Original title:
Testování kybernetické bezpečnosti energetických a průmyslových zařízení
Translated title:
Cybersecurity testing of energy and industrial devices
Authors:
Cíbik, Jakub ; Kuchař, Karel (referee) ; Blažek, Petr (advisor) Document type: Bachelor's theses
Year:
2026
Language:
slo Publisher:
Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií Abstract:
[slo][eng]
Táto práca sa zaoberá testovaním kybernetickej bezpečnosti energetických a priemysel- ných zariadení typu RTU. Vychádza z existujúcej metodiky testovania bezpečnostných parametrov, ktorú aktualizuje vzhľadom na aktuálne požiadavky a regulácie, ako sú NIS2, rámec ENISA Cyber Stress Testing a odporúčania NIST. Prvým príspevkom práce je dopl- nenie metodiky o konkrétne technické parametre v nasledujúcich oblastiach: kryptografia, bezpečnostné logovanie, bezpečné spúšťanie a aktualizácie (verifikácia podpisu a časo- vých pečiatok) a systémový hardening (ASLR, whitelisting portov). Druhým príspevkom je návrh a implementácia sady skriptov pre jednotlivé testy metodiky, ktoré poskytujú zjednotený výstup testov a dôkazného materiálu pre potreby auditu a opakovateľnosti. Súčasťou práce je aj porovnanie vybraných linuxových distribúcií a určenie tých, ktoré sú vhodné pre použitie v OT prostredí. Navrhnutý postup je overený na viacerých za- riadeniach typu RTU. Výsledky poskytujú prehľadné PASS/WARN/FAIL vyhodnotenie jednotlivých testov. Práca tak prináša použiteľnú a auditovateľnú metodiku doplnenú o automatizačnú sadu, ktorú je možné ďalej rozvíjať.
This thesis focuses on cybersecurity testing of Remote Terminal Unit (RTU) devices used in industrial and energy infrastructures. It builds on an existing security testing methodology and extends it in line with current requirements and regulations, such as NIS2, the ENISA Cyber Stress Testing framework, and NIST recommendations. The first contribution of the thesis is the enhancement of the methodology with specific techni- cal requirements in the areas of cryptography, security logging, secure boot and update mechanisms (signature and timestamp verification), and system hardening (ASLR, port whitelisting). The second contribution is the design and implementation of a set of scripts that automate the execution of individual tests and provide unified test outputs and evidence required for audit and repeatability. The thesis also evaluates selected Linux distributions and identifies those most suitable for use in OT environments. The proposed approach was verified on multiple RTU devices.The results provide clear PASS/WARN/- FAIL evaluation across the tested categories. The thesis delivers a practical and auditable methodology supported by an automation toolkit that can be further expanded.
Keywords:
cybersecurity; ENISA; hardening; industrial control systems; Linux distri- butions; NIS2; NIST; remote terminal units
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/258285