Ανάπτυξη συστήματος ενσωμάτωσης αυτόματων ελέγχων ασφάλειας σε συστήματα καταγραφής αγαθών

Development of a System for Integrating Automated Security Controls into Goods Tracking Systems (Αγγλική)

  1. MSc thesis
  2. ΠΑΝΑΓΙΩΤΗΣ ΜΠΕΛΗΓΙΑΝΝΗΣ
  3. Συστήματα Κινητού και Διάχυτου Υπολογισμού (ΣΔΥ)
  4. 27 Σεπτεμβρίου 2026
  5. Ελληνικά
  6. 144
  7. Αχιλλέας Καμέας
  8. Νικόλαος Σκλάβος
  9. Industrial Internet of Things (IIoT), Cybersecurity in Logistics, Intrusion Detection Systems (IDS), Scalable Architecture, ROC Curve & AUC, Queueing Theory (M/M/1), Performance Evaluation, ANOVA Statistical Analysis, Attack Detection, Flask – Celery Distributed Systems
  10. ΣΔΥ51
  11. 4
  12. 62
  13. Περιλαμβάνει: Πίνακες, Διαγράμματα, Παραρτήματα
    • Η παρούσα μεταπτυχιακή διατριβή πραγματεύεται τον σχεδιασμό, την υλοποίηση και την πειραματική αξιολόγηση ενός κλιμακούμενου συστήματος ανίχνευσης επιθέσεων και εντοπισμού ευπαθειών σε περιβάλλον Industrial Internet of Things (IIoT) με έμφαση σε εφαρμογές logistics. Η έρευνα εστιάζει στην ανάγκη αυτοματοποιημένης παρακολούθησης βιομηχανικών και υβριδικών IT/OT υποδομών, λαμβάνοντας υπόψη τη διευρυνόμενη επιφάνεια επίθεσης και τις σύγχρονες απειλές κυβερνοασφάλειας.

      Το προτεινόμενο σύστημα υλοποιήθηκε με αρχιτεκτονική Flask + Celery και αξιολογήθηκε σε περιβάλλον έως 310 agents, επιτυγχάνοντας 100% detection rate με μηδενικά false positives. Η ανάλυση απόδοσης έδειξε γραμμική κλιμάκωση για μικρό φόρτο (17–62 agents) και σταδιακό κορεσμό μετά τους 100 agents , με θεωρητικό μοντέλο λογιστικής κλιμάκωσης (R² = 0.97). Η στατιστική ανάλυση (ANOVA) επιβεβαίωσε τη σημαντική επίδραση του φόρτου στην απόδοση (p < 0.001)

      Η αξιολόγηση ανίχνευσης επιθέσεων (Port Scan, Brute Force, Telemetry Flood) κατέδειξε υψηλή αποτελεσματικότητα, με μέσο χρόνο ανίχνευσης 11.6 sec και AUC = 0.98 στην καμπύλη ROC , γεγονός που καταδεικνύει εξαιρετική διακριτική ικανότητα του συστήματος. Επιπλέον, πραγματοποιήθηκε συγκριτική ανάλυση με σύγχρονες προσεγγίσεις της βιβλιογραφίας, όπου το σύστημα παρουσίασε ανώτερη απόδοση τόσο σε detection rate όσο και σε latency

      Τα αποτελέσματα τεκμηριώνουν ότι η προτεινόμενη αρχιτεκτονική μπορεί να υποστηρίξει βιομηχανικό περιβάλλον μεγάλης κλίμακας με υψηλή αξιοπιστία και προβλεψιμότητα συμπεριφοράς, συνδυάζοντας θεωρητικά μοντέλα ουρών με εμπειρική αξιολόγηση.

    • This master’s thesis presents the design, implementation, and experimental evaluation of a scalable intrusion detection and vulnerability identification system for Industrial Internet of Things (IIoT) environments, with particular emphasis on logistics applications. The research addresses the increasing need for automated monitoring of hybrid IT/OT infrastructures, considering the expanding attack surface and the evolving landscape of cybersecurity threats in industrial ecosystems.

      The proposed system was implemented using a Flask + Celery distributed architecture and experimentally evaluated in environments scaling up to 310 agents. The platform achieved a 100% detection rate with zero false positives, demonstrating high reliability in identifying Port Scanning, Brute Force, and Telemetry Flood attacks. Performance analysis revealed linear scalability under low workload conditions (17–62 agents) and gradual resource saturation beyond 100 agents. A logistic scalability model demonstrated excellent goodness-of-fit (R² = 0.97), while statistical analysis (ANOVA) confirmed the significant impact of workload on system performance (p < 0.001).

      The attack detection evaluation yielded an Area Under the ROC Curve (AUC) of 0.98, indicating excellent discriminative capability. Furthermore, comparative analysis against related state-of-the-art architectures showed superior performance in terms of detection rate and latency.

      The findings demonstrate that the proposed architecture can effectively support large-scale industrial monitoring scenarios with high accuracy, scalability, and predictable behavior. By integrating queueing theory modeling (M/M/1) with empirical cybersecurity experimentation, the study bridges theoretical performance modeling and practical IIoT security implementation.

  14. Hellenic Open University
  15. Attribution-NonCommercial-NoDerivatives 4.0 Διεθνές