Research Article

A Decoy Placement Model for Engineering Workstations and Historian Systems in Manufacturing OT Networks

by  Daniel Ward
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 127
Published: July 2026
Authors: Daniel Ward
10.5120/ijca54a0f5aecad7
PDF

Daniel Ward . A Decoy Placement Model for Engineering Workstations and Historian Systems in Manufacturing OT Networks. International Journal of Computer Applications. 187, 127 (July 2026), 53-61. DOI=10.5120/ijca54a0f5aecad7

                        @article{ 10.5120/ijca54a0f5aecad7,
                        author  = { Daniel Ward },
                        title   = { A Decoy Placement Model for Engineering Workstations and Historian Systems in Manufacturing OT Networks },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 127 },
                        pages   = { 53-61 },
                        doi     = { 10.5120/ijca54a0f5aecad7 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Daniel Ward
                        %T A Decoy Placement Model for Engineering Workstations and Historian Systems in Manufacturing OT Networks%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 127
                        %P 53-61
                        %R 10.5120/ijca54a0f5aecad7
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

Engineering workstations and historian systems concentrate control-project artifacts, privileged maintenance paths, and process knowledge in manufacturing operational technology (OT) networks. This paper develops and evaluates a safety-constrained decoy placement model for those assets. The revised study combines design science with a reproducible computational experiment built on a 26-node, 54-edge directed manufacturing OT attack graph. Six attack scenarios were tested against a no-deception baseline and four equal-budget alternatives: demilitarized-zone-heavy, random, betweenness-centrality, and asset-proximal placement. Each strategy was evaluated with 10,000 Monte Carlo trials per scenario under a five-decoy budget, resulting in 360,000 nominal trials with an arbitrary fixed seed of 314159. The proposed distributed placement achieved weighted pre-impact detection of 0.639 (95% CI 0.636-0.643), compared with 0.587 for asset-proximal placement, 0.574 for centrality placement, 0.411 for random placement, 0.356 for DMZ-heavy placement, and 0.122 for the baseline. Critical-target reach declined to 0.361. The advantage remained under reduced-fidelity and attacker-policy sensitivity tests. The results support distributed, high-value placement across remote access, engineering, project-file, historian, and protocol-discovery paths. The experiment is synthetic and does not claim live-plant effectiveness, but it provides falsifiable, reproducible evidence for comparative placement decisions.

References
  • D. Ward, "Enhancing Security: A Comprehensive Study on Deception Technology Integration in Manufacturing and Critical Infrastructure," Ph.D. dissertation, University of the Cumberlands, Williamsburg, KY, USA, 2025. Available: https://www.proquest.com/openview/ebf38e1aa599115548a9f7486917e669/1
  • K. A. Stouffer, M. Pease, C. Y. Tang, T. Zimmerman, V. Y. Pillitteri, S. Lightman, A. Hahn, S. Saravia, A. Sherule, and M. Thompson, "Guide to Operational Technology (OT) Security," NIST Special Publication 800-82, Rev. 3, 2023. doi: 10.6028/NIST.SP.800-82r3.
  • National Institute of Standards and Technology, "The NIST Cybersecurity Framework (CSF) 2.0," NIST Cybersecurity White Paper 29, 2024. doi: 10.6028/NIST.CSWP.29.
  • International Electrotechnical Commission, "IEC 62443-2-1:2024, Security for Industrial Automation and Control Systems - Part 2-1: Security Program Requirements for IACS Asset Owners," 2024. Available: https://webstore.iec.ch/en/publication/62883
  • Cybersecurity and Infrastructure Security Agency, "Cross-Sector Cybersecurity Performance Goals, Version 2.0," 2025. Available: https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
  • MITRE, "ATT&CK for ICS Matrix," ATT&CK, 2026. Available: https://attack.mitre.org/matrices/ics/
  • J. Franco, A. Aris, B. Canberk, and A. S. Uluagac, "A Survey of Honeypots and Honeynets for Internet of Things, Industrial Internet of Things, and Cyber-Physical Systems," IEEE Communications Surveys & Tutorials, vol. 23, no. 4, pp. 2351-2383, 2021. doi: 10.1109/COMST.2021.3106669.
  • S. Maesschalck, V. Giotsas, B. Green, and N. Race, "Don't Get Stung, Cover Your ICS in Honey: How Do Honeypots Fit within Industrial Control System Security," Computers & Security, vol. 114, art. 102598, 2022. doi: 10.1016/j.cose.2021.102598.
  • E. Lopez-Morales, C. Rubio-Medrano, A. Doupe, Y. Shoshitaishvili, R. Wang, T. Bao, and G. J. Ahn, "HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems," in Proc. ACM SIGSAC Conf. Computer and Communications Security, 2020, pp. 279-291. doi: 10.1145/3372297.3423356.
  • M. Lucchese, F. Lupia, M. Merro, F. Paci, N. Zannone, and A. Furfaro, "HoneyICS: A High-Interaction Physics-Aware Honeynet for Industrial Control Systems," in Proc. 18th Int. Conf. Availability, Reliability and Security, 2023, art. 113. doi: 10.1145/3600160.3604984.
  • L. Salazar, E. Lopez-Morales, J. Lozano, C. Rubio-Medrano, and A. A. Cardenas, "ICSNet: A Hybrid-Interaction Honeynet for Industrial Control Systems," in Proc. Sixth Workshop on CPS&IoT Security and Privacy, 2024, pp. 68-79. doi: 10.1145/3690134.3694813.
  • A. Javadpour, F. Ja'fari, T. Taleb, M. Shojafar, and C. Benzaid, "A Comprehensive Survey on Cyber Deception Techniques to Improve Honeypot Performance," Computers & Security, vol. 140, art. 103792, 2024. doi: 10.1016/j.cose.2024.103792.
  • D. Ward, "Operationalizing Deception Technology in ICS/OT: A Control Mapping Framework for Critical Infrastructure Cybersecurity," International Journal of Soft Computing and Engineering, vol. 16, no. 3, pp. 1-9, 2026. doi: 10.35940/ijsce.C3723.16030726.
  • D. Ward, "Decoy-Assisted Detection Metrics for Manufacturing Operational Technology Networks," International Journal of Scientific and Research Publications, vol. 16, no. 6, pp. 330-333, 2026. doi: 10.29322/IJSRP.16.06.2026.p17419.
  • C. R. Harris et al., "Array Programming with NumPy," Nature, vol. 585, pp. 357-362, 2020. doi: 10.1038/s41586-020-2649-2.
  • A. A. Hagberg, D. A. Schult, and P. J. Swart, "Exploring Network Structure, Dynamics, and Function Using NetworkX," in Proc. 7th Python in Science Conf., 2008, pp. 11-15. Available: https://networkx.org/
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

Cyber deception decoy placement engineering workstations historian systems industrial control systems operational technology Monte Carlo evaluation

Powered by PhDFocusTM