JOURNAL ARTICLE

Automated Incident Response for Industrial Control Systems Leveraging Software-defined Networking

Abstract

Modern technologies and concepts for Industrial Control Systems (ICS) are evolving towards high flexibility of processes and respectively networks. Such dynamic networks are already functioning well, for example in data centres. This is enabled by application of the Software-defined Networking (SDN) paradigm. For this reason, ICS is currently adopting SDN. The concept of having a centralized view of the network and generating packet forwarding rules to control it enables performing automated responses to network events and classified incidents via SDN. This automation can provide timely and, due to the holistic view of the network, accurate incident response actions. However, availability, safety, real-time and redundancy requirements within the ICS domain restrict the application of such an automated approach. At present, SDN-based incident response (SDN-IR) does not take into consideration these requirements. In this work, we identify possible SND-based response actions to ICS incidents and introduce classification of assets and links. Furthermore, we present a concept for SDN-IR where a predefined rule set restricts the response actions based on the asset’s classification thereby satisfying ICS specific requirements. Subsequently, we describe and evaluate a prototype implementation of this concept, built with the open-source SDN platform OpenDaylight and the SDN protocol OpenFlow.

Keywords:
OpenFlow Computer science Software-defined networking Redundancy (engineering) Industrial control system Computer network Network packet Distributed computing Networking hardware Flexibility (engineering) Incident response Control (management) Computer security Operating system Artificial intelligence

Metrics

4
Cited By
0.19
FWCI (Field Weighted Citation Impact)
8
Refs
0.50
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Software-Defined Networks and 5G
Physical Sciences →  Computer Science →  Computer Networks and Communications
Smart Grid Security and Resilience
Physical Sciences →  Engineering →  Control and Systems Engineering
Software System Performance and Reliability
Physical Sciences →  Computer Science →  Computer Networks and Communications

Related Documents

JOURNAL ARTICLE

Automated Incident Response for Industrial Control Systems Leveraging Software-defined Networking

Patzer, FlorianMeshram, A.Heß, M.

Journal:   Fraunhofer-Gesellschaft zur Förderung der angewandten Forschung e.V Year: 2025
DISSERTATION

Software-Defined Networking Approaches for Intrusion Response in Industrial Control Systems

Etxezarreta, Xabier

University:   eRepository Mondragon University (Mondragon University) Year: 2024
JOURNAL ARTICLE

Software-Defined Networking approaches for intrusion response in Industrial Control Systems: A survey

Xabier EtxezarretaIñaki GaritanoMikel IturbeUrko Zurutuza

Journal:   International Journal of Critical Infrastructure Protection Year: 2023 Vol: 42 Pages: 100615-100615
© 2026 ScienceGate Book Chapters — All rights reserved.