Close menu

SURE

Sunderland Repository records the research produced by the University of Sunderland including practice-based research and theses.

TRIST: Towards a Container-Based ICS Testbed for Cyber Threat Simulation and Anomaly Detection

Lo, Carol, Christie, Jack, Win, Thu Yein, Rezaeifar, Zeinab, Khan, Zaheer and Legg, Phil (2025) TRIST: Towards a Container-Based ICS Testbed for Cyber Threat Simulation and Anomaly Detection. In: Proceedings of the International Conference on Cybersecurity, Situational Awareness and Social Media Cyber Science 2024; 27–28 June; Edinburgh Napier University, Scotland. Springer Proceedings in Complexity (SPCOM) . Springer, Singapore. ISBN 978-981-96-0401-2

Item Type: Book Section

Abstract

Cyber-attacks on Industrial Control Systems (ICS), as exemplified by the incidents at the Maroochy water treatment plant and the Ukraine’s electric power grid, have demonstrated that cyber threats can inflict significant physical impacts.
These incidents caused widespread service disruptions and substantial economic losses, underscoring the urgent need for an in-depth understanding of cyber threats in industrial environments. Industrial security research is usually conducted on physical testbeds to avoid safety issues, production interruptions and other operational constraints in industrial processes. Nevertheless, security defenders often encounter obstacles in developing or accessing physical testbeds due to associated costs and
complexities. These factors hinder research progress to devise early detection mechanisms for cyber threats—essential for effective incident response. To overcome these obstacles, this paper presents a container-based virtual testbed. Its lightweight architecture enables replicable and efficient deployment of testbeds at low cost for simulating cyber threats on Cyber-Physical Systems (CPS)—the cornerstone of industrial automation and control systems. Also, the container-based virtual testbed provides
a cost-effective option for producing datasets for training, testing and optimization of unsupervised anomaly detection models. Besides, an evaluation on resource consumption is conducted. The paper also discusses the benefits and limitations of proposed container-based ICS testbeds and suggests future research areas.

[thumbnail of Article published in The International Conference on Cybersecurity, Situational Awareness and Social Media] PDF (Article published in The International Conference on Cybersecurity, Situational Awareness and Social Media)
978-981-96-0401-2.pdf - Published Version
Restricted to Repository staff only

Download (14MB) | Request a copy

More Information

Additional Information: Included in the following conference series: CYBER SCIENCE: The International Conference on Cybersecurity, Situational Awareness and Social Media Conference proceedings info: Cyber Science 2024 2024.
Depositing User: Thomas Thu Yein

Identifiers

Item ID: 20134
Identification Number: 10.1007/978-981-96-0401-2_13
ISBN: 978-981-96-0401-2
URI: https://sure.sunderland.ac.uk/id/eprint/20134
Official URL: https://doi.org/10.1007/978-981-96-0401-2_13

Users with ORCIDS

ORCID for Thu Yein Win: ORCID iD orcid.org/0000-0002-4977-0511

Catalogue record

Date Deposited: 15 May 2026 09:50
Last Modified: 15 May 2026 09:50

Contributors

Author: Thu Yein Win ORCID iD
Author: Carol Lo
Author: Jack Christie
Author: Zeinab Rezaeifar
Author: Zaheer Khan
Author: Phil Legg

University Divisions

Faculty of Business and Technology

Subjects

Computing > Cybersecurity
Computing > Artificial Intelligence

Actions (login required)

View Item (Repository Staff Only) View Item (Repository Staff Only)

Downloads per month over past year