Predicting Attack Paths and Technology Evolution in Industrial Factory Networks
Yang Peng, Yu Ziyuan, Li Zhen, Zhong Zlyao, Ye Danlian, Tan Liang, She KunThe integration of IT and OT networks in smart factories has expanded the attack surface, necessitating proactive and precise defense strategies. This article presents a dual-layer prediction framework targeting two core challenges: (1) macro-level attack path identification across converged IT/OT networks, and (2) micro-level attack technique evolution prediction. First, a multi-source network security knowledge base is constructed to model the threat ontology, and device threat levels are quantified based on the Common Vulnerability Scoring System (CVSS). Macro attack paths are predicted using threat propagation algorithms. Second, micro-level attack techniques are predicted along the macro paths by integrating Firewall-Intrusion Detection System(FW-IDS) configurations and Adversarial Tactics, Techniques, and Common Knowledge(ATT&CK) techniques into an evolution path prediction algorithm. The dual-layer prediction results are visualized to enhance interpretability. They demonstrate improved accuracy in attack path and technique prediction as well as real-time threat perception. Simulation experiments show that this approach significantly enhances the security posture of factory networks. Compared to existing methods, the dual-layer architecture proposed in this paper reduces the Weighted Mean Residual Paths (WMRP) by over 30%. This metric is used to quantify the number of potential attack paths remaining during the repair process. This significant reduction demonstrates that our method can more effectively contain threats at an early stage and minimize the attack surface more efficiently.This enables earlier detection and response to complex threats, thereby strengthening the protection of critical systems and devices in industrial environments.Beyond the implemented prediction tasks, the ontology-based semantic integration and cross-layer prediction structure also provide a foundational pathway toward future (self-*)adaptive security in Industry 5.0 smart factories, where online knowledge evolution, closed-loop feedback, and adaptive response orchestration are required to cope with dynamic and uncertain industrial threat environments.