Related Experiment Video
Updated: Jun 13, 2026

Integration of 5G Experimentation Infrastructures into a Multi-Site NFV Ecosystem
Published on: February 3, 2021
An Integrated Testbed for MITRE-Mapped Attack Emulation in Industrial Control Networks
Jaafer Rahmani1,2, Kai Oliver Detken3, Axel Sikora1
1Institute of Reliable Embedded Systems and Communication Electronics (ivESK), Offenburg University of Applied Sciences, 77652 Offenburg, Germany.
This study introduces a novel method for labeling Industrial Control System (ICS) traffic with specific MITRE ATT&CK technique identifiers. This enables precise evaluation of intrusion detection systems against sophisticated cyber threats in OT environments.
Area of Science:
- Cybersecurity
- Industrial Control Systems (ICS)
- Network Intrusion Detection
Background:
- Existing Industrial Control System (ICS) datasets lack per-technique labels for evaluating intrusion detection.
- Reconstructing MITRE ATT&CK technique information post-capture is complex and error-prone.
- There is a need for accurate ground truth in Operational Technology (OT) traffic for robust security assessments.
Purpose of the Study:
- To develop and demonstrate a methodology for capturing Industrial Control System (ICS) attack traffic with in-orchestrator, per-technique MITRE ATT&CK labeling.
- To create a protocol-aware detection pipeline for processing labeled OT traffic.
- To provide reproducible attack chains and a labeled dataset for benchmarking intrusion detection systems.
Main Methods:
- An in-orchestrator labeling methodology was implemented, embedding MITRE technique identifiers directly into traffic captures.
- A protocol-aware detection pipeline with a priority-ordered router was designed to dispatch traffic to specific detector plug-ins.
- Four CALDERA chains were developed to automate attacks and test the labeling and detection pipeline.
Main Results:
- A dataset of 40,000 benign and 9,997 attack Modbus sequences across four MITRE ATT&CK techniques was generated.
- The CNN-BiLSTM-AE model achieved a 100% true-positive rate (TPR) at the 98th-percentile benign threshold for all techniques.
- The system demonstrated high detection rates, with per-technique TPRs ranging from 96.1% to 100%.
Conclusions:
- The proposed in-orchestrator labeling methodology effectively provides per-technique ground truth for ICS attack traffic.
- The protocol-aware detection pipeline and labeled dataset enable accurate benchmarking of intrusion detection systems.
- This approach enhances the evaluation of cybersecurity defenses in Operational Technology (OT) environments.
Related Concept Videos
Automated Microbial Diagnostics
IP3/DAG Signaling Pathway
Multimachine Stability
In analyzing the system, the nodal equations represent the relationship between bus voltages, machine voltages, and machine currents. The nodal equation is given by:
Line Protection with Impedance Relays
Under normal conditions, low load currents keep the measured...
Electro-mechanical Systems
A key component of the DC motor is the armature, a rotating circuit positioned within a magnetic field. As an electric current passes through the...
Control Systems: Applications
In modern vehicles, control systems manage various functions to enhance performance and safety. The steering wheel and accelerator are primary inputs in a car's control system. The direction...
