Cyber Threat Intelligence for Industrial Control System
Mr. JEYAPRAKASH S 1, Mr. RAMESH E R 2,
1 Mr. JEYAPRAKASH S, M.sc CFIS, Department of Computer Science Engineering,
jeyaprakash6303@gmail.com, 6379892639, Dr. MGR UNIVERSITY, Chennai, India
2 Mr. RAMESH E R, Assistant Professor, Center Of Excellence in Digital Forensics, Chennai, India
---------------------------------------------------------------------***---------------------------------------------------------------------
Abstract - The ICS Sentinel platform is a state-of-the-art cyber threat intelligence (CTI) solution intended to protect Industrial Control Systems (ICS) against emerging cyber threats. It is developed with a contemporary web architecture, utilizing a React 18.2.0 frontend with Vite, Tailwind CSS, and markdown rendering for user-friendly threat analysis and reporting. The platform includes a secure, role-based authentication mechanism with guarded routing, providing authorized access to key functionalities. Its RESTful API allows for hassle-free communication with a backend for real-time data retrieval of threats, user administration, and generation of reports. The main constituents are a threat dashboard, extensive analysis interface, and report generator, which provide security teams an effective means of monitoring, analyzing, and acting on ICS-specific threats. The system makes use of React Context API as a state management tool and Axios for strong API interactions, augmented by loading and error states that improve user experience. Containerized through a multi-stage Docker build (build: Node 20.9.0, prod: Nginx 1.25.3-alpine), ICS Sentinel promotes scalable, secure deployment. Engineered for use on critical infrastructure, it speaks to the singular cybersecurity concerns of ICS environments with actionable intelligence, responsive design, and alignment with best practice in component separation, secure communication, and sustainable styling. Through the combination of threat indicator management and technical analysis, ICS Sentinel enables organizations to enhance their cybersecurity stance, reduce risks, and safeguard critical industrial operations from advanced cyber attacks.
Key Words: ICS, SCADA, IOC, MATLAB, SIEM, Cyber Threat.