Cyber Physical System Security by Splunk

Kundankumar Rameshwar Saraf*, P. Malathi **
* Capgemini Technology Services India Ltd, Pune, Maharashtra, India.
** Department of Electronics and Telecommunication Engineering, D.Y. Patil College of Engineering, Pune, Maharashtra, India.
Periodicity:July - December'2020


Cyber Physical System (CPS) is an integration of sensing, monitoring and analyzing devices connected with each other and establishes communication through internet. This system is prone to many cyber-attacks such as Man-In-The-Middle Attack, Denial of Service Attack, Cross-Site Scripting Attack, SQL Injection Attack, Password Cracking Attack, etc. Present security measures to protect CPS against cyber-attacks includes use of Intrusion Detection System (IDS), Firewalls, Anti-Malware, Anti-Virus, Anti-Spyware, HTTPS/SSH Encryption, Faradays Cage, Password Policy with periodic password change, Least Privileges, Strong Code, Intrusion Prevention System (IPS), etc. All these security measures have one or more challenges in their implementation such as reduced performance, higher power consumption, high transmission delays, huge cost, etc. Also, firewall, IPS, antivirus can only prevent the known threats. Today, many threats have no fixed pattern and their pattern are adaptable. Hence, all these intrusion prevention and protection systems becomes ineffective to protect the CPS against cyber-attacks. This paper reviews how Splunk Enterprise Security (Splunk ES) can be used to secure the CPS against all known, unknown and adaptable cyber threats with minimum user efforts and cost. Operation Technology Option in Splunk ES provides real time predictive analysis of cyber-attacks. By using artificial intelligence, machine learning and behavioral analysis, Splunk can predict any cyber-threat to CPS, 30 to 45 minutes in advance. Splunk can trigger the alert to CPS administrator who can implement the precautionary measures and protect the CPS before the actual occurrence of cyber-attack. This research performs the demonstration of cyber-attack on CPS and shows the result generated by Splunk ES.


Cyber-Attack, Cyber Physical System, Operation Technology, Splunk Enterprise Security.

Saraf, K. R., and Malath, P. (2020). Cyber Physical System Security by Splunk. i-manager's Journal on Communication Engineering and Systems, 9(2), 41-48.


