{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T12:00:10Z","timestamp":1784203210586,"version":"3.55.0"},"reference-count":92,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100007053","name":"Human Resources Program in Energy Technology of the Korea Institute of Energy Technology Evaluation and Planning (KETEP), through the Ministry of Trade, Industry and Energy, South Korea","doi-asserted-by":"publisher","award":["20174030201790"],"award-info":[{"award-number":["20174030201790"]}],"id":[{"id":"10.13039\/501100007053","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010193","name":"Korea Electric Power Corporation","doi-asserted-by":"publisher","award":["R18XA01"],"award-info":[{"award-number":["R18XA01"]}],"id":[{"id":"10.13039\/501100010193","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/access.2020.2983179","type":"journal-article","created":{"date-parts":[[2020,3,25]],"date-time":"2020-03-25T21:11:13Z","timestamp":1585170673000},"page":"62954-62968","source":"Crossref","is-referenced-by-count":19,"title":["Keeping Host Sanity for Security of the SCADA Systems"],"prefix":"10.1109","volume":"8","author":[{"given":"Jae-Myeong","family":"Lee","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6184-9310","authenticated-orcid":false,"given":"Sugwon","family":"Hong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref73","article-title":"Chapter 19: DLL basics","author":"richter","year":"1999","journal-title":"Programming Applications for Microsoft Windows"},{"key":"ref72","year":"2018","journal-title":"DllMain Entry Point"},{"key":"ref71","year":"2019","journal-title":"Link an Executable to a DLL"},{"key":"ref70","year":"2006","journal-title":"Dependency Walker 2 2"},{"key":"ref76","year":"2018","journal-title":"ThreadProc Callback Function"},{"key":"ref77","year":"2018","journal-title":"LoadLibraryA Function"},{"key":"ref74","article-title":"Chapter 16: Breaking through process boundary walls","author":"richter","year":"1995","journal-title":"Advanced Windows The Developers Guide to the WIN32 API for Windows NT 3 5 and Windows 95"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2018.4"},{"key":"ref75","year":"2018","journal-title":"CreateRemoteThread Function"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2016.4"},{"key":"ref78","year":"2018","journal-title":"SetWindowsHookExA Function"},{"key":"ref79","year":"2018","journal-title":"Asynchronous Procedure Calls"},{"key":"ref33","first-page":"1098","article-title":"Analyzing WannaCry ransomware considering the weapons and exploits","volume":"7","author":"kao","year":"2018","journal-title":"Proc ICACT-TACT"},{"key":"ref32","author":"mcneil","year":"2017","journal-title":"How did the WannaCry ransomworm spread?"},{"key":"ref31","year":"2017","journal-title":"WannaCry on Industrial Networks Error Correction"},{"key":"ref30","article-title":"TRITON: The first ICS cyber attack","author":"pinto","year":"0"},{"key":"ref37","article-title":"Security monitoring and network management for the power control network","volume":"9","author":"hong","year":"2020","journal-title":"Int J Electr Electron Eng Telecommun"},{"key":"ref36","author":"brandl","year":"2014","journal-title":"Are Microsoft Technologies Still Best for Process Control Systems?"},{"key":"ref35","year":"2017","journal-title":"Dated Windows Software the Weak Link for SCADA Systems"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04798-5_5"},{"key":"ref60","first-page":"55","article-title":"A deep learning approach for intrusion detection system in industry network","author":"hijazi","year":"2019","journal-title":"Proc 1st Int Conf Big Data Cybersecurity Intell"},{"key":"ref62","article-title":"Omni SCADA intrusion detection using deep learning algorithms","author":"gao","year":"2019","journal-title":"arXiv 1908 01974"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2019.8802785"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2019.8909701"},{"key":"ref28","year":"2017","journal-title":"TRISIS Malware Analysis of Safety System Targeted Malware"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/PCCC.2018.8710993"},{"key":"ref27","author":"johnson","year":"2017","journal-title":"Attackers deploy new ics attack framework triton and cause operational disruption to critical infrastructure"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2017.36"},{"key":"ref66","year":"2018","journal-title":"Power Systems Management and Associated Information Exchange&#x2014;Data and Communications Security&#x2014;Part 3 Communication Network and System Security&#x2014;Profiles Including TCP\/IP"},{"key":"ref29","year":"2017","journal-title":"MAR-17-352-01 HatMan&#x2014;Safety System Targeted Malware (Update B)"},{"key":"ref67","year":"2018","journal-title":"Power Systems Management and Associated Information Exchange&#x2014;Data and Communications Security&#x2014;Part 4 Profiles Including MMS"},{"key":"ref68","year":"2013","journal-title":"Power Systems Management and Associated Information Exchange&#x2014;Data and Communications Security&#x2014;Part 5 Security for IEC 60870-5 and Derivatives"},{"key":"ref69","year":"2007","journal-title":"Power Systems Management and Associated Information Exchange&#x2014;Data and Communications Security&#x2014;Part 6 Security for IEC 61850"},{"key":"ref2","year":"2016","journal-title":"Recommended Practice Improving Industrial Control Systems Cybersecurity with Defense-In-Depth Strategies"},{"key":"ref1","doi-asserted-by":"crossref","first-page":"747","DOI":"10.12720\/sgce.8.6.747-756","article-title":"Cyber security strategies and their implications for substation automation systems","volume":"8","author":"hong","year":"2019","journal-title":"Int J Smart Grid Clean Energy"},{"key":"ref20","year":"2017","journal-title":"HAVE"},{"key":"ref22","year":"2017","journal-title":"WIN32\/INDUSTROYER A new threat for industrial control systems"},{"key":"ref21","year":"2014","journal-title":"ICS Alert (ICS-ALERT-14-176-02A)"},{"key":"ref24","year":"2017","journal-title":"CrashOverride Analysis of the threat to electric grid operations"},{"key":"ref23","year":"2017","journal-title":"ICS Defense Use Case No 6 Modular ICS Malware"},{"key":"ref26","article-title":"CRASHOVERRIDE: Reassessing the 2016 Ukraine electric power event as a protection-focused attack","author":"slowik","year":"2019"},{"key":"ref25","author":"slowik","year":"2018","journal-title":"Anatomy of an Attack Detecting and Defeating Crashoverride"},{"key":"ref50","first-page":"1","article-title":"Adapting bro into SCADA: Building a specification-based intrusion detection system for the DNP3 protocol","author":"lin","year":"2012","journal-title":"Proc CSIIRW"},{"key":"ref51","first-page":"1","article-title":"Using model-based intrusion detection for SCADA networks","author":"cheung","year":"2007","journal-title":"Proc SCADA Security Sci Symp"},{"key":"ref92","year":"2020","journal-title":"InjectAllTheThings"},{"key":"ref91","year":"2016","journal-title":"GMER 2 2 19882"},{"key":"ref90","year":"2010","journal-title":"Virus Center&#x2014;Win32\/Parite B"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.4108\/eai.25-1-2019.159348"},{"key":"ref58","first-page":"1","article-title":"Through the eye of the PLC: Towards semantic security monitoring for industrial control systems","author":"hadziosmanovic","year":"2014","journal-title":"Proc ACSAC"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.3390\/electronics4040995"},{"key":"ref56","first-page":"1","article-title":"What&#x2019;s under the hood? Improving SCADA security with process awareness","author":"chromik","year":"2016","journal-title":"Proc Joint Workshop Cyber-Phys Secur Resilience Smart Grids (CPSR-SG)"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2897795.2897814"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2016.2547742"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2018.13"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2016.7568964"},{"key":"ref10","article-title":"W32.Stuxnet Dossier version 1.4","author":"falliere","year":"2011"},{"key":"ref11","article-title":"How Stuxnet spreads&#x2014;A study of infection paths in best practice systems","author":"byres","year":"2011"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2899015.2899028"},{"key":"ref12","author":"matrosov","year":"2011","journal-title":"Stuxnet Under the Microscope"},{"key":"ref13","article-title":"To kill a centrifuge: A technical analysis of what Stuxnet&#x2019;s creators tried to achieve","author":"langner","year":"2013"},{"key":"ref14","article-title":"Trojan.Dropper","author":"lau","year":"2012"},{"key":"ref15","author":"malik","year":"2020","journal-title":"DLL Injection and Hooking"},{"key":"ref82","year":"2019","journal-title":"PE Format"},{"key":"ref16","year":"2015","journal-title":"BlackEnergy 3&#x2014;Exfiltration of Data in ICS Networks ver 1 0"},{"key":"ref81","year":"2018","journal-title":"PAPCFUNC Callback Function"},{"key":"ref17","year":"2016","journal-title":"Security Report Black Energy"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/I4CT.2015.7219584"},{"key":"ref18","year":"2016","journal-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid"},{"key":"ref83","first-page":"1","article-title":"Detours: Binary Interception of Win32 Functions","author":"hunt","year":"1999","journal-title":"Proc 3rd Usenix Windows NT Symp"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2016.7"},{"key":"ref80","year":"2018","journal-title":"QueueUserAPC Function"},{"key":"ref89","year":"2010","journal-title":"Win32\/Parite"},{"key":"ref4","year":"2013","journal-title":"Industrial Communication Networks&#x2014;Network and System Security&#x2014;Part 3&#x2013;3 System Security Requirement and Security Levels"},{"key":"ref3","year":"2015","journal-title":"Guide to industrial control systems (ICS) security"},{"key":"ref6","author":"cleveland","year":"2012","journal-title":"Security Standards for the Power System Information Infrastructure"},{"key":"ref5","year":"2020","journal-title":"What is PERA?"},{"key":"ref85","year":"2019","journal-title":"Cheat Engine 7 0"},{"key":"ref8","author":"slowik","year":"2020","journal-title":"Evolution of ICS Attacks and the Prospects for Future Disruptive Events"},{"key":"ref86","year":"2004","journal-title":"OllyDbg 1 1"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.11159\/EEE19.117"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/PESGM.2016.7741668"},{"key":"ref87","article-title":"Chapter 4: Assembly language and disassembly primer","author":"monnappa","year":"2018","journal-title":"Learning Malware Analysis"},{"key":"ref88","year":"2018","journal-title":"VirtualQuery Function"},{"key":"ref9","author":"weiss","year":"2019","journal-title":"Control System Cyberattacks Have Become More Stealthy and Dangerous&#x2014;And Less Detectable"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRD.2016.2603339"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.14257\/ijsia.2016.10.4.27"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRD.2014.2300099"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2013.2294473"},{"key":"ref42","first-page":"ps2-09","article-title":"Cybersecurity defense system for distributed communication network in IEC-61850 power substations","author":"ko","year":"2019","journal-title":"CIGRE Colloquium"},{"key":"ref41","doi-asserted-by":"crossref","DOI":"10.3990\/1.9789036536455","article-title":"Anomaly detection in SCADA systems: A network based approach","author":"barbosa","year":"2014"},{"key":"ref44","article-title":"Cyber security of the smart grid control systems: Intrusion detection in IEC 61850 communication networks","author":"kabir-querrec","year":"2017"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2017.2737826"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8948470\/09046797.pdf?arnumber=9046797","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,19]],"date-time":"2022-10-19T19:35:22Z","timestamp":1666208122000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9046797\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":92,"URL":"https:\/\/doi.org\/10.1109\/access.2020.2983179","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}