📖 ABSTRACT/OVERVIEW
Embedded systems controlling industrial automation in Nigerian oil and gas, food processing, and chemical manufacturing plants in the South South and North Central zones are frequently deployed without security hardening, exposing critical infrastructure to cyber-physical attacks. This study conducted a professional vulnerability assessment of embedded control systems at three industrial automation facilities in Delta, Bayelsa, and Niger States. A structured penetration testing methodology aligned with IEC 62443-3-3 was applied with written authorisation from facility operators. Assessment activities included firmware extraction and analysis, communication protocol analysis (Modbus, DNP3, and proprietary protocols), default credential testing, physical port security review, and network segmentation assessment. Results across the three facilities identified an average of 22.6 security findings per facility, classified as 4.3 critical, 8.7 high, and 9.6 medium severity per facility. Critical findings included unencrypted engineering workstation-to-PLC communications at all facilities, default vendor passwords on 38 percent of PLC units, and direct internet-facing connections to SCADA servers without firewall protection at one facility. Firmware analysis revealed outdated third-party libraries with publicly known CVEs in two facilities. A remediation roadmap with prioritised corrective actions, estimated implementation costs, and risk-reduction impact scores was developed for each facility. The study recommends the Department of Petroleum Resources mandate ICS security assessments for all licensed oil and gas facilities and develop a Nigeria-specific ICS security assurance framework aligned to IEC 62443.
Keywords: embedded systems security, industrial automation, ICS vulnerability assessment, OT cybersecurity, Nigeria
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬