CBL - Campus del Baix Llobregat

Projecte llegit

Títol: Implementación de un SIEM en un entorno OT


Estudiants que han llegit aquest projecte:


Director/a: LEÓN ABARCA, OLGA

Departament: ENTEL

Títol: Implementación de un SIEM en un entorno OT

Data inici oferta: 21-01-2026     Data finalització oferta: 21-09-2026



Estudis d'assignació del projecte:
    GR ENG TELEMÀTICA
Tipus: Individual
 
Lloc de realització: EETAC
 
Paraules clau:
SIEM, OT, Modbus TCP, Elastic Stack, Zeek, ciberseguridad industrial, detección de intrusiones
 
Descripció del contingut i pla d'activitats:
Este Trabajo de Fin de Grado consiste en la implementación de una red OT simulada y el análisis de la detección de comportamientos maliciosos mediante una plataforma SIEM. Se construirá un entorno virtual que represente una red industrial básica, sobre el que se desplegarán distintos escenarios de ataque controlados. A partir de los eventos generados, se estudiará la capacidad del SIEM para detectar y analizar incidentes de seguridad. El proyecto se realizará utilizando herramientas open-source y entornos virtualizados, sin necesidad de hardware industrial real.
 
Overview (resum en anglès):
This project evaluates whether an open-source SIEM can monitor and detect attacks against an industrial network. A virtualised OT environment was built using Docker, consisting of a PLC exposing 100 holding registers over Modbus TCP, an HMI that polls the PLC periodically, and an attacker host. The monitoring stack is based on the Elastic Stack, with Packetbeat capturing network flows and Zeek parsing Modbus at the application layer, both forwarding data to Elasticsearch and Kibana, where detection rules were configured. Five attacks were executed against the PLC: port scanning, register enumeration, protocol abuse, unauthorised writes and a denial of service through connection exhaustion. The results show that Packetbeat only produces flow-level events and cannot interpret Modbus function codes, which limits its detection capability, while Zeek covers those gaps by generating specific alerts for each attack type. The main conclusion is that sensor placement and the ability to interpret the industrial protocol are more determinative than the SIEM technology itself.


© CBLTIC Campus del Baix Llobregat - UPC