Skip to the content.

OT-Security-Lab: Integrated Industrial Control System (ICS) Security Environment

Compliance Framework License: MIT CI Compliance Gate Site Contributing Security

Category Specification
Industry Water Treatment & Filtration
Frameworks IEC 62443, MITRE ATT&CK for ICS, ISA-95 Purdue Model
Environment 5-Zone Segmented Docker Lab with L3/L4 Firewall
Monitoring Protocol-Aware (Modbus/TCP) Anomaly detection
Evidence Verified Attack Simulation Logs

Project Overview

This repository contains a full-scale, simulated industrial environment designed to demonstrate the implementation of robust security controls within an Operational Technology (OT) context. The project encompasses the entire lifecycle of an IT/OT Security Engineer’s responsibilities: from architectural design and network segmentation based on the Purdue Model, to threat modeling, detection engineering, and IEC 62443 compliance mapping.

The lab simulates a Water Treatment & Filtration Facility, facilitating a hands-on platform for validating security configurations and detection rules against realistic ICS attack vectors.


2. Architecture: The Purdue Model

The environment is segmented into logical levels according to the ISA-95 Purdue Model, ensuring strict isolation of critical control processes.

graph TD
    %% Level Definition
    subgraph L4_5 ["Level 4 & 5: Enterprise"]
        A[Attacker Simulation]
        B[Corporate Workstation]
    end

    subgraph DMZ ["Industrial DMZ"]
        JH[Jump Host / Bastion]
        RP[Reverse Proxy]
    end

    subgraph L3 ["Level 3: Operations"]
        C[Historian - InfluxDB]
        D[Engineering Workstation]
    end

    subgraph L2 ["Level 2: Supervisory"]
        E[SCADA / HMI Server]
    end

    subgraph L1 ["Level 1: Control"]
        F1[PLC-01: Intake]
        F2[PLC-02: Treatment]
        F3[PLC-03: Distribution]
    end

    subgraph L0 ["Level 0: Field Devices"]
        G[Sensors/Actuators]
    end

    %% Conduits
    B ---|VPN/HTTPS| JH
    JH ---|RDP/SSH| D
    D ---|S7/Modbus| F1
    E ---|Modbus/TCP| F1
    E ---|Modbus/TCP| F2
    E ---|Modbus/TCP| F3
    F1 ---|Process Flow| F2
    F2 ---|Process Flow| F3
    F3 ---|Hardwired| G

    %% Styling
    style DMZ fill:#fff2cc,stroke:#d6b656,stroke-width:2px
    style L1 fill:#fdb,stroke:#333,stroke-width:2px

Purdue Levels Mapping:


3. Table of Contents

  1. Architecture & Design
  2. Lab Environment
  3. Asset Inventory
  4. Threat Model & Risk Analysis
  5. Detection & Monitoring

Physics-Aware Violation Demo

* [Modbus Anomaly Detection](./detection/rules/modbus_anomaly.py)
* [**Physics-Aware Safety Monitor**](./detection/rules/process_safety_violation.py)
* [Cross-Zone Traffic Alerter](./detection/rules/cross_zone_traffic.py)
*   [Brute Force Detection](./detection/rules/ot_brute_force.py)
*   [**Live Detection Evidence (JSON Logs)**](./detection/logs/alerts.json) — refreshed automatically by the Compliance Gate on every green run 6.  [Hardening & Compliance](./hardening/)
*   [Security Hardening Checklist](./hardening/HARDENING_CHECKLIST.md)
*   [IEC 62443 Gap Analysis](./iec62443/gap-analysis.csv) 7.  [Incident Response](./incident-response/)
*   [PLC Unauthorized Change Playbook](./incident-response/ir-playbook-unauthorised-plc-change.md) 8.  [Engineering Post-Mortem](./LESSONS_LEARNED.md)

Integrated SIEM Dashboard (Loki & Grafana)

SOC Overview Dashboard

Forensic Log Analysis (MITRE ATT&CK Mapping)

Loki Raw Logs


4. Governance, Risk & Compliance (GRC)

To bridge the gap between technical implementation and industrial standards (Exceltic/ISA-62443 requirements), this lab includes formal documentation:


5. Scalability & Protocol Realities

This lab currently utilizes Modbus TCP as a representative industrial protocol. In a production rollout (e.g., Railway/Transportation):


6. Key Findings & Engineering Judgments


7. Getting Started

To spin up the entire simulated environment (OpenPLC, HMI, Historian, and Firewall):

# Clone the repository
git clone https://github.com/LiamCarPer/OT-Security-Lab.git
cd ot-security-lab

# Start the environment (firewall rules and IDS rules apply automatically)
make up

# Validate the environment: simulate attacks and assert detection
make compliance

The gateway container applies the IEC 62443 zone firewall on boot and launches all custom detection rules as persistent services (make up is sufficient; no manual docker cp/docker exec steps are required).


8. Technologies Used

8.1 CI/CD & Supply Chain


9. Known Limitations & Future Work

Current Limitations:

Future Roadmap:


10. Compliance Mapping