Data flow and asset classification

Purdue reference model

Level 4
Enterprise
SIEM / SOC platformAlert correlation and response
—
Enterprise
DVWAVulnerable web app
.192
Enterprise
OWASP ShepherdVulnerable web app
.184
Enterprise
Metasploitable3Vulnerable VM
.194
Enterprise
Corporate business systems, ERP, SOC — no direct OT access
FIREWALL
Level 3.5
IDMZ
Security gatewayLog forwarder
—
IDMZ
SIEM collectorEvent normalization
—
IDMZ
Secure buffer between IT and OT — log forwarding, event normalization, no direct control
FIREWALL
Telemetry alerts
Level 3
Operations
Passive OT sensorSecurity Onion / Zeek
.180
OT-DMZ
HistorianData archive
.190
OT-DMZ
Application serverNode-RED / MQTT broker
.152
OT-DMZ
Site-wide operations — passive monitoring, historians, application servers
FIREWALL
Operational OT data
Level 2
Supervisory
HMIWindows 7 — operator interface
.193
OT
SCADAWindows 10 — process control
.195
OT
Engineering WSConfiguration and programming
—
OT
Operator workstations — real-time monitoring, SCADA displays, control commands
OT protocol traffic
Level 1
Control
PLCProgrammable logic controller
—
OT
Gateway routerNetwork edge device
.1
OT
RTURemote terminal unit
—
OT
Local controllers — execute control logic, read sensors, drive actuators
Fieldbus / IO signals
Level 0
Process
IoT sensorTemperature / weather
.79 .133
OT-Field
IoT sensorLight / motion
.169
OT-Field
IoT sensorSmart device
.49
OT-Field
Smart TV / phonesSamsung TV, iPhones
DHCP
OT-Field
Physical field devices — sensors, actuators, IoT endpoints generating raw process data
▲ OT process data
▲ Log / telemetry
▲ Alerts
OT / OT-Field
OT-DMZ
IDMZ
Enterprise