Analysis of Publicly Accessible Operational Technology and Associated Risks

📅 2025-08-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Industrial operational technology (OT) systems—prioritizing functionality over security—are frequently misconfigured and exposed to the public Internet, posing severe cyber-physical risks. Method: We propose a comprehensive framework integrating cyberspace mapping, protocol fingerprinting, firmware version analysis, and a novel automated HMI/SCADA interface screenshot recognition technique to systematically assess global OT exposure. Our methodology correlates findings with vulnerability databases (e.g., NVD, ICS-CERT) and geolocation data across protocols, vendors, software, and regions. Contribution/Results: We identify nearly 70,000 publicly exposed OT devices, predominantly in North America and Europe; many run outdated firmware containing known critical vulnerabilities and remain unpatched for extended periods. Crucially, our interface-based analysis uncovers multiple previously undocumented unauthorized access paths—enabling the first large-scale, visually grounded quantification of real-world industrial attack surfaces and delivering actionable, operationally relevant insights for risk mitigation.

Technology Category

Application Domains: Internet of Things, Sensor Networks & Smart CitiesPlanning, Routing, and Scheduling: Optimization of Spatio-temporal SystemsSearch and Optimization: Distributed Search

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deploymentsSecurity and Privacy: Large-scale security measurementsWeb Mining and Content Analysis: Web data provenance, reliability, and authenticity
📝 Abstract
Operational Technology (OT) is an integral component of critical national infrastructure, enabling automation and control in industries such as energy, manufacturing, and transportation. However, OT networks, systems, and devices have been designed and deployed prioritising functionality rather than security. This leads to inherent vulnerabilities in many deployed systems when operational misconfigurations expose them to the internet. This report provides an up-to-date overview of the OT threat landscape exposed to the public internet and studies the affected protocols, vendors, software, and the geographic distribution of systems. Our findings reveal nearly 70,000 exposed OT devices globally, with significant concentrations in North America and Europe. Analysis of prevalent protocols (e.g., ModbusTCP, EtherNet/IP, S7) shows that many devices expose detailed identifying information, including outdated firmware versions with known critical vulnerabilities that remain unpatched for years after disclosure. Furthermore, we demonstrate how automated analysis of screenshots can uncover exposed graphical interfaces of Human Machine Interfaces (HMIs) and Supervisory Control and Data Acquisition (SCADA) systems, highlighting diverse pathways for potential unauthorized access and underscoring the risks to industrial processes and critical infrastructure.
Problem

Research questions and friction points this paper is trying to address.

Identifies vulnerabilities in OT devices exposed to the internet
Analyzes geographic and protocol distribution of exposed OT systems
Demonstrates risks from unpatched firmware and exposed interfaces
Innovation

Methods, ideas, or system contributions that make the work stand out.

Automated analysis of exposed OT devices
Identification of outdated firmware vulnerabilities
Screenshot analysis for exposed HMI interfaces
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.