{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T05:31:36Z","timestamp":1778823096668,"version":"3.51.4"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Engineering Applications of Artificial Intelligence"],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1016\/j.engappai.2025.112410","type":"journal-article","created":{"date-parts":[[2025,9,30]],"date-time":"2025-09-30T06:20:01Z","timestamp":1759213201000},"page":"112410","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":3,"special_numbering":"PB","title":["An intrusion detection system for critical infrastructures: Modbus approach"],"prefix":"10.1016","volume":"162","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2679-4278","authenticated-orcid":false,"given":"Murat","family":"Varol","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8210-5070","authenticated-orcid":false,"given":"Murat","family":"\u0130skefiyeli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"issue":"6","key":"10.1016\/j.engappai.2025.112410_b1","article-title":"Anomaly detection system based on deep learning for cyber physical systems on sensory and network datasets","volume":"14","author":"Almendli","year":"2024","journal-title":"Int. J. Electr. Comput. Eng. (IJECE)"},{"issue":"24","key":"10.1016\/j.engappai.2025.112410_b2","doi-asserted-by":"crossref","DOI":"10.3390\/app142411804","article-title":"SMS spam detection system based on deep learning architectures for turkish and english messages","volume":"14","author":"Altunay","year":"2024","journal-title":"Appl. Sci."},{"key":"10.1016\/j.engappai.2025.112410_b3","series-title":"Evaluation of machine learning-based anomaly detection algorithms on an industrial modbus\/TCP data set","first-page":"1","author":"Anton","year":"2018"},{"issue":"4","key":"10.1016\/j.engappai.2025.112410_b4","doi-asserted-by":"crossref","first-page":"502","DOI":"10.1016\/j.ifacol.2024.07.268","article-title":"Modbus vulnerability: Hard-to-detect sabotage scenario","volume":"58","author":"Barty\u015b","year":"2024","journal-title":"IFAC-PapersOnLine"},{"key":"10.1016\/j.engappai.2025.112410_b5","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijcip.2022.100573","article-title":"Feasibility of critical infrastructure protection using network functions for programmable and decoupled ICS policy enforcement over WAN","volume":"39","author":"Baxley","year":"2022","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.engappai.2025.112410_b6","series-title":"Securing substations with trust, risk posture, and multi-agent systems: A comprehensive approach","first-page":"1","author":"Boakye-Boateng","year":"2023"},{"key":"10.1016\/j.engappai.2025.112410_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2024.110804","article-title":"Malware communication in smart factories: A network traffic data set","volume":"255","author":"Brenner","year":"2024","journal-title":"Comput. Netw."},{"key":"10.1016\/j.engappai.2025.112410_b8","article-title":"Enhancing cybersecurity in edge iIoT networks: An asynchronous federated learning approach with a deep hybrid detection model","volume":"27","author":"Bukhari","year":"2024","journal-title":"Internet Things"},{"key":"10.1016\/j.engappai.2025.112410_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2023.108768","article-title":"An efficient evolutionary deep learning-based attack prediction in supply chain management systems","volume":"109","author":"Chauhdary","year":"2023","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.engappai.2025.112410_b10","series-title":"CIC modbus dataset 2023","author":"[dataset] Kwasi Boakye-Boateng","year":"2023"},{"issue":"3","key":"10.1016\/j.engappai.2025.112410_b11","first-page":"5743","article-title":"RRCNN: Request response-based convolutional neural network for ICS network traffic anomaly detection","volume":"75","author":"Du","year":"2023","journal-title":"Comput. Mater. Contin."},{"key":"10.1016\/j.engappai.2025.112410_b12","article-title":"Cybersecurity-aware log management system for critical water infrastructures","volume":"169","author":"Dural Balta","year":"2024","journal-title":"Appl. Soft Comput."},{"key":"10.1016\/j.engappai.2025.112410_b13","series-title":"Critical Information Infrastructures Security","first-page":"230","article-title":"Denial of service attacks: Detecting the frailties of machine learning algorithms in the classification process","author":"Fraz\u00e3o","year":"2019"},{"key":"10.1016\/j.engappai.2025.112410_b14","series-title":"Deep learning-based multi-PLC anomaly detection in industrial control systems","first-page":"4878","author":"Gawehn","year":"2022"},{"issue":"4","key":"10.1016\/j.engappai.2025.112410_b15","doi-asserted-by":"crossref","first-page":"895","DOI":"10.3390\/jcp3040041","article-title":"Anomaly detection for modbus over TCP in control systems using entropy and classification-based analysis","volume":"3","author":"Ghosh","year":"2023","journal-title":"J. Cybersecur. Priv."},{"issue":"2","key":"10.1016\/j.engappai.2025.112410_b16","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1016\/j.ijcip.2013.05.001","article-title":"Accurate modeling of modbus\/TCP for intrusion detection in scada systems","volume":"6","author":"Goldenberg","year":"2013","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"issue":"5","key":"10.1016\/j.engappai.2025.112410_b17","doi-asserted-by":"crossref","first-page":"2947","DOI":"10.1007\/s10586-023-04028-4","article-title":"A novel method to detect cyber-attacks in IoT\/iIoT devices on the modbus protocol using deep learning","volume":"26","author":"Gueye","year":"2023","journal-title":"Clust. Comput."},{"key":"10.1016\/j.engappai.2025.112410_b18","series-title":"Anomaly detection sensors for a modbus-based oil and gas well-monitoring system","first-page":"1","author":"He","year":"2019"},{"key":"10.1016\/j.engappai.2025.112410_b19","series-title":"Deep neural networks for industrial protocol recognition and cipher suite used","first-page":"1","author":"Holasova","year":"2022"},{"key":"10.1016\/j.engappai.2025.112410_b20","series-title":"Smart meter modbus RS-485 intrusion detection by federated learning approach","first-page":"559","author":"Hossain","year":"2023"},{"key":"10.1016\/j.engappai.2025.112410_b21","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1016\/j.asoc.2018.06.017","article-title":"Securing the operations in SCADA-IoT platform based industrial control system using ensemble of deep belief networks","volume":"71","author":"Huda","year":"2018","journal-title":"Appl. Soft Comput."},{"key":"10.1016\/j.engappai.2025.112410_b22","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1016\/j.ijcip.2008.08.003","article-title":"Attack taxonomies for the modbus protocols","volume":"1","author":"Huitsing","year":"2008","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.engappai.2025.112410_b23","series-title":"Security of machine learning-based anomaly detection in cyber physical systems","first-page":"1","author":"Jadidi","year":"2022"},{"issue":"23","key":"10.1016\/j.engappai.2025.112410_b24","doi-asserted-by":"crossref","DOI":"10.3390\/s22239084","article-title":"Deep learning anomaly classification using multi-attention residual blocks for industrial control systems","volume":"22","author":"Jiang","year":"2022","journal-title":"Sensors"},{"key":"10.1016\/j.engappai.2025.112410_b25","doi-asserted-by":"crossref","DOI":"10.1016\/j.adhoc.2022.102930","article-title":"Enhancing iIoT networks protection: A robust security model for attack detection in internet industrial control systems","volume":"134","author":"Khan","year":"2022","journal-title":"Ad Hoc Netw."},{"issue":"2","key":"10.1016\/j.engappai.2025.112410_b26","doi-asserted-by":"crossref","first-page":"11100","DOI":"10.1016\/j.ifacol.2020.12.258","article-title":"Assessment of hidden channel attacks: Targetting modbus\/TCP","volume":"53","author":"Lamsh\u00f6ft","year":"2020","journal-title":"IFAC-PapersOnLine"},{"issue":"3","key":"10.1016\/j.engappai.2025.112410_b27","doi-asserted-by":"crossref","first-page":"641","DOI":"10.1007\/s40998-022-00493-6","article-title":"Development of intrusion detection in industrial control systems based on deep learning","volume":"46","author":"Monfared","year":"2022","journal-title":"Iran. J. Sci. Technol. Trans. Electrical Eng."},{"key":"10.1016\/j.engappai.2025.112410_b28","series-title":"Critical Infrastructure Protection VIII","first-page":"65","article-title":"Industrial control system traffic data sets for intrusion detection research","author":"Morris","year":"2014"},{"issue":"3","key":"10.1016\/j.engappai.2025.112410_b29","doi-asserted-by":"crossref","first-page":"1345","DOI":"10.32604\/iasc.2022.020801","article-title":"Industrial datasets with ICS testbed and attack detection using machine learning techniques","volume":"31","author":"Mubarak","year":"2022","journal-title":"Intell. Autom. & Soft Comput."},{"issue":"6","key":"10.1016\/j.engappai.2025.112410_b30","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1109\/MCOM.002.2200553","article-title":"Modbus\/RS-485 attack detection on communication signals with machine learning","volume":"61","author":"Ochiai","year":"2023","journal-title":"IEEE Commun. Mag."},{"key":"10.1016\/j.engappai.2025.112410_b31","series-title":"CENTER water: A secure testbed infrastructure proposal for waste and potable water management","first-page":"1","author":"Ozcelik","year":"2021"},{"key":"10.1016\/j.engappai.2025.112410_b32","doi-asserted-by":"crossref","first-page":"2453","DOI":"10.1016\/j.procs.2020.04.265","article-title":"Fooling the master: Exploiting weaknesses in the modbus protocol","volume":"171","author":"Parian","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"10.1016\/j.engappai.2025.112410_b33","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijcip.2021.100427","article-title":"A systematic literature review on RAMS analysis for critical infrastructures protection","volume":"33","author":"Pirbhulal","year":"2021","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.engappai.2025.112410_b34","series-title":"Network traffic anomaly detection using recurrent neural networks","author":"Radford","year":"2018"},{"key":"10.1016\/j.engappai.2025.112410_b35","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijcip.2022.100568","article-title":"Launch of denial of service attacks on the modbus\/TCP protocol and development of its protection mechanisms","volume":"39","author":"Rahman","year":"2022","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.engappai.2025.112410_b36","series-title":"Design of intrusion prevention system for OT networks using deep neural networks","first-page":"1","author":"Rajapkar","year":"2020"},{"key":"10.1016\/j.engappai.2025.112410_b37","doi-asserted-by":"crossref","DOI":"10.1016\/j.ijcip.2023.100647","article-title":"A survey on safeguarding critical infrastructures: Attacks, ai security, and future directions","volume":"44","author":"Raval","year":"2024","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"10.1016\/j.engappai.2025.112410_b38","series-title":"D-IDS for cyber-physical DER modbus system - architecture, modeling, testbed-based evaluation","first-page":"153","author":"Ravikumar","year":"2020"},{"key":"10.1016\/j.engappai.2025.112410_b39","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103373","article-title":"MOSTO: A toolkit to facilitate security auditing of ICS devices using modbus\/TCP","volume":"132","author":"Rodr\u00edguez","year":"2023","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.engappai.2025.112410_b40","doi-asserted-by":"crossref","DOI":"10.1155\/2022\/1241122","article-title":"Securing the IoT system of smart city against cyber threats using deep learning","volume":"2022","author":"Saba","year":"2022","journal-title":"Discrete Dyn. Nat. Soc."},{"issue":"9","key":"10.1016\/j.engappai.2025.112410_b41","doi-asserted-by":"crossref","first-page":"8852","DOI":"10.1109\/JIOT.2020.2996425","article-title":"An ensemble of deep recurrent neural networks for detecting IoT cyber attacks using network traffic","volume":"7","author":"Saharkhizan","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.engappai.2025.112410_b42","series-title":"Autoencoder via DCNN and LSTM models for intrusion detection in industrial control systems of critical infrastructures","first-page":"9","author":"Saheed","year":"2023"},{"issue":"2","key":"10.1016\/j.engappai.2025.112410_b43","doi-asserted-by":"crossref","first-page":"1137","DOI":"10.1109\/TNSM.2021.3078381","article-title":"A unified deep learning anomaly detection and classification approach for smart grid environments","volume":"18","author":"Siniosoglou","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.engappai.2025.112410_b44","series-title":"Anomaly detection in air-gapped industrial control systems of nuclear power plants","first-page":"1","author":"Thiyagarajan","year":"2024"},{"issue":"1","key":"10.1016\/j.engappai.2025.112410_b45","doi-asserted-by":"crossref","first-page":"101","DOI":"10.1016\/j.dcan.2022.09.008","article-title":"An ensemble deep learning model for cyber threat hunting in industrial internet of things","volume":"9","author":"Yazdinejad","year":"2023","journal-title":"Digit. Commun. Networks"},{"key":"10.1016\/j.engappai.2025.112410_b46","doi-asserted-by":"crossref","first-page":"49587","DOI":"10.1109\/ACCESS.2023.3277250","article-title":"GAN neural networks architectures for testing process control industrial network against cyber-attacks","volume":"11","author":"Zarzycki","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.engappai.2025.112410_b47","series-title":"MODLSTM: A method to recognize DoS attacks on modbus\/TCP","first-page":"319","author":"Zhang","year":"2022"},{"issue":"2","key":"10.1016\/j.engappai.2025.112410_b48","doi-asserted-by":"crossref","first-page":"839","DOI":"10.1007\/s11036-023-02108-8","article-title":"Improve the security of industrial control system: A fine-grained classification method for DoS attacks on modbus\/TCP","volume":"28","author":"Zhang","year":"2023","journal-title":"Mob. Networks Appl."}],"container-title":["Engineering Applications of Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0952197625024352?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0952197625024352?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T16:07:02Z","timestamp":1761840422000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0952197625024352"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12]]},"references-count":48,"alternative-id":["S0952197625024352"],"URL":"https:\/\/doi.org\/10.1016\/j.engappai.2025.112410","relation":{},"ISSN":["0952-1976"],"issn-type":[{"value":"0952-1976","type":"print"}],"subject":[],"published":{"date-parts":[[2025,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"An intrusion detection system for critical infrastructures: Modbus approach","name":"articletitle","label":"Article Title"},{"value":"Engineering Applications of Artificial Intelligence","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.engappai.2025.112410","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2025 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"112410"}}