITRE Caldera framework to systematically emulate multi-stage adversarial killchains while capturing comprehensive telemetry across network, endpoint, and host resource layers (Zeek, Sysmon, atop, Wireshark). Finally, Stage 3 adapts these attacks for a live physical grid, deploying a custom automated orchestrator across two deployments at the REIDI solar power plant using a non-intrusive, dual-node network capture architecture to adhere to strict operational safety constraints. Executed attacks span the full ICS killchain, ranging from reconnaissance and data collection to exfiltration (HTTP, HTTPS, SCP) and impact techniques (ARP poisoning, False Data Injection). The final physical testbed dataset comprises over 6.1 million rows of benign traffic and 6.2 million rows of attack traffic. Structured in CSV format, the data encompasses IT traffic (49 columns) and engineered Modbus features (14 columns), comprehensively labeled using the MITRE ATT&CK for ICS framework. This research demonstrates thorough forensic monitoring of executed killchains, yielding a highly structured, realistic dataset ideally suited for training supervised machine learning models and benchmarking future Intrusion Detection Systems.
| Item Type: | Thesis (Other) |
|---|---|
| Subjects: | T Technology > T Technology (General) > T58.5 Information technology. IT--Auditing |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Informatics Engineering > 55201-(S1) Undergraduate Thesis |
| Depositing User: | Nashwan Rasyid Muhammad |
| Date Deposited: | 27 Jul 2026 01:46 |
| Last Modified: | 27 Jul 2026 01:46 |
| URI: | http://repository.its.ac.id/id/eprint/137783 |
Actions (login required)
![]() |
View Item |
