Latency-aware architectural mediation for containing IT-OT lateral movement in critical infrastructure

Cornelius Chipasha, Simon Tembo, Mulundumina Shimaponda

Abstract


Critical Digital Infrastructure (CDI),  integrated enterprise IT and OT systems supporting essential services including energy, transport, and industrial automation,  increasingly exposes legacy operational technology (OT) to adversarial lateral movement originating in enterprise IT networks. This paper evaluates mediation-based architectural containment at the IT-OT boundary across eight network scales (N = 50-500 nodes) using 30 Monte Carlo simulation runs per configuration. Three baseline configurations are compared: unrestricted propagation, permissive firewall, and full mediation. Against a permissive firewall baseline, mediation achieves an additional 93-99% reduction in Total Compromised Nodes (TCN), confirmed by Mann-Whitney U tests (all p < 10^-10) with complete rank separation between mediated and baseline distributions. Complete rank separation arises because hop-limit enforcement imposes a hard structural bound on propagation distance. The purpose of the simulation is to quantify the containment, latency, and availability consequences of enforcing a specific architectural constraint under a bounded adversary model, not to prove universal attack prevention. The mediation gateway introduces measured mean RTT overhead of 0.42-0.52 ms; estimated real-world overhead at 5x-10x production scaling, applied as engineering safety margins rather than empirically derived constants, is 2.1-5.2 ms, remaining below 5.2% of IEC 61850 MMS timing tolerance. Under the adopted operational-service trust model, baseline SAI falls to 0.000 once OT services are compromised or no longer safely usable; mediated SAI is preserved at 0.965-0.995. Core operational asset compromise was not achieved in any of 240 simulation runs under the bounded adversary model.

Received 11 June 2026

Accepted 27 July 2026

Published 16 September 2026


Keywords


Critical Digital Infrastructure; IT-OT Security; Architectural Mediation; Lateral Movement Containment; Network Segmentation; Industrial Control Systems Security; IEC 62443; Cyber Resilience

Full Text:

PDF

References


A. A. Cárdenas, S. Amin, and S. Sastry, “Research Challenges for the Security of Control Systems,” in 3rd USENIX Workshop on Hot Topics in Security, San Jose, CA, USA, Jan. 2008.

E. Byres, “The Myths and Facts Behind Cyber Security Risks for Industrial Control Systems,” in VDE Kongress, Berlin, Germany, Dec. 2004, pp. 213–218.

R. Mitchell and I.-R. Chen, “A Survey of Intrusion Detection Techniques for Cyber-Physical Systems,” ACM Computing Surveys, vol. 46, no. 4, pp. 1–29, Mar. 2014, doi: 10.1145/2542049.

S. Adepu and A. Mathur, “Distributed Attack Detection in a Water Treatment Plant: Method and Case Study,” IEEE Transactions on Dependable and Secure Computing, vol. 18, no. 1, pp. 86–99, Jan. 2021, doi: 10.1109/tdsc.2018.2875008.

K. Stouffer, M. Pease, C. Tang, T. Zimmerman , V. Pillitteri, and S. Lightman, Guide to Operational Technology (OT) Security. Gaithersburg, MD, USA: NIST Special Publication (SP) 800-82 Rev. 3, 2023. doi: 10.6028/nist.sp.800-82r3.

International Society of Automation (ISA) and International Electrotechnical Commission (IEC), Security for Industrial Automation and Control Systems. Research Triangle Park, NC, USA: ISA/IEC 62443 Standards Series, 2018.

A. Humayed, J. Lin, F. Li, and B. Luo, “Cyber-Physical Systems Security—a Survey,” IEEE Internet of Things Journal, vol. 4, no. 6, pp. 1802–1831, Dec. 2017, doi: 10.1109/jiot.2017.2703172.

N. Tuptuk and S. Hailes, “Security of Smart Manufacturing Systems,” Journal of Manufacturing Systems, vol. 47, pp. 93–106, Apr. 2018, doi: 10.1016/j.jmsy.2018.04.007.

E. D Knapp and J. Langill, Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems, 2Nd edition. Waltham, MA, USA: Syngress, 2015.

R. Langner, “Stuxnet: Dissecting a Cyberwarfare Weapon,” IEEE Security & Privacy Magazine, vol. 9, no. 3, pp. 49–51, May 2011, doi: 10.1109/msp.2011.67.

S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, Gaithersburg, MD, USA, vol. 1, Aug. 2020, doi: 10.6028/nist.sp.800-207.

B. Lantz, B. Heller, and N. McKeown, “A network in a laptop: Rapid prototyping for software-defined networks,” in 9th ACM SIGCOMM Workshop on Hot Topics in Networks (HotNets-IX), Monterey, CA, USA: ACM, 2010. doi: 10.1145/1868447.1868466.

F. Callegati, S. Giallorenzo, A. Melis, S. Melloni, M. Prandini, and A. Vannini, “Investigating Operational Technology Attacks as Code,” Empirical Software Engineering, vol. 30, no. 6, p. 153, Sep. 2025, doi: 10.1007/s10664-025-10713-2.

M. Boeding, M. Hempel, and H. Sharif, “End-to-End Framework for Identifying Vulnerabilities of Operational Technology Protocols and Their Implementations in Industrial IoT,” Future Internet, vol. 17, no. 1, p. 34, Jan. 2025, doi: 10.3390/fi17010034.

T. Sishuba, E. Innocents, and P. A. Pradhan, “A Systematic Review of the Implementation of IT and OT Cybersecurity Standards in an IT/OT Converged Environment,” in 7th European Conference on Industrial Engineering and Operations Management, Jul. 2024. doi: 10.46254/eu07.20240093.

D. Kuipers and M. Fabro, “Control Systems Cyber Security:Defense in Depth Strategies,” Idaho National Laboratory, Tech. Rep. INL/CON-06-01154, Idaho Falls, ID, USA, May 2006. doi: 10.2172/911553.

G. Schäfer, H. Waclawek, C. Binder, S. Huber, and A. Lüder, “IT/OT Integration by Design: Security architecture for converged systems,” arXiv (Cornell University), Jan. 2023, doi: 10.48550/arxiv.2305.19735.

M. M. Aslam, A. Tufail, A. Awg, Silva, and Muhammad Taqi Raza, “Scrutinizing Security in Industrial Control Systems: An Architectural Vulnerabilities and Communication Network Perspective,” IEEE Access, vol. 12, pp. 1–1, Jan. 2024, doi: 10.1109/access.2024.3394848.

K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, and A. Hahn, “Guide to Industrial Control Systems (ICS) Security,” NIST Special Publication 800-82, Vol. 1, Rev Gaithersburg, MD, USA, May 2011, doi: 10.6028/NIST.SP.800-82r2.

R. Ross, M. McEvilley, and J. C. Oren, “Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems,” NIST Special Publication 800-160, vol. 1, Mar. 2018, doi: 10.6028/nist.sp.800-160v1.

C. Queiroz, A. Mahmood, and Z. Tari, “SCADASim—a Framework for Building SCADA Simulations,” IEEE Transactions on Smart Grid, vol. 2, no. 4, pp. 589–597, Dec. 2011, doi: 10.1109/tsg.2011.2162432.

A. Lemay , J. Fernandez , and S. Knight, “An isolated virtual cluster for SCADA network security research,” in 1st International Symposium for ICS & SCADA Cyber Security Research 2013 (ICS-CSR 2013) (ICSCSR), Leicester, UK, 2013.

E. D. Knapp and J. T. Langill, “Security monitoring of industrial control systems,” in Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems, MA, USA: Syngress: Waltham, 2015, pp. 351–386.

Cybersecurity and Infrastructure Security Agency (CISA), “Zero Trust Maturity Model Version 2.0,” 2023. Accessed: Aug. 20, 2026. [Online]. Available: https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf

European Union Agency for Cybersecurity (ENISA), “ENISA Threat Landscape 2024,” Oct. 2024. [Online]. Available: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024

F. Holik, M. M. Cook, X. Li, A. A. Shah, and D. Pezaros, “Programmable Data Planes for Increased Digital Resilience in OT Networks,” IEEE Communications Magazine, vol. 63, no. 7, pp. 162–169, Jul. 2025, doi: 10.1109/mcom.001.2400446.

M. Ahmed, A. Naser Mahmood, and J. Hu, “A Survey of Network Anomaly Detection Techniques,” Journal of Network and Computer Applications, vol. 60, pp. 19–31, Jan. 2016, doi: 10.1016/j.jnca.2015.11.016.

K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, and A. Hahn, “NIST Special Publication 800-82 Revision 2 Guide to Industrial Control Systems (ICS) Security Supervisory Control and Data Acquisition (SCADA) Systems, Distributed Control Systems (DCS), and Other Control System Configurations Such as Programmable Logic Controllers (PLC),” NIST, vol. 2, May 2015, doi: 10.6028/NIST.SP.800-82r2.

E. Johansson, “Securing the Industrial Cyber Space With IEC 62443,” Engineering & Technology Reference, Mar. 2016, doi: 10.1049/etr.2015.0140.

R. Khan, K. McLaughlin, B. Kang, D. Laverty, and S. Sezer, “A Secure Cloud Migration, Monitoring and Analytics Framework for Industrial Internet of Things,” 2020 IEEE 6th World Forum on Internet of Things (WF-IoT), pp. 1–6, Jun. 2020, doi: 10.1109/wf-iot48130.2020.9221106.

Y. Cherdantseva et al., “A Review of Cyber Security Risk Assessment Methods for SCADA Systems,” Computers & Security, vol. 56, no. 56, pp. 1–27, Feb. 2016, doi: 10.1016/j.cose.2015.09.009.

Cybersecurity and Infrastructure Security Agency (CISA), “Cross-Sector Cybersecurity Performance Goals.” [Online]. Available: https://www.cisa.gov/cross-sector-cybersecurity-performance-goals.

MITRE Corporation, “Matrix | MITRE ATT&CK for ICS.” [Online]. Available: https://attack.mitre.org/matrices/ics/

B. Kim, M. A. Alawami, E. Kim, S. Oh, J. Park, and H. Kim, “A Comparative Study of Time Series Anomaly Detection Models for Industrial Control Systems,” Sensors, vol. 23, no. 3, p. 1310, Jan. 2023, doi: 10.3390/s23031310.

E. Anthi, L. Williams, M. Rhode, P. Burnap, and A. Wedgbury, “Adversarial Attacks on Machine Learning Cybersecurity Defences in Industrial Control Systems,” Journal of Information Security and Applications, vol. 58, no. Art, p. 102717, May 2021, doi: 10.1016/j.jisa.2020.102717.

C. Smiliotopoulos, G. Kambourakis, and C. Kolias, “Detecting Lateral Movement: A Systematic Survey,” Heliyon, vol. 10, no. 4, pp. e26317-e26317, Feb. 2024, doi: 10.1016/j.heliyon.2024.e26317.

Z. El Mrabet, N. Kaabouch, H. El Ghazi, and H. El Ghazi, “Cyber-Security in Smart Grid: Survey and Challenges,” Computers & Electrical Engineering, vol. 67, pp. 469–482, Apr. 2018, doi: 10.1016/j.compeleceng.2018.01.015.

R. S. H. Piggin, “Development of industrial cyber security standards: IEC 62443 for SCADA and industrial control system security,” in IET Conference on Control and Automation 2013: Uniting Problems and Solutions, Birmingham, UK, Jun. 2013, p. 11.

N. Vlajic, J. Sarai, and G. Novkovic, “Comprehensive Study of ICS Malware Attacks & Prioritizing Critical Defenses Using MITRE ATT&CK,” in International Conference on Communication, Computing, Networking, and Control in Cyber-Physical Systems (CCNCPS), Jun. 2025, pp. 262–269. Accessed: Sep. 01, 2026. [Online]. Available: https://ieeexplore.ieee.org/document/11135791

P. Radanliev et al., “Cyber Security Framework for the Internet-of-Things in Industry 4.0,” www.preprints.org, Mar. 2019, doi: 10.20944/preprints201903.0111.v1.

W. Knowles, D. Prince, D. Hutchison, J. F. P. Disso, and K. Jones, “A Survey of Cyber Security Management in Industrial Control Systems,” International Journal of Critical Infrastructure Protection, vol. 9, pp. 52–80, Jun. 2015, doi: 10.1016/j.ijcip.2015.02.002.




DOI: https://dx.doi.org/10.21622/ACE.2026.06.2.2264

Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Cornelius Chipasha, Simon Tembo, Mulundumina Shimaponda


Advances in Computing and Engineering

E-ISSN: 2735-5985

P-ISSN: 2735-5977

 

Published by:

Academy Publishing Center (APC)

Arab Academy for Science, Technology and Maritime Transport (AASTMT)

Alexandria, Egypt

ace@aast.edu