DOI: 10.3390/jsan15040062 ISSN: 2224-2708

Longitudinal Behavioural Analysis of Industrial IoT Network Traffic Using Passive Monitoring

Henrique Santos, Pedro Magalhães

Industrial Internet of Things (IIoT) production environments rely on automated communication between control systems and embedded devices while operating under strict availability constraints that limit the deployment of conventional IT security controls. Despite extensive research on intrusion detection systems, empirical studies based on long-term observations of real industrial networks remain scarce. This paper presents a longitudinal 92-day passive monitoring study of a production-line IIoT network comprising 22 monitored devices. A containerised instance of Zeek was deployed in promiscuous mode to collect flow-level and application-layer telemetry without interfering with operations. The resulting dataset contains more than 41.5 million network flows and 520.5 million packets, represented by 48.48 GB of structured Zeek logs. The results reveal highly deterministic communication patterns dominated by periodic HTTP polling between a central server and distributed devices. In particular, the hourly mean HTTP response size remained highly stable at 132.76 bytes, with a standard deviation of 1.37 bytes and a coefficient of variation of 1.0%. Although no confirmed malicious activity was observed, transient deviations were identified and attributed to planned production stoppages restart periods, which caused temporary traffic reductions and short-lived packet bursts. These findings demonstrate that production-line IIoT networks can exhibit predictable behaviour regimes suitable for statistical anomaly detection. The study contributes a longitudinal empirical characterisation of a real operational IIoT network, a reproducible methodology for behavioural baseline extraction using passive telemetry, and practical insights for safe monitoring deployment.

More from our Archive