Self-reconfiguration of industrial control systems as a response to cyberattacks

preprint OA: closed
Full text JSON View at publisher
AI-generated summary by claude@2026-07, 2026-07-16

This paper proposes and models a self-reconfiguring industrial control system that uses task migration to maintain functionality when components are compromised by cyberattacks.

One-sentence paraphrase of the abstract; not a substitute for reading it. No clinical advice. How this works

AI-generated deep summary by claude@2026-07, 2026-07-16 · read from full text

This paper studies how to defend industrial control systems (ICS) against cyberattacks by using self-reconfiguration rather than conventional IT responses that may sacrifice availability. The authors propose that when a component is detected as compromised, virtualization enables dynamic migration of tasks from that device to healthy ones, while containing the attack, and they model the problem using IEC 62443 as zones connected by conduits with security levels, device capacities, application dependencies, and communication constraints. They formulate task migration as a constraint programming optimization problem and evaluate variants that activate countermeasures or conduits and that preemptively allocate application instances under memory limits, measuring reconfiguration execution time and resilience (the number of devices attacked before a critical application must be stopped). A major limitation explicitly acknowledged in the article is that it is a preprint/has not yet been peer reviewed. The paper does not explicitly discuss endometriosis or adenomyosis; it was included in the corpus via a keyword match in the upstream search index.

Read from the paper's body, not the abstract. Not a substitute for reading the paper. No clinical advice. How this works

Abstract

Abstract As industrial control systems become increasingly connected, the threat of cyberattacks grows accordingly. Classical IT reactions that prioritize confidentiality, such as device shutdown or network isolation, cannot be directly applied as they compromise availability, which is critical to keep the system safe. This paper explores the concept of self-reconfiguration in Industrial Control Systems (ICS) as a proactive and reactive defense mechanism against cyberattacks. Recognizing the critical importance of availability in OT environments, we propose a system that, upon detection of a compromised component, dynamically reconfigures itself to maintain functionality. Our approach leverages the increasing virtualization of ICS to migrate tasks from compromised devices to healthy ones, ensuring continued operation while containing the attack. We model the reconfiguration problem using the IEC 62443 standard, representing ICS as a network of zones linked by conduits. We present a system model incorporating security levels, device capacities, application dependencies, and communication constraints. Then, we formulate the task migration as an optimization problem solved via constraint programming. We detail several variations of the base reconfiguration program, including the activation of countermeasures or conduits, and the preemptive allocations of applications instances to host devices with memory size constraints. Our approach is evaluated through a combination of a physical training factory use case and generated problem instances with arbitrary sizes. This evaluation concerns the execution time of the reconfiguration process, as well as the resilience, measured in number of devices attacked before a critical application must be stopped.
Full text 14,212 characters · extracted from preprint-html · click to expand
Self-reconfiguration of industrial control systems as a response to cyberattacks | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Self-reconfiguration of industrial control systems as a response to cyberattacks Jolahn VAUDEY, Stéphane MOCANU, Eric RUTTEN, Gwenaël DELAVAL This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6343996/v1 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 30 Sep, 2025 Read the published version in Journal of Network and Systems Management → Version 1 posted 10 You are reading this latest preprint version Abstract As industrial control systems become increasingly connected, the threat of cyberattacks grows accordingly. Classical IT reactions that prioritize confidentiality, such as device shutdown or network isolation, cannot be directly applied as they compromise availability, which is critical to keep the system safe. This paper explores the concept of self-reconfiguration in Industrial Control Systems (ICS) as a proactive and reactive defense mechanism against cyberattacks. Recognizing the critical importance of availability in OT environments, we propose a system that, upon detection of a compromised component, dynamically reconfigures itself to maintain functionality. Our approach leverages the increasing virtualization of ICS to migrate tasks from compromised devices to healthy ones, ensuring continued operation while containing the attack. We model the reconfiguration problem using the IEC 62443 standard, representing ICS as a network of zones linked by conduits. We present a system model incorporating security levels, device capacities, application dependencies, and communication constraints. Then, we formulate the task migration as an optimization problem solved via constraint programming. We detail several variations of the base reconfiguration program, including the activation of countermeasures or conduits, and the preemptive allocations of applications instances to host devices with memory size constraints. Our approach is evaluated through a combination of a physical training factory use case and generated problem instances with arbitrary sizes. This evaluation concerns the execution time of the reconfiguration process, as well as the resilience, measured in number of devices attacked before a critical application must be stopped. Reconfiguration Resilience Industrial control systems Constraint Programming IEC 62443 Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Published Journal Publication published 30 Sep, 2025 Read the published version in Journal of Network and Systems Management → Version 1 posted Editorial decision: Revision requested 05 Jun, 2025 Reviews received at journal 05 Jun, 2025 Reviewers agreed at journal 27 May, 2025 Reviews received at journal 11 Apr, 2025 Reviewers agreed at journal 03 Apr, 2025 Reviewers agreed at journal 02 Apr, 2025 Reviewers invited by journal 01 Apr, 2025 Editor assigned by journal 01 Apr, 2025 Submission checks completed at journal 31 Mar, 2025 First submitted to journal 31 Mar, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6343996","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":441684402,"identity":"a3768010-1e28-4ab6-9a09-9e780d88b2cb","order_by":0,"name":"Jolahn VAUDEY","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA90lEQVRIiWNgGAWjYBACxgbmBmYo24CBoUKCgQHErcCrhRFZyxmoljOE7IFrYWyDMvFpYW5vbPxcuIMhsX9G8sbHvPMs8szbmR8wHNyDx46eg83SM88wJM64kVZszLtNoljmMJsBw4FneLTMSGyQ5m1jMGa4kWMmDdSSOIOZwYD5wwG8Wpp/g7TI38gx/807B6SF/QPDAfxa2kC2yBkAbWHmbQBp4THAr6XnYJs1b5uEnOGZZ8WSc46BtRQcwKfFsL358G3eNhseuePJGz+8qalLnMF/fOMDvFoawJQEmGTigYri0cDAII/iyh/4lI6CUTAKRsGIBQDWsVCRz/r43gAAAABJRU5ErkJggg==","orcid":"","institution":"Grenoble Computer Science Laboratory","correspondingAuthor":true,"prefix":"","firstName":"Jolahn","middleName":"","lastName":"VAUDEY","suffix":""},{"id":441684403,"identity":"822d6bcb-4bec-4992-8dc0-20f0dd217082","order_by":1,"name":"Stéphane MOCANU","email":"","orcid":"","institution":"Grenoble Institute of Technology","correspondingAuthor":false,"prefix":"","firstName":"Stéphane","middleName":"","lastName":"MOCANU","suffix":""},{"id":441684405,"identity":"829acf9a-8c43-429e-a72a-087b403251e5","order_by":2,"name":"Eric RUTTEN","email":"","orcid":"","institution":"Inria Grenoble - Rhône-Alpes research centre","correspondingAuthor":false,"prefix":"","firstName":"Eric","middleName":"","lastName":"RUTTEN","suffix":""},{"id":441684406,"identity":"4fe6b0cc-fdf9-42fd-ad46-e9c61acc6ff8","order_by":3,"name":"Gwenaël DELAVAL","email":"","orcid":"","institution":"Grenoble Alpes University","correspondingAuthor":false,"prefix":"","firstName":"Gwenaël","middleName":"","lastName":"DELAVAL","suffix":""}],"badges":[],"createdAt":"2025-03-31 10:38:17","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6343996/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6343996/v1","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.1007/s10922-025-09979-0","type":"published","date":"2025-09-30T15:57:09+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":92883880,"identity":"93712082-85f7-4bdd-8453-f2fee54405a7","added_by":"auto","created_at":"2025-10-06 16:10:21","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1928439,"visible":true,"origin":"","legend":"","description":"","filename":"JNSMCopie.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6343996/v1_covered_85007269-7915-4566-8351-ccc15a9c0f0a.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Self-reconfiguration of industrial control systems as a response to cyberattacks","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"[email protected]","identity":"journal-of-network-and-systems-management","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jons","sideBox":"Learn more about [Journal of Network and Systems Management](http://link.springer.com/journal/10922)","snPcode":"10922","submissionUrl":"https://submission.nature.com/new-submission/10922/3","title":"Journal of Network and Systems Management","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Reconfiguration, Resilience, Industrial control systems, Constraint Programming, IEC 62443","lastPublishedDoi":"10.21203/rs.3.rs-6343996/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6343996/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"As industrial control systems become increasingly connected, the threat of cyberattacks grows accordingly. Classical IT reactions that prioritize confidentiality, such as device shutdown or network isolation, cannot be directly applied as they compromise availability, which is critical to keep the system safe. This paper explores the concept of self-reconfiguration in Industrial Control Systems (ICS) as a proactive and reactive defense mechanism against cyberattacks. Recognizing the critical importance of availability in OT environments, we propose a system that, upon detection of a compromised component, dynamically reconfigures itself to maintain functionality. Our approach leverages the increasing virtualization of ICS to migrate tasks from compromised devices to healthy ones, ensuring continued operation while containing the attack. We model the reconfiguration problem using the IEC 62443 standard, representing ICS as a network of zones linked by conduits. We present a system model incorporating security levels, device capacities, application dependencies, and communication constraints. Then, we formulate the task migration as an optimization problem solved via constraint programming. We detail several variations of the base reconfiguration program, including the activation of countermeasures or conduits, and the preemptive allocations of applications instances to host devices with memory size constraints. Our approach is evaluated through a combination of a physical training factory use case and generated problem instances with arbitrary sizes. This evaluation concerns the execution time of the reconfiguration process, as well as the resilience, measured in number of devices attacked before a critical application must be stopped.","manuscriptTitle":"Self-reconfiguration of industrial control systems as a response to cyberattacks","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-04-21 18:28:50","doi":"10.21203/rs.3.rs-6343996/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-06-05T20:40:28+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-06-05T07:54:17+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"97816113235803373277979482288861117065","date":"2025-05-27T17:54:47+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-04-11T12:32:07+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"15781576067766065664311725289085932277","date":"2025-04-03T08:59:23+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"128048389040658346653555818990982239792","date":"2025-04-02T11:10:17+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2025-04-01T08:46:11+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2025-04-01T07:02:11+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-04-01T00:46:00+00:00","index":"","fulltext":""},{"type":"submitted","content":"Journal of Network and Systems Management","date":"2025-03-31T10:31:27+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"[email protected]","identity":"journal-of-network-and-systems-management","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jons","sideBox":"Learn more about [Journal of Network and Systems Management](http://link.springer.com/journal/10922)","snPcode":"10922","submissionUrl":"https://submission.nature.com/new-submission/10922/3","title":"Journal of Network and Systems Management","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"7325a3c1-f2e0-4e43-9606-575eaab8d3cf","owner":[],"postedDate":"April 21st, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"published-in-journal","subjectAreas":[],"tags":[],"updatedAt":"2025-10-06T16:04:40+00:00","versionOfRecord":{"articleIdentity":"rs-6343996","link":"https://doi.org/10.1007/s10922-025-09979-0","journal":{"identity":"journal-of-network-and-systems-management","isVorOnly":false,"title":"Journal of Network and Systems Management"},"publishedOn":"2025-09-30 15:57:09","publishedOnDateReadable":"September 30th, 2025"},"versionCreatedAt":"2025-04-21 18:28:50","video":"","vorDoi":"10.1007/s10922-025-09979-0","vorDoiUrl":"https://doi.org/10.1007/s10922-025-09979-0","workflowStages":[]},"version":"v1","identity":"rs-6343996","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6343996","identity":"rs-6343996","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}

Text is read by the "Ask this paper" AI Q&A widget below. Extraction quality varies by source — PMC NXML preserves structure cleanly, OA-HTML may include some navigation residue, and OA-PDF can have broken hyphenation. The publisher copy (via DOI) is the canonical version.

My notes (saved in your browser only)

Ask this paper AI returns verbatim quotes from the full text · source: preprint-html

Answers must be backed by verbatim quotes from this paper's full text. Hallucinated quotes are dropped automatically; if no verbatim passage answers the question, we say so. How this works

Citation neighborhood (no data yet)

We don't have any in-corpus citations linked to this paper yet. This is a recent paper (2025) — citers typically take a year or two to land, and the OpenAlex reference graph may still be filling in.

Source provenance

europepmc
last seen: 2026-05-20T01:45:00.602351+00:00