{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T02:39:08Z","timestamp":1784774348896,"version":"3.55.0"},"reference-count":40,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T00:00:00Z","timestamp":1780358400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"DOI":"10.13039\/100005501","name":"BIRD Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100005501","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.cose.2026.104979","type":"journal-article","created":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T05:24:12Z","timestamp":1780118652000},"page":"104979","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":1,"special_numbering":"C","title":["An evidence-driven analysis of threat information sharing challenges for industrial control systems"],"prefix":"10.1016","volume":"169","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9507-4368","authenticated-orcid":false,"given":"Rubin","family":"Krief","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1214-3466","authenticated-orcid":false,"given":"Adam","family":"Hahn","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel","family":"Rebori-Carretero","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aviad","family":"Elyashar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nik","family":"Urlaub","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7229-3899","authenticated-orcid":false,"given":"Rami","family":"Puzis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2026.104979_b1","doi-asserted-by":"crossref","first-page":"917","DOI":"10.3390\/electronics13050917","article-title":"Industrial control systems security validation based on mitre att&ck","volume":"13","author":"Afenu","year":"2024","journal-title":"Electronics"},{"key":"10.1016\/j.cose.2026.104979_b2","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103352","article-title":"Cyber-threat intelligence for security decision-making: A review and research agenda for practice","volume":"132","author":"Ainslie","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.104979_b3","article-title":"Current approaches and future directions for cyber threat intelligence sharing","author":"Alaeifar","year":"2024","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cose.2026.104979_b4","series-title":"NeurIPS 2024 Datasets & Benchmarks","article-title":"Ctibench: A benchmark for evaluating llms in cyber threat intelligence","author":"Alam","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b5","series-title":"MITRE ATT&CK\u00ae for Industrial Control Systems: Design and Philosophy","author":"Alexander","year":"2020"},{"key":"10.1016\/j.cose.2026.104979_b6","series-title":"Designing Lightweight Cryptographic Primitives for Securing Industrial Control Systems","author":"Banerjee","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b7","series-title":"Secure: Benchmarking large language models for cybersecurity advisory","author":"Bhusal","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b8","series-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","author":"Case","year":"2016"},{"key":"10.1016\/j.cose.2026.104979_b9","series-title":"CSET @ USENIX Security 2021","article-title":"Probabilistic attack sequence generation and execution based on mitre att&ck for ics datasets","author":"Choi","year":"2021"},{"key":"10.1016\/j.cose.2026.104979_b10","series-title":"Threat detection, investigation, and response (tdir)","author":"CrowdStrike","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b11","series-title":"MAR-17-352-01 HatMan\u2014Safety System Targeted Malware","author":"Cybersecurity and Infrastructure Security Agency","year":"2017"},{"key":"10.1016\/j.cose.2026.104979_b12","series-title":"Known exploited vulnerabilities catalog","author":"Cybersecurity and Infrastructure Security Agency","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b13","series-title":"2023 Annual Report on Implementation","author":"Cyberspace Solarium Commission","year":"2023"},{"key":"10.1016\/j.cose.2026.104979_b14","series-title":"Promoting private sector cybersecurity information sharing","author":"Executive Order No. 13691","year":"2015"},{"key":"10.1016\/j.cose.2026.104979_b15","series-title":"IEEE EuroS&PW 2024","article-title":"Actionable cyber threat intelligence using knowledge graphs and large language models","author":"Fieblinger","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b16","series-title":"ACNS 2019","first-page":"277","article-title":"Quality evaluation of cyber threat intelligence feeds","volume":"vol. 12146","author":"Griffioen","year":"2019"},{"key":"10.1016\/j.cose.2026.104979_b17","series-title":"NDSS 2024","article-title":"Sharing cyber threat intelligence: Does it really help?","author":"Jin","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b18","series-title":"2021 13th International Conference on Cyber Conflict","first-page":"171","article-title":"Possibilities and limitations of cyber threat intelligence in energy systems","author":"Krasznay","year":"2021"},{"key":"10.1016\/j.cose.2026.104979_b19","doi-asserted-by":"crossref","unstructured":"L\u00f3pez-Morales, E., 2024. Securing cyber-physical systems via advanced cyber threat intelligence methods. In: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. pp. 5119\u20135121.","DOI":"10.1145\/3658644.3690865"},{"key":"10.1016\/j.cose.2026.104979_b20","series-title":"ACM ARES 2023","article-title":"Stixnet: A novel and modular solution for extracting all stix objects in cti reports","author":"Marchiori","year":"2023"},{"key":"10.1016\/j.cose.2026.104979_b21","series-title":"Reversing the tristation network protocol","author":"Miller","year":"2018"},{"key":"10.1016\/j.cose.2026.104979_b22","series-title":"MITRE D3FEND: A knowledge graph of cybersecurity countermeasures","author":"MITRE Corporation","year":"2025"},{"key":"10.1016\/j.cose.2026.104979_b23","series-title":"Stuxnet Facts Report: A Technical and Strategic Analysis","author":"NATO Cooperative Cyber Defence Centre of Excellence","year":"2013"},{"key":"10.1016\/j.cose.2026.104979_b24","series-title":"STIX\u2122 Version 2.1","author":"OASIS Open","year":"2021"},{"key":"10.1016\/j.cose.2026.104979_b25","series-title":"Formal Ontology in Information Systems - Proceedings of the 13th International Conference","first-page":"334","article-title":"Boosting d3fend: Ontological analysis and recommendations","author":"Oliveira","year":"2023"},{"key":"10.1016\/j.cose.2026.104979_b26","series-title":"Rfc 9424: Indicators of compromise (iocs) and their role in attack defence","author":"Paine","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b27","first-page":"1","article-title":"Cybersecurity guide for smes: Protecting small and medium-sized enterprises in the digital era","volume":"16","author":"Papathanasiou","year":"2025","journal-title":"J. Inf. Secur."},{"key":"10.1016\/j.cose.2026.104979_b28","series-title":"The State of ICS\/OT Cybersecurity in 2022 and Beyond","author":"Parsons","year":"2022"},{"key":"10.1016\/j.cose.2026.104979_b29","article-title":"A cyberattack in saudi arabia had a deadly goal. experts fear another try","author":"Perlroth","year":"2018","journal-title":"N. Y. Times"},{"key":"10.1016\/j.cose.2026.104979_b30","series-title":"Top 20 secure plc coding practices v1.0","author":"PLC Security","year":"2021"},{"key":"10.1016\/j.cose.2026.104979_b31","series-title":"ARES 2019","article-title":"A quantitative evaluation of trust in the quality of cyber threat intelligence","author":"Schaberreiter","year":"2019"},{"key":"10.1016\/j.cose.2026.104979_b32","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1016\/j.ijcip.2014.01.004","article-title":"An evaluation of modification attacks on programmable logic controllers","volume":"7","author":"Schuett","year":"2014","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.cose.2026.104979_b33","article-title":"Ics patch tuesday advisories published by siemens, schneider electric, aveva, cisa","author":"SecurityWeek","year":"2024","journal-title":"SecurityWeek"},{"key":"10.1016\/j.cose.2026.104979_b34","series-title":"Threat detection, investigation, and response (tdir)","author":"Splunk","year":"2023"},{"key":"10.1016\/j.cose.2026.104979_b35","series-title":"MITRE ATT&CK\u00ae: Design and Philosophy","author":"Strom","year":"2020"},{"key":"10.1016\/j.cose.2026.104979_b36","series-title":"Mitre att&ck\u00ae for ics","author":"The MITRE Corporation","year":"2024"},{"key":"10.1016\/j.cose.2026.104979_b37","series-title":"Cybersecurity: Federal Actions Urgently Needed to Better Protect the Nation\u2019s Critical Infrastructure","author":"U.S. Government Accountability Office","year":"2023"},{"key":"10.1016\/j.cose.2026.104979_b38","series-title":"Final Safety Evaluation by The Office of Nuclear Reactor Regulation: Triconex Topical Report 7286-545-1, Revision 4 - Invensys Operations Management Project No. 709","author":"U.S. Nuclear Regulatory Commission","year":"2012"},{"key":"10.1016\/j.cose.2026.104979_b39","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2019.101589","article-title":"Cyber threat intelligence sharing: Survey and research directions","author":"Wagner","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.104979_b40","series-title":"Enhancing the stix representation of mitre att&ck for group filtering and technique prioritization","author":"Zych","year":"2022"}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826001550?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826001550?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T08:45:51Z","timestamp":1780994751000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404826001550"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":40,"alternative-id":["S0167404826001550"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2026.104979","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"An evidence-driven analysis of threat information sharing challenges for industrial control systems","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2026.104979","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104979"}}