An Approach to Generate Attack Graphs with a Case Study on Siemens PCS7 Blueprint for Water Treatment Plants

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Miranda, Lucas, Banjar, Carlos, Menasche, Daniel, Kocheturov, Anton, Srivastava, Gaurav, Limmer, Tobias
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866913072363339776
author Miranda, Lucas
Banjar, Carlos
Menasche, Daniel
Kocheturov, Anton
Srivastava, Gaurav
Limmer, Tobias
author_facet Miranda, Lucas
Banjar, Carlos
Menasche, Daniel
Kocheturov, Anton
Srivastava, Gaurav
Limmer, Tobias
contents Assessing the security posture of Industrial Control Systems (ICS) is critical for protecting essential infrastructure. However, the complexity and scale of these environments make it challenging to identify and prioritize potential attack paths. This paper introduces a semi-automated approach for generating attack graphs in ICS environments to visualize and analyze multi-step attack scenarios. Our methodology integrates network topology information with vulnerability data to construct a model of the system. This model is then processed by a stateful traversal algorithm to identify potential exploit chains based on preconditions and consequences. We present a case study applying the proposed framework to the Siemens PCS7 Cybersecurity Blueprint for Water Treatment Plants. The results demonstrate the framework's ability to simulate different attack scenarios, including those originating from known CVEs and potential device misconfigurations. We show how a single point of failure can compromise network segmentation and how patching a critical vulnerability can protect an entire security zone, providing actionable insights for risk mitigation.
format Preprint
id arxiv_https___arxiv_org_abs_2603_24888
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle An Approach to Generate Attack Graphs with a Case Study on Siemens PCS7 Blueprint for Water Treatment Plants
Miranda, Lucas
Banjar, Carlos
Menasche, Daniel
Kocheturov, Anton
Srivastava, Gaurav
Limmer, Tobias
Cryptography and Security
Assessing the security posture of Industrial Control Systems (ICS) is critical for protecting essential infrastructure. However, the complexity and scale of these environments make it challenging to identify and prioritize potential attack paths. This paper introduces a semi-automated approach for generating attack graphs in ICS environments to visualize and analyze multi-step attack scenarios. Our methodology integrates network topology information with vulnerability data to construct a model of the system. This model is then processed by a stateful traversal algorithm to identify potential exploit chains based on preconditions and consequences. We present a case study applying the proposed framework to the Siemens PCS7 Cybersecurity Blueprint for Water Treatment Plants. The results demonstrate the framework's ability to simulate different attack scenarios, including those originating from known CVEs and potential device misconfigurations. We show how a single point of failure can compromise network segmentation and how patching a critical vulnerability can protect an entire security zone, providing actionable insights for risk mitigation.
title An Approach to Generate Attack Graphs with a Case Study on Siemens PCS7 Blueprint for Water Treatment Plants
topic Cryptography and Security
url https://arxiv.org/abs/2603.24888