Ilmu Komputer & AI editorial
Open AccessOA2026
Quantifying IIoT Sensor Node Criticality by Fusing its Data Criticality and Security Vulnerability
A Dempster-Shafer Framework for Ranking Industrial IoT Nodes Using Data Impact and CVSS v4.0
Sachin K. Sen; Gour C. Karmakar; Shaoning Pangยท 2026ยท DOI 10.48550/arXiv.2609.09807
The core problem
The integration of the Industrial Internet of Things (IIoT) into manufacturing has transformed industrial operations by optimising production management and ensuring product quality through smart industrial sensors that regulate processes based on real-time data. However, these sensor nodes are highly vulnerable to cyber threats, posing significant security risks that compromise their reliability and integrity. While existing research explores cybersecurity vulnerabilities and cyberattack-based methods for ranking critical nodes, some studies assess node criticality based on the impact of sensor data on product quality. However, a comprehensive approach that integrates both data criticality and cybersecurity vulnerability remains unexplored. To bridge this gap, this study introduces a novel framework that evaluates IIoT sensor node criticality by leveraging Dempster--Shafer (D-S) theory to fuse data criticality and cybersecurity vulnerabilities. The proposed method is validated using a dataset from red wine production, demonstrating its effectiveness in ranking sensor nodes based on both factors. The results show that criticality rankings based on security vulnerability scores comp
Innovation
The proposed method was applied to the red wine production dataset. Sensor nodes were ranked based on their fused criticality scores. The results indicate that the criticality rankings obtained using CVSS v4.0 differ significantly from those using CVSS v3.1. This discrepancy highlights the influence of enhanced vulnerability assessment methodologies on node criticality. For instance, nodes that were considered moderately critical under CVSS v3.1 may be ranked higher under CVSS v4.0 due to more granular and severe vulnerability scoring. The fusion approach effectively integrates data criticality and security vulnerability, providing a more comprehensive ranking than either factor alone. The validation demonstrates the effectiveness of the framework in ranking sensor nodes based on both factors.
The integration of the Industrial Internet of Things (IIoT) into manufacturing has transformed industrial operations by optimising production management and ensuring product quality through smart industrial sensors that regulate processes based on real-time data. However, these sensor nodes are highly vulnerable to cyber threats, posing significant security risks that compromise their reliability and integrity. While existing research explores cybersecurity vulnerabilities and cyberattack-based methods for ranking critical nodes, some studies assess node criticality based on the impact of sensor data on product quality. However, a comprehensive approach that integrates both data criticality and cybersecurity vulnerability remains unexplored. To bridge this gap, this study introduces a novel framework that evaluates IIoT sensor node criticality by leveraging Dempster--Shafer (D-S) theory to fuse data criticality and cybersecurity vulnerabilities. The proposed method is validated using a dataset from red wine production, demonstrating its effectiveness in ranking sensor nodes based on both factors. The results show that criticality rankings based on security vulnerability scores computed using CVSS version 4.0 differ significantly from those obtained with CVSS version 3.1, highlighting the influence of enhanced vulnerability assessment methodologies. While initially applied to wine manufacturing, this framework is adaptable to broader industrial applications with minimal modifications, offering a robust approach to securing IIoT-enabled production systems.
The proposed framework fuses two distinct sources of evidence: data criticality and security vulnerability. Data criticality quantifies the impact of a sensor node's data on product quality, while security vulnerability assesses the node's exposure to cyber threats. Dempster-Shafer (D-S) theory, a mathematical framework for reasoning with uncertainty, is employed to combine these heterogeneous metrics into a unified criticality score.
Why it matters
The significant difference in rankings between CVSS v3.1 and v4.0 underscores the importance of using up-to-date vulnerability assessment methods. CVSS v4.0 introduces improvements such as more precise metrics for attack requirements, user interaction, and impact, leading to different vulnerability scores. Consequently, the fused criticality rankings shift, which can affect security prioritization and resource allocation. The Dempster-Shafer fusion approach is advantageous because it can handle uncertainty and conflicting evidence, which is common when combining data criticality and security vulnerability. The framework is adaptable to broader industrial applications with minimal modifications, as the underlying principles of data criticality and vulnerability assessment are generalizable. However, the study has limitations: it is validated on a single dataset from wine production, and the data criticality assessment may vary across different manufacturing processes. Future work could extend the framework to other domains and incorporate real-time data. Overall, the study offers a robust approach to securing IIoT-enabled production systems by providing a holistic view of node criticality.
Who should read this
CS practitioners and researchers
Opening member contentโฆ