Date of Award
2026-05-01
Degree Name
Master of Science
Department
Computer Science
Advisor(s)
Deepak K. Tosh
Abstract
Live vulnerability testing and penetration assessments of critical infrastructure are costly, complex operationally and, in many cases, unsafe to conduct directly against live systems, whether these are commissioned in-house and through third-party providers. For Operational Technology environments specifically, these constraints are further aggravated by the limited vendor support and inconsistent security patching available that characterize many industrial communication protocols. This significantly restricts the scope and feasibility of conventional penetration testing. At the same time, the increasing overlapping of OT systems with enterprise networks and the internet has expanded the attack surface of ICS infrastructure, making more pressing the need for safe, reproducible and grounded security testing methodologies. Successful attacks against OT environments carry consequences that can extend well beyond traditional IT incidents, not limited to physical damage, halted industrial processes and direct threats to human life. And yet, the tools and methodologies available for safely detecting and analyzing adversarial behavior in these environments remain insufficient. This thesis proposes and evaluates a methodology for emulation, detection and behavior analysis of APT campaigns in virtualized OT environments, addressing the gap between the theoretical understanding of OT threats and the practical ability to test and validate the mitigation against them. The CALDERA attack emulation framework, extended with its OT-specific plugin, is employed as the primary platform for conducting controlled APT emulations against ICS infrastructure, enabling the safe identification of vulnerabilities and the validation of security responses without exposing live systems to risk. Two complementary graph-based visualization approaches are then investigated as tools for analysis: provenance graphs, created from CALDERA's operation reports and process trees, derived from system security logs, in both cases they capture the evolution of attacks and the evolution of host behavior across baseline, active and post-attack stages. This experimental methodology centers on the emulation of two documented APT campaigns, ArcaneDoor, a state-sponsored campaign targeting edge devices and engineering workstations through a diverse method of implants and command-and-control channels, is emulated over a two-week period across five stages to reproduce the extended timeline and persistence characteristics. Night Dragon, a cyber espionage operation centering on SCADA systems and operational data in the energy section, replicated with a focus on discovery and exfiltration stages against a virtualized ICS environment. Both campaigns were executed across two dedicated OT testbeds, Labshock and vicsort, with each attack mapped to its corresponding MITRE ATT\&CK technique to ensure consistency across behaviors with real-world adversary methods. The results demonstrate that provenance graphs provide a graphical view at a command level for the operation and the causal relationship between each, successfully revealing orchestration topologies, adaptive and redundant scanning behavior, and evidence of direct human involvement across stages. A particularly significant finding is that the provenance graph generated for the Modbus attack is structurally identical to the general Discovery graph, indicating that OT-targeted reconnaissance bears resemblance to standard IT intrusion. This result carries direct implications for the design of OT specific detection systems and underscores the limitation of these graphs as a standalone detection mechanism. Process tree analysis addresses this limitation by capturing host-level deviations in behavior that provenance graphs do not reflect, tracking the evolution of node creation corresponding to shell activity, system discovery and system crashes that can be attributed to the final stage of ArcaneDoor emulation. The combination of both methods is proven to provide a more complete and actionable characterization of APT behavior than either approach alone, with each method presented compensating for the blind spot of the other. The work done here contributes a reproducible and safely executable emulation methodology for APT campaigns targeting OT infrastructure, a dual graph-based framework for behavioral threat detection, and a foundation for future integration with machine learning-based IDS. the findings further demonstrate that CALDERA enhanced by the OT-specific plugins and graph-based analysis, constitutes a viable and accessible platform through which organizations can identify vulnerabilities, validate security protocols and develop empirically grounded in depth defense strategies for OT environments without compromising the availability of live systems.
Language
en
Provenance
Received from ProQuest
Copyright Date
2026-05
File Size
80 p.
File Format
application/pdf
Rights Holder
Laura Aminta Guevara
Recommended Citation
Guevara, Laura Aminta, "Provenance Analysis Of Advanced Persistent Threats In Operational Technology Environments" (2026). Open Access Theses & Dissertations. 4694.
https://scholarworks.utep.edu/open_etd/4694