Self-reconfiguration of industrial control systems as a response to cyberattacks | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Self-reconfiguration of industrial control systems as a response to cyberattacks Jolahn VAUDEY, Stéphane MOCANU, Eric RUTTEN, Gwenaël DELAVAL This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-6343996/v1 This work is licensed under a CC BY 4.0 License Status: Published Journal Publication published 30 Sep, 2025 Read the published version in Journal of Network and Systems Management → Version 1 posted 10 You are reading this latest preprint version Abstract As industrial control systems become increasingly connected, the threat of cyberattacks grows accordingly. Classical IT reactions that prioritize confidentiality, such as device shutdown or network isolation, cannot be directly applied as they compromise availability, which is critical to keep the system safe. This paper explores the concept of self-reconfiguration in Industrial Control Systems (ICS) as a proactive and reactive defense mechanism against cyberattacks. Recognizing the critical importance of availability in OT environments, we propose a system that, upon detection of a compromised component, dynamically reconfigures itself to maintain functionality. Our approach leverages the increasing virtualization of ICS to migrate tasks from compromised devices to healthy ones, ensuring continued operation while containing the attack. We model the reconfiguration problem using the IEC 62443 standard, representing ICS as a network of zones linked by conduits. We present a system model incorporating security levels, device capacities, application dependencies, and communication constraints. Then, we formulate the task migration as an optimization problem solved via constraint programming. We detail several variations of the base reconfiguration program, including the activation of countermeasures or conduits, and the preemptive allocations of applications instances to host devices with memory size constraints. Our approach is evaluated through a combination of a physical training factory use case and generated problem instances with arbitrary sizes. This evaluation concerns the execution time of the reconfiguration process, as well as the resilience, measured in number of devices attacked before a critical application must be stopped. Reconfiguration Resilience Industrial control systems Constraint Programming IEC 62443 Full Text Additional Declarations No competing interests reported. Cite Share Download PDF Status: Published Journal Publication published 30 Sep, 2025 Read the published version in Journal of Network and Systems Management → Version 1 posted Editorial decision: Revision requested 05 Jun, 2025 Reviews received at journal 05 Jun, 2025 Reviewers agreed at journal 27 May, 2025 Reviews received at journal 11 Apr, 2025 Reviewers agreed at journal 03 Apr, 2025 Reviewers agreed at journal 02 Apr, 2025 Reviewers invited by journal 01 Apr, 2025 Editor assigned by journal 01 Apr, 2025 Submission checks completed at journal 31 Mar, 2025 First submitted to journal 31 Mar, 2025 You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-6343996","acceptedTermsAndConditions":true,"allowDirectSubmit":false,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":441684402,"identity":"a3768010-1e28-4ab6-9a09-9e780d88b2cb","order_by":0,"name":"Jolahn VAUDEY","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA90lEQVRIiWNgGAWjYBACxgbmBmYo24CBoUKCgQHErcCrhRFZyxmoljOE7IFrYWyDMvFpYW5vbPxcuIMhsX9G8sbHvPMs8szbmR8wHNyDx46eg83SM88wJM64kVZszLtNoljmMJsBw4FneLTMSGyQ5m1jMGa4kWMmDdSSOIOZwYD5wwG8Wpp/g7TI38gx/807B6SF/QPDAfxa2kC2yBkAbWHmbQBp4THAr6XnYJs1b5uEnOGZZ8WSc46BtRQcwKfFsL358G3eNhseuePJGz+8qalLnMF/fOMDvFoawJQEmGTigYri0cDAII/iyh/4lI6CUTAKRsGIBQDWsVCRz/r43gAAAABJRU5ErkJggg==","orcid":"","institution":"Grenoble Computer Science Laboratory","correspondingAuthor":true,"prefix":"","firstName":"Jolahn","middleName":"","lastName":"VAUDEY","suffix":""},{"id":441684403,"identity":"822d6bcb-4bec-4992-8dc0-20f0dd217082","order_by":1,"name":"Stéphane MOCANU","email":"","orcid":"","institution":"Grenoble Institute of Technology","correspondingAuthor":false,"prefix":"","firstName":"Stéphane","middleName":"","lastName":"MOCANU","suffix":""},{"id":441684405,"identity":"829acf9a-8c43-429e-a72a-087b403251e5","order_by":2,"name":"Eric RUTTEN","email":"","orcid":"","institution":"Inria Grenoble - Rhône-Alpes research centre","correspondingAuthor":false,"prefix":"","firstName":"Eric","middleName":"","lastName":"RUTTEN","suffix":""},{"id":441684406,"identity":"4fe6b0cc-fdf9-42fd-ad46-e9c61acc6ff8","order_by":3,"name":"Gwenaël DELAVAL","email":"","orcid":"","institution":"Grenoble Alpes University","correspondingAuthor":false,"prefix":"","firstName":"Gwenaël","middleName":"","lastName":"DELAVAL","suffix":""}],"badges":[],"createdAt":"2025-03-31 10:38:17","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-6343996/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-6343996/v1","draftVersion":[],"editorialEvents":[{"content":"https://doi.org/10.1007/s10922-025-09979-0","type":"published","date":"2025-09-30T15:57:09+00:00"}],"editorialNote":"","failedWorkflow":false,"files":[{"id":92883880,"identity":"93712082-85f7-4bdd-8453-f2fee54405a7","added_by":"auto","created_at":"2025-10-06 16:10:21","extension":"pdf","order_by":1,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1928439,"visible":true,"origin":"","legend":"","description":"","filename":"JNSMCopie.pdf","url":"https://assets-eu.researchsquare.com/files/rs-6343996/v1_covered_85007269-7915-4566-8351-ccc15a9c0f0a.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Self-reconfiguration of industrial control systems as a response to cyberattacks","fulltext":[],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":false,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":false,"highlight":"","institution":"","isAcceptedByJournal":true,"isAuthorSuppliedPdf":true,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":true,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"journal-of-network-and-systems-management","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jons","sideBox":"Learn more about [Journal of Network and Systems Management](http://link.springer.com/journal/10922)","snPcode":"10922","submissionUrl":"https://submission.nature.com/new-submission/10922/3","title":"Journal of Network and Systems Management","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false},"keywords":"Reconfiguration, Resilience, Industrial control systems, Constraint Programming, IEC 62443","lastPublishedDoi":"10.21203/rs.3.rs-6343996/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-6343996/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"As industrial control systems become increasingly connected, the threat of cyberattacks grows accordingly. Classical IT reactions that prioritize confidentiality, such as device shutdown or network isolation, cannot be directly applied as they compromise availability, which is critical to keep the system safe. This paper explores the concept of self-reconfiguration in Industrial Control Systems (ICS) as a proactive and reactive defense mechanism against cyberattacks. Recognizing the critical importance of availability in OT environments, we propose a system that, upon detection of a compromised component, dynamically reconfigures itself to maintain functionality. Our approach leverages the increasing virtualization of ICS to migrate tasks from compromised devices to healthy ones, ensuring continued operation while containing the attack. We model the reconfiguration problem using the IEC 62443 standard, representing ICS as a network of zones linked by conduits. We present a system model incorporating security levels, device capacities, application dependencies, and communication constraints. Then, we formulate the task migration as an optimization problem solved via constraint programming. We detail several variations of the base reconfiguration program, including the activation of countermeasures or conduits, and the preemptive allocations of applications instances to host devices with memory size constraints. Our approach is evaluated through a combination of a physical training factory use case and generated problem instances with arbitrary sizes. This evaluation concerns the execution time of the reconfiguration process, as well as the resilience, measured in number of devices attacked before a critical application must be stopped.","manuscriptTitle":"Self-reconfiguration of industrial control systems as a response to cyberattacks","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-04-21 18:28:50","doi":"10.21203/rs.3.rs-6343996/v1","editorialEvents":[{"type":"communityComments","content":0},{"type":"decision","content":"Revision requested","date":"2025-06-05T20:40:28+00:00","index":"","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-06-05T07:54:17+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"97816113235803373277979482288861117065","date":"2025-05-27T17:54:47+00:00","index":"hide","fulltext":""},{"type":"editorInvitedReview","content":"","date":"2025-04-11T12:32:07+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"15781576067766065664311725289085932277","date":"2025-04-03T08:59:23+00:00","index":"hide","fulltext":""},{"type":"reviewerAgreed","content":"128048389040658346653555818990982239792","date":"2025-04-02T11:10:17+00:00","index":"hide","fulltext":""},{"type":"reviewersInvited","content":"","date":"2025-04-01T08:46:11+00:00","index":"","fulltext":""},{"type":"editorAssigned","content":"","date":"2025-04-01T07:02:11+00:00","index":"","fulltext":""},{"type":"checksComplete","content":"","date":"2025-04-01T00:46:00+00:00","index":"","fulltext":""},{"type":"submitted","content":"Journal of Network and Systems Management","date":"2025-03-31T10:31:27+00:00","index":"","fulltext":""}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"journal-of-network-and-systems-management","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":false,"externalIdentity":"jons","sideBox":"Learn more about [Journal of Network and Systems Management](http://link.springer.com/journal/10922)","snPcode":"10922","submissionUrl":"https://submission.nature.com/new-submission/10922/3","title":"Journal of Network and Systems Management","twitterHandle":"","acdcEnabled":true,"dfaEnabled":true,"editorialSystem":"em","reportingPortfolio":"Springer Hybrid","inReviewEnabled":true,"inReviewRevisionsEnabled":false}}],"origin":"","ownerIdentity":"7325a3c1-f2e0-4e43-9606-575eaab8d3cf","owner":[],"postedDate":"April 21st, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"published-in-journal","subjectAreas":[],"tags":[],"updatedAt":"2025-10-06T16:04:40+00:00","versionOfRecord":{"articleIdentity":"rs-6343996","link":"https://doi.org/10.1007/s10922-025-09979-0","journal":{"identity":"journal-of-network-and-systems-management","isVorOnly":false,"title":"Journal of Network and Systems Management"},"publishedOn":"2025-09-30 15:57:09","publishedOnDateReadable":"September 30th, 2025"},"versionCreatedAt":"2025-04-21 18:28:50","video":"","vorDoi":"10.1007/s10922-025-09979-0","vorDoiUrl":"https://doi.org/10.1007/s10922-025-09979-0","workflowStages":[]},"version":"v1","identity":"rs-6343996","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-6343996","identity":"rs-6343996","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.