Resiliência Cibernética em Ambientes de TO: Uma Abordagem Baseada em Monitoramento Passivo em Conformidade com a IEC 62443

  • Carlos W. de Souza UNIFEI
  • Gabriel M. Rosa UNIFEI
  • Otávio S. M. Gomes UNIFEI

Resumo


A convergência entre TI e TO reduziu o isolamento físico das indústrias, expondo infraestruturas críticas a incidentes cibernéticos. Diferente da TI, a TO prioriza disponibilidade e segurança física de máquinas, equipamentos, meio ambiente e pessoas. Este artigo aborda vulnerabilidades em sistemas industriais e propõe uma estratégia de defesa em profundidade baseada em monitoramento passivo e DPI. Por meio de um experimento prático com o protocolo Modbus TCP, apresenta-se como alterações não autorizadas são detectadas e mapeadas para o framework MITRE ATT&CK for ICS. Os resultados indicam que o monitoramento passivo pode contribuir para objetivos de segurança relacionados à IEC 62443, especialmente à integridade dos sistemas, sem introduzir tráfego adicional no caminho operacional monitorado.

Referências

Barbosa, R. R. R. and Pras, A. (2010). Intrusion detection in industrial control systems.

Claroty (2026). Passive monitoring: Collection method overview.

Goldenberg, N. and Wool, A. (2013). Accurate modeling of modbus/tcp for intrusion detection in scada systems.

Huitsing, P., Chandia, R., Papa, M., and Shenoi, S. (2008). Attack taxonomies for the modbus protocols.

International Electrotechnical Commission (2013). Industrial communication networks – network and system security – part 3-3: System security requirements and security levels. Technical report, International Electrotechnical Commission, Geneva, Switzerland.

Knapp, E. D. and Langill, J. T. (2014). Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid, SCADA, and Other Industrial Control Systems. Syngress.

MITRE (2025a). Mitre att&ck for ics.

MITRE (2025b). Modify parameter (t0836) – mitre att&ck for ics.

National Institute of Standards and Technology (2023). Guide to operational technology (ot) security. Technical report, National Institute of Standards and Technology.

Williams, T. J. (1994). The purdue enterprise reference architecture. Computers in Industry, 24(2–3):141–158.
Publicado
01/09/2026
SOUZA, Carlos W. de; ROSA, Gabriel M.; GOMES, Otávio S. M.. Resiliência Cibernética em Ambientes de TO: Uma Abordagem Baseada em Monitoramento Passivo em Conformidade com a IEC 62443. In: TRILHA DE INTERAÇÃO COM A INDÚSTRIA E DE INOVAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 875-881. DOI: https://doi.org/10.5753/sbseg_estendido.2026.27099.