A Review of Digital Oil Field Cybersecurity with a Perspective on Cyberphysical Attack Mitigation with the Integration of Physically Unclonable Functions
Aug 2026· SPE Nigeria Annual International Conference and Exhibition· 0 citations· 39 references
TL;DR
The System-on-Chip (SoC) strategies exemplifying the use of Physically Unclonable functions (PUF) in the generation of data provenance attributes to boost the cyber-physical security infrastructures in digital oil fields are highlighted.
Abstract
Due to the proliferation of immersive adoption of automation systems and infrastructure in the operation, monitoring and optimizing oil production fields, ICT systems have become a significant tool in the realization of this paradigm shift. This sensing and automation systems bring about situational awareness of the field using technologies in the form of SCADA (Supervisory Control and Data Acquisition), DCS (Distributed Control System) or WAMS (Wide Area Monitoring System) infrastructure. These technologies are closely integrated with vessels, equipment, wells and process variables. Due to the criticality of data for efficient operations, they are susceptible to cyber-attack for malicious reasons by intruders. Therefore, it is essential for these networks and data therein to be protected from cyber-attacks to ensure reliable and robust sensing, transmission and utilization of data in the oil production field. This paper discusses digitization of oil fields, cyber vulnerabilities, real cyber-attack events and mitigation strategies, cyber threats associated with digital oil fields. It also highlights and focuses on the System-on-Chip (SoC) strategies exemplifying the use of Physically Unclonable functions (PUF) in the generation of data provenance attributes to boost the cyber-physical security infrastructures in digital oil fields. A proposed framework for the deployment of PUFs to be integrated into digital systems infrastructure in the oil field is presented with benefits and limitations discussed.
The maritime industry, the silent engine of global trade, is undergoing a profound digital transformation, often referred to as Shipping 4.0 (Mesa et al., 2024). This significant shift involves the widespread adoption of digital, interconnected operating environments known as Cyber-physical Systems. While this technological leap has brought about remarkable improvements in efficiency and competitiveness, it has also, ironically, exposed the sector to a new wave of complex cybersecurity threats. This critical review paper delves into the rapidly changing landscape of maritime cyber threats and, crucially, assesses their tangible economic impact on global maritime trade. Our investigation begins by mapping out the primary vulnerabilities found in both shipboard and port-side systems. We pay special attention to mission-critical technologies like the Electronic Chart Display and Information System (ECDIS), GNSS, and automated cargo-handling infrastructure. Key real-world incidents, such as the devastating NotPetya attack on A.P. Moller-Maersk, are analysed not only to illustrate the threat but also to provide an empirical basis for quantifying the full spectrum of costs. These costs include staggering direct financial losses, widespread trade disruption, significant reputational damage, and an inevitable rise in insurance premiums across the sector. Furthermore, the study critically reviews existing global policy and regulatory frameworks, specifically examining the effectiveness of instruments like the IMO Guidelines on Maritime Cyber Risk. This analysis highlights critical gaps in their practical implementation, particularly the persistent lack of economic incentives needed to encourage robust, industry-wide security investments. Ultimately, this paper concludes by offering strategic, economically sound recommendations designed to foster strong cyber-resilience, which is vital for protecting the integrity and efficiency of the critical maritime supply chain in this fast-evolving digital age.
M. Sultan· JOURNAL OF MARITIME LOGISTIC...· 0 citations
Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along with the deployment of Industry 4.0 technologies increases the attack surface of ICS environments, which in turn makes them more vulnerable to advanced cyber threats. Therefore, many researchers have shown interest in the field of cybersecurity of ICS. The topics of intrusion detection, anomaly detection, threat intelligence, attack simulation and resilience assessment of ICS have received much attention. Nevertheless, the development and testing of cybersecurity solutions for ICS remains to be challenging due to the lack of appropriate datasets and experimental environment. The main objective of this paper is to provide the roadmap of existing ICS cybersecurity datasets, testbeds and digital twins. This paper presents various taxonomies along with systematic analysis of architecture, characteristics, capabilities, pros and cons of these tools. The results of the analysis demonstrate the presence of persistent problems such as lack of standardized benchmarking datasets, lack of modern attack scenarios, insufficient number of datasets based on real operational traffic and difficulty in validating artificial intelligence-driven cybersecurity solutions. In addition to summarizing current research on ICS cybersecurity datasets and testbeds, this roadmap provides the identification of research gaps and recommendations on creation of new tools.
Ebtesam S. Alqahtani, Mohammad Hammoudeh· 0 citations
By Industry 4.0 has resulted in the prevalence of smart factories, in which there is a close relationship between computation, communication, and physical processes through cyber-physical systems (CPS). Even though productivity, flexibility, and efficiency are improved under this integration, new security challenges that have never been experienced previously and go beyond the traditional cybersecurity boundaries are created. Cyber-physical security (CPSec) is the provision of defensive of the cyber components, as well as physical processes against malicious attacks, failures, and system anomalies. The paper is a systematic and multifaceted review of the new trends in cyber-physical security of smart factories. It looks at the threat landscapes, attack vectors, architecture weaknesses, and intersection of the information technology (IT) and operational technology (OT) worlds. In addition, the article evaluates the innovative defense systems such as artificial intelligence-based intrusion detection systems, blockchain-based trust management systems, zero-trust-based architectures, and security validation using digital twins. An adaptable, resilient, and real-time threat response-focused layered security approach is suggested to smart manufacturing settings. Recent experimental data on the role of advanced CPSec strategies is presented based on the considerations of industrial case studies and simulations. Lastly, the paper identifies open research problems and future directions requirements in order to establish robust, scale up and smart cyber-physical security systems in next generation smart factories.
Hiroshi Tanaka, Yuki Nakamura· International Journal of Mod...· 0 citations
In recent years, the growing use of autonomous ships is transforming the way maritime operations are conducted. At the centre of this transformation are Remote Operations Centres (ROCs), which function as hubs for monitoring, decision-making, and control. Through advanced human–machine interfaces, real-time sensor data, satellite communications, and automated systems, ROCs oversee vessel navigation, safety, and operational compliance. While these technologies promise increased efficiency and reduced risks to seafarers, the high level of digital connectivity and centralised control also creates serious cybersecurity vulnerabilities. As critical elements of the autonomous shipping system, ROCs may therefore become attractive targets for cyber-attacks with potentially wide-ranging maritime, economic, and environmental consequences. Cyber attackers may exploit ROCs using various techniques, including GPS spoofing, communication jamming, malware infections, data breaches, and system hijacking. Such attacks can interfere with navigation, disrupt command systems, or allow unauthorised access to ship controls. In more serious cases, attackers may be able to seize effective control of an autonomous ship and hold it ‘hostage’, threatening to cause collisions, or even the sinking of the ship unless their demands are met. These scenarios raise important questions not only about maritime safety and security, but also about the ability of existing international legal frameworks to respond to cyber threats affecting maritime operations. This paper considers whether cyber-attacks targeting ROCs and autonomous ships can be addressed and punished under international law, with particular attention to the Convention for the Suppression of Unlawful Acts against the Safety of Maritime Navigation (SUA Convention). It examines whether the Convention’s offence-based framework is capable of covering cyber-enabled attacks that are carried out remotely and may originate far from the maritime domain. The analysis explores whether conduct such as remote interference with navigation systems, digital hijacking of vessel controls, or threats to destroy or endanger a ship can fall within existing SUA offences, even where no physical force is used and no attacker is present on board. The paper also highlights key legal challenges, including difficulties in attribution, jurisdiction, and the required connection between the offence and the ship under the SUA Convention. It argues that although the SUA Convention offers a more suitable legal basis than traditional piracy rules for addressing cyber threats to autonomous shipping, further interpretative development and regulatory clarification are needed. The paper concludes by emphasising the importance of international cooperation and legal adaptation to ensure effective accountability for cyber-attacks against ROCs in an increasingly digital maritime environment.
With the fast pace of digitalization of transport infrastructure, smart elements and technologies have been integrated into railway networks and smart port operations, improving the degree of automation, real-time monitoring, predictive maintenance, and efficient logistics management. While all these developments enhance the efficiency and reliability of operations, they create new cybersecurity challenges with the increasing interconnections between cyber and physical elements. Such cyber threats as malware, distributed denial-of-service (DDoS) attacks, GPS spoofing, insider attacks, false data injection, and sensor tampering can impact transportation operations, tamper with operational data, and pose a threat to public safety for critical infrastructures. This research introduces an intelligent cyber-physical security framework for integrated railway and smart port operations, which integrates artificial intelligence (AI), Internet of Things (IoT) technologies, edge computing, blockchain-based secure communication, modeling and simulation with a digital twin, and decision support functions to create an all-encompassing cybersecurity architecture for the integrated transportation systems. The proposed framework was able to continuously retrieve diverse operational data from the railway signaling systems, smart port automation equipment, industrial control systems, IoT sensors, surveillance systems, communication networks, and logistics databases for real-time security analysis. Intelligent threat detection and classification are achieved with the help of advanced AI algorithms, and blockchain technology offers secure authentication and trusted information sharing and tamper-resistant data management. Edge computing can minimize communication delays by analyzing security data near operational assets, while digital twin technology can be used for predictive security risk evaluation, cyberattack simulation, infrastructure monitoring, and assessing infrastructure resilience. The experimental evaluation of the performance shows the ability to detect intrusions with better accuracy, false alarm rate, throughput, response time, and AUC values than the traditional machine learning and deep learning models.
A. S. Anshad, Kunal G. Srinivas, Sahana S. Kumar et al.· International journal of com...· 0 citations