{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T15:22:34Z","timestamp":1778167354629,"version":"3.51.4"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2019,10,24]],"date-time":"2019-10-24T00:00:00Z","timestamp":1571875200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2019,10,24]],"date-time":"2019-10-24T00:00:00Z","timestamp":1571875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2020,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n<jats:p>Disruptive innovations of the last few decades, such as smart cities and Industry 4.0, were made possible by higher integration of physical and digital elements. In today\u2019s pervasive cyber-physical systems, connecting more devices introduces new vulnerabilities and security threats. With increasing cybersecurity incidents, cybersecurity professionals are becoming incapable of addressing what has become the greatest threat climate than ever before. This research investigates the spectrum of risk of a cybersecurity incident taking place in the cyber-physical-enabled world using the VERIS Community Database. The findings were that the majority of known actors were from the US and Russia, most victims were from western states and geographic origin tended to reflect global affairs. The most commonly targeted asset was information, with the majority of attack modes relying on privilege abuse. The key feature observed was extensive internal security breaches, most often a result of human error. This tends to show that access in any form appears to be the source of vulnerability rather than incident specifics due to a fundamental trade-off between usability and security in the design of computer systems. This provides fundamental evidence of the need for a major reevaluation of the founding principles in cybersecurity.<\/jats:p>","DOI":"10.1007\/s11227-019-03028-9","type":"journal-article","created":{"date-parts":[[2019,12,16]],"date-time":"2019-12-16T16:26:04Z","timestamp":1576513564000},"page":"2643-2664","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":73,"title":["Threats on the horizon: understanding security threats in the era of cyber-physical systems"],"prefix":"10.1007","volume":"76","author":[{"given":"Steven","family":"Walker-Roberts","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1058-0996","authenticated-orcid":false,"given":"Mohammad","family":"Hammoudeh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Omar","family":"Aldabbas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mehmet","family":"Aydin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Dehghantanha","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,10,24]]},"reference":[{"issue":"4","key":"3028_CR1","first-page":"17","volume":"2","author":"AO Adebayo","year":"2012","unstructured":"Adebayo AO (2012) A foundation for breach data analysis. J Inf Eng Appl 2(4):17\u201323","journal-title":"J Inf Eng Appl"},{"key":"3028_CR2","doi-asserted-by":"publisher","unstructured":"Ashfaq AB, Ali MQ, Al-Shaer E, Khayam SA (2013) POSTER: revisiting anomaly detection system design philosophy. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security, vol 13. ACM Press. \nhttps:\/\/doi.org\/10.1145\/2508859.2512529","DOI":"10.1145\/2508859.2512529"},{"key":"3028_CR3","doi-asserted-by":"publisher","unstructured":"Baker T, Asim M, MacDermott A, Iqbal F, Kamoun F, Shah B, Alfandi O, Hammoudeh M (2019) A secure fog-based platform for scada-based iot critical infrastructure. Softw Pract Exp. \n https:\/\/doi.org\/10.1002\/spe.2688","DOI":"10.1002\/spe.2688"},{"key":"3028_CR4","doi-asserted-by":"crossref","unstructured":"Barona R, Anita EM (2017) A survey on data breach challenges in cloud computing security: issues and threats. In: 2017 International Conference on Circuit, Power and Computing Technologies (ICCPCT). IEEE, pp 1\u20138","DOI":"10.1109\/ICCPCT.2017.8074287"},{"key":"3028_CR5","doi-asserted-by":"publisher","unstructured":"Belguith S, Kaaniche N, Hammoudeh M (2019) Analysis of attribute-based cryptographic techniques and their application to protect cloud services. Trans Emerg Telecommun Technol. \n https:\/\/doi.org\/10.1002\/ett.3667","DOI":"10.1002\/ett.3667"},{"key":"3028_CR6","doi-asserted-by":"publisher","unstructured":"B\u00f6hme R (2016) Back to the roots: information sharing economics and what we can learn for security. In: Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security, WISCS\u201916. ACM, New York, NY, USA, pp 1\u20132. \nhttps:\/\/doi.org\/10.1145\/2994539.2994540","DOI":"10.1145\/2994539.2994540"},{"key":"3028_CR7","doi-asserted-by":"publisher","unstructured":"Bray T (2014) The JavaScript Object Notation (JSON) Data Interchange Format. \nhttps:\/\/doi.org\/10.17487\/rfc7159\n\n. Accessed 28 Oct 2017","DOI":"10.17487\/rfc7159"},{"issue":"4","key":"3028_CR8","doi-asserted-by":"publisher","first-page":"204","DOI":"10.1016\/j.istr.2005.10.002","volume":"10","author":"S Broderick","year":"2005","unstructured":"Broderick S (2005) Firewalls\u2014are they enough protection for current networks? Inf Secur Tech Rep 10(4):204\u2013212. \nhttps:\/\/doi.org\/10.1016\/j.istr.2005.10.002","journal-title":"Inf Secur Tech Rep"},{"issue":"6","key":"3028_CR9","first-page":"1","volume":"6","author":"A Carlin","year":"2015","unstructured":"Carlin A, Hammoudeh M, Aldabbas O (2015) Intrusion detection and countermeasure of virtual cloud systems-state of the art and current challenges. Int J Adv Comput Sci Appl 6(6):1\u201315","journal-title":"Int J Adv Comput Sci Appl"},{"issue":"1","key":"3028_CR10","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1145\/2096149.2096160","volume":"42","author":"Y Chung","year":"2012","unstructured":"Chung Y (2012) Distributed denial of service is a scalability problem. ACM SIGCOMM Comput Commun Rev 42(1):69. \nhttps:\/\/doi.org\/10.1145\/2096149.2096160","journal-title":"ACM SIGCOMM Comput Commun Rev"},{"issue":"1","key":"3028_CR11","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1145\/1327452.1327492","volume":"51","author":"J Dean","year":"2008","unstructured":"Dean J, Ghemawat S (2008) Mapreduce: simplified data processing on large clusters. Commun ACM 51(1):107\u2013113. \nhttps:\/\/doi.org\/10.1145\/1327452.1327492","journal-title":"Commun ACM"},{"key":"3028_CR12","unstructured":"Department for Culture, Media and Sport: Almost half of UK firms hit by cyber breach or attack in the past year - gov.uk (2017). \nhttps:\/\/www.gov.uk\/government\/news\/almost-half-of-uk-firms-hit-by-cyber-breach-or-attack-in-the-past-year\n\n. Accessed on 26 Oct 2017"},{"key":"3028_CR13","doi-asserted-by":"publisher","unstructured":"Durumeric Z, Kasten J, Adrian D, Halderman JA, Bailey M, Li F, Weaver N, Amann J, Beekman J, Payer M, Paxson V (2014) The matter of heartbleed. In: Proceedings of the 2014 Conference on Internet Measurement Conference, IMC\u201914. ACM, New York, NY, USA, pp 475\u2013488. \nhttps:\/\/doi.org\/10.1145\/2663716.2663755","DOI":"10.1145\/2663716.2663755"},{"issue":"7","key":"3028_CR14","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(16)30051-3","volume":"2016","author":"J Elmellas","year":"2016","unstructured":"Elmellas J (2016) Knowledge is power: the evolution of threat intelligence. Comput Fraud Secur 2016(7):5\u20139","journal-title":"Comput Fraud Secur"},{"issue":"7","key":"3028_CR15","doi-asserted-by":"publisher","first-page":"e3856","DOI":"10.1002\/cpe.3856","volume":"29","author":"K Gai","year":"2017","unstructured":"Gai K, Qiu M, Hassan H (2017) Secure cyber incident analytics framework using Monte Carlo simulations for financial cybersecurity insurance in cloud computing. Concurr Comput Pract Exp 29(7):e3856. \nhttps:\/\/doi.org\/10.1002\/cpe.3856","journal-title":"Concurr Comput Pract Exp"},{"key":"3028_CR16","unstructured":"Heinl C (2018) NTU Singapore cyber risk management project, key observations to enhance cyber resilience. Tech. rep., Department of Computer Science, Michigan State University"},{"issue":"2","key":"3028_CR17","doi-asserted-by":"publisher","first-page":"2225","DOI":"10.1109\/JIOT.2018.2883728","volume":"6","author":"A Ikpehai","year":"2019","unstructured":"Ikpehai A, Adebisi B, Rabie KM, Anoh K, Ande RE, Hammoudeh M, Gacanin H, Mbanaso UM (2019) Low-power wide area network technologies for internet-of-things: a comparative review. IEEE Internet Things J 6(2):2225\u20132240. \nhttps:\/\/doi.org\/10.1109\/JIOT.2018.2883728","journal-title":"IEEE Internet Things J"},{"issue":"2","key":"3028_CR18","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1145\/2408776.2408793","volume":"56","author":"A Juels","year":"2013","unstructured":"Juels A, Oprea A (2013) New approaches to security and availability for cloud data. Commun ACM 56(2):64\u201373. \nhttps:\/\/doi.org\/10.1145\/2408776.2408793","journal-title":"Commun ACM"},{"key":"3028_CR19","doi-asserted-by":"crossref","unstructured":"Luiijf E, Klaver M (2015) On the sharing of cyber security information. In: International Conference on Critical Infrastructure Protection. Springer, pp 29\u201346","DOI":"10.1007\/978-3-319-26567-4_3"},{"issue":"1","key":"3028_CR20","doi-asserted-by":"publisher","first-page":"14","DOI":"10.3390\/jsan8010014","volume":"8","author":"M Mackintosh","year":"2019","unstructured":"Mackintosh M, Epiphaniou G, Al-Khateeb H, Burnham K, Pillai P, Hammoudeh M (2019) Preliminaries of orthogonal layered defence using functional and assurance controls in industrial control systems. J Sens Actuator Netw 8(1):14","journal-title":"J Sens Actuator Netw"},{"key":"3028_CR21","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1016\/j.compeleceng.2019.02.022","volume":"75","author":"DR McKinnel","year":"2019","unstructured":"McKinnel DR, Dargahi T, Dehghantanha A, Choo KKR (2019) A systematic literature review and meta-analysis on artificial intelligence in penetration testing and vulnerability assessment. Comput Electr Eng 75:175\u2013188. \nhttps:\/\/doi.org\/10.1016\/j.compeleceng.2019.02.022","journal-title":"Comput Electr Eng"},{"key":"3028_CR22","doi-asserted-by":"publisher","unstructured":"Pinheiro P, Aparicio M, Costa C (2014) Adoption of cloud computing systems. In: Proceedings of the International Conference on Information Systems and Design of Communication, ISDOC\u201914. ACM, New York, NY, USA, pp. 127\u2013131. \nhttps:\/\/doi.org\/10.1145\/2618168.2618188","DOI":"10.1145\/2618168.2618188"},{"key":"3028_CR23","doi-asserted-by":"publisher","unstructured":"Saleem J, Hammoudeh M, Raza U, Adebisi B, Ande R (2018) Iot standardisation: Challenges, perspectives and solution. In: Proceedings of the 2Nd International Conference on Future Networks and Distributed Systems, ICFNDS\u201918. ACM, New York, NY, USA, pp. 1:1\u20131:9. \nhttps:\/\/doi.org\/10.1145\/3231053.3231103","DOI":"10.1145\/3231053.3231103"},{"issue":"7","key":"3028_CR24","doi-asserted-by":"publisher","first-page":"388","DOI":"10.1145\/361011.361067","volume":"17","author":"JH Saltzer","year":"1974","unstructured":"Saltzer JH (1974) Protection and the control of information sharing in multics. Commun ACM 17(7):388\u2013402. \nhttps:\/\/doi.org\/10.1145\/361011.361067","journal-title":"Commun ACM"},{"issue":"5","key":"3028_CR25","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1109\/msecp.2003.1236236","volume":"1","author":"F Schneider","year":"2003","unstructured":"Schneider F (2003) Least privilege and more. IEEE Secur Priv Mag 1(5):55\u201359. \nhttps:\/\/doi.org\/10.1109\/msecp.2003.1236236","journal-title":"IEEE Secur Priv Mag"},{"key":"3028_CR26","unstructured":"Verizon RISK: vz-risk\/vcdb: Veris community database (2017). \nhttps:\/\/github.com\/vz-risk\/VCDB\n\n. Accessed 26 Oct 2017"},{"key":"3028_CR27","unstructured":"Walker-Roberts S (2017) Jsdoc: Home. \nhttps:\/\/steven.walkerroberts.co.uk\/verisdb-analyst\/\n\n. Accessed 26 Oct 2017"},{"key":"3028_CR28","unstructured":"Walker-Roberts S (2017) Veris json data not compliant with json spec. issue #10292 vz-risk\/vcdb . \nhttps:\/\/github.com\/vz-risk\/VCDB\/issues\/10292#issuecomment-340160543\n\n. Accessed 30 Oct 2017"},{"key":"3028_CR29","unstructured":"Walker-Roberts S (2017) walkerandco\/verisdb-analyst: an application for realtime visual and interactive analysis of verisdb incident data. the server uses isomorphic javascript and mongodb to analyse the data at lightning fast speeds. \nhttps:\/\/github.com\/walkerandco\/verisdb-analyst\n\n. Accessed 26 Oct 2017"},{"key":"3028_CR30","doi-asserted-by":"publisher","first-page":"131","DOI":"10.1007\/978-3-319-92624-7_6","volume-title":"Artificial intelligence agents as mediators of trustless security systems and distributed computing applications","author":"S Walker-Roberts","year":"2018","unstructured":"Walker-Roberts S, Hammoudeh M (2018) Artificial intelligence agents as mediators of trustless security systems and distributed computing applications. Springer, Cham, pp 131\u2013155. \nhttps:\/\/doi.org\/10.1007\/978-3-319-92624-7_6"},{"key":"3028_CR31","doi-asserted-by":"publisher","first-page":"25167","DOI":"10.1109\/ACCESS.2018.2817560","volume":"6","author":"S Walker-Roberts","year":"2018","unstructured":"Walker-Roberts S, Hammoudeh M, Dehghantanha A (2018) A systematic review of the availability and efficacy of countermeasures to internal threats in healthcare critical infrastructure. IEEE Access 6:25167\u201325177","journal-title":"IEEE Access"},{"key":"3028_CR32","doi-asserted-by":"publisher","first-page":"101988","DOI":"10.1016\/j.adhoc.2019.101988","volume":"95","author":"M Walshe","year":"2019","unstructured":"Walshe M, Epiphaniou G, Al-Khateeb H, Hammoudeh M, Katos V, Dehghantanha A (2019) Non-interactive zero knowledge proofs for the authentication of iot devices in reduced connectivity environments. Ad Hoc Netw 95:101988. \nhttps:\/\/doi.org\/10.1016\/j.adhoc.2019.101988","journal-title":"Ad Hoc Netw"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-019-03028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11227-019-03028-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-019-03028-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,10,22]],"date-time":"2020-10-22T23:20:19Z","timestamp":1603408819000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11227-019-03028-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,10,24]]},"references-count":32,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,4]]}},"alternative-id":["3028"],"URL":"https:\/\/doi.org\/10.1007\/s11227-019-03028-9","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,10,24]]},"assertion":[{"value":"24 October 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}