SwiftAutomate is a complete, hands-on lab environment for monitoring and simulating Industrial Control System (ICS) processes. It provides a low-cost, accessible test bed for practicing OT (Operational Technology) security, data visualization, and alert response.
The project bridges the gap between physical hardware (a sensor-equipped Arduino) and a modern, IT-grade monitoring stack (Prometheus, Grafana, Loki), all managed via a custom web-based "SOC Panel."
This project creates a small-scale, simulated industrial environment and the tools to monitor it.
It's built from three main parts:
-
Physical Process Simulator (Arduino): The Arduino (
iso_dashboard.ino) uses ultrasonic sensors to measure physical distances, simulating industrial process values (like tank levels or proximity). -
Data & Command Bridge (Python/Flask): A web server (
stat_1.py) reads data from the Arduino and serves a web-based "ICS SOC Panel" for live viewing. It also provides a JSON API for log/metric collection and a command-line interface to send commands back to the Arduino. -
Monitoring & Alerting Stack (Docker): A complete
docker-compose.ymlstack provides a professional monitoring solution:-
Prometheus: Scrapes and stores metrics.
-
Loki: Aggregates logs from all services.
-
Promtail: Ships logs from "SCADA" applications or the Python bridge to Loki.
-
Grafana: For visualizing all metrics and logs in dashboards.
-
Alertmanager: To fire and route alerts based on industrial rules (e.g., "High Motor Temperature").
-
The primary goal is to create an affordable and effective test bed for ICS/OT security and monitoring.
Traditional IT security tools often don't translate directly to OT environments. This project allows you to:
-
Practice Monitoring: Learn how to collect and visualize data from a physical process using standard tools like Prometheus and Grafana.
-
Develop Industrial Alerts: Write and test rules for industrial scenarios (e.g., HighMotorTemperature, LowTankPressure) using real, physical data.
-
Simulate Attacks: The project is designed to simulate a common attack: sensor data spoofing. A user can send a command (e.g., attack S1 5.0) to the Python server, which tells the Arduino to ignore its real sensor and report a fake value.
-
Improve Detection: By simulating attacks, you can practice detecting anomalies. For example, how does a "normal" dashboard look versus one where a sensor's value is being faked? This helps in developing better dashboards and alerts for attack detection.
-
Bridge OT & IT: It provides a safe sandbox to understand the interaction between physical process-layer devices (OT) and the enterprise monitoring systems (IT).
-
The "Plant": Physical Simulator (Arduino)
-
The
iso_dashboard.inosketch runs on an Arduino. -
It uses three ultrasonic sensors (S1, S2, S3) to measure distances in real-time.
-
It continuously prints this data to the Serial port in a CSV format (e.g.,
S1:12.34,S2:56.78,S3:9.01). -
Crucially, it also listens for commands on the Serial port. If it receives an "attack" command, it will override the real sensor value with the fake one provided in the command.
-
-
The Bridge: ICS SOC Panel (Python Flask)
-
The
stat_1.pyscript runs a Flask web server. -
It opens a connection to the Arduino's
SERIAL_PORT. -
Data Ingestion: It continuously reads the CSV data from the Arduino, parses it, and stores it in a global variable.
-
Web Dashboard (
/): It serves an HTML dashboard that fetches data from the/dataendpoint every 5 seconds to provide a real-time view of the sensors. -
API Endpoints:
-
GET /data: Returns the latest sensor data as JSON. -
GET /logs: Returns the data as a JSON log line, designed to be scraped by Promtail/Loki. -
POST /send_command: This is the attack vector. The web dashboard's CLI uses this endpoint. It takes a JSON command (e.g.,{"command": "attack S1 5.0"}) and writes it to the Arduino's Serial port, triggering the data override.
-
-
-
The SOC: Monitoring Stack (Docker)
-
The
docker-compose.ymlfile launches the entire monitoring stack. -
Prometheus is configured to scrape targets, including a sample
modbus_plcjob, demonstrating how it would monitor a real industrial device. -
Promtail is configured to find logs in
/var/log/scada/*.log, simulating a SCADA application's log output. It can also be configured to scrape thehttp://<python_server_ip>:5000/logsendpoint from the Python script. -
Alertmanager is configured to receive alerts from Prometheus and route them to a
webhook_receiver. -
Grafana (running on port 3000) is the central point for visualization. You would manually configure it to use Prometheus and Loki as data sources to build dashboards showing sensor values, logs, and alerts.
-
A detailed guide for setting up the environment, including dependencies and specific steps, is available in INSTALL.md.
The general setup process is:
-
Hardware: Set up the Arduino with the ultrasonic sensors as defined in
iso_dashboard.ino. -
Arduino: Upload the
iso_dashboard.inosketch to your Arduino. -
Python Server:
-
Install Python dependencies (Flask, PySerial).
-
Update
SERIAL_PORTinstat_1.pyto match your Arduino's port.
-
Run the server: python3 stat_1.py.
-
Monitoring Stack:
-
Install Docker and Docker Compose.
-
From the project's main directory, run:
docker-compose up -d.
-
-
Configure & Explore:
-
Access the Python dashboard at
http://localhost:5000. -
Access Grafana at
http://localhost:3000. -
Access Prometheus at
http://localhost:9090. -
In Grafana, add Prometheus (
http://prometheus:9090) and Loki (http://loki:3100) as data sources. -
Try sending commands (e.g.,
attack S1 5.0orreset) from thehttp://localhost:5000dashboard and watch the values change.
-

