This project will explore how digital forensic analysis can be carried out on components within an industrial computer network, including both modern equipment and legacy devices that may lack up-to-date security features. Industrial networks are used in areas such as manufacturing and energy, and typically include devices like PLCs, HMIs, robot controllers, industrial switches, and older controllers. The student will investigate what types of forensic evidence these devices can produce and how this evidence can be collected and examined. The project will also look at the additional challenges and vulnerabilities with legacy systems.
The project may involve:
Capturing and analysing network traffic from modern and legacy industrial devices Identifying what forensic artefacts are available from different types of industrial equipment Exploring how industrial communication protocols affect evidence collection Testing and comparing basic forensic or network-analysis tools Building a small, simulated environment to demonstrate a simple forensic investigation
The final output will include a clear explanation of the forensic techniques used, the differences between modern and legacy devices, and practical recommendations for improving forensic readiness in industrial networks.