{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T10:06:10Z","timestamp":1771668370559,"version":"3.50.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100004681","name":"Higher Education Commission Pakistan, Technology Development Fund Grant 206","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004681","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/access.2021.3111420","type":"journal-article","created":{"date-parts":[[2021,9,9]],"date-time":"2021-09-09T16:01:58Z","timestamp":1631203318000},"page":"126789-126800","source":"Crossref","is-referenced-by-count":30,"title":["Last Line of Defense: Reliability Through Inducing Cyber Threat Hunting With Deception in SCADA Networks"],"prefix":"10.1109","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4418-4959","authenticated-orcid":false,"given":"Abdul Basit","family":"Ajmal","sequence":"first","affiliation":[{"name":"Department of Computer Science, Cyber Security Laboratory, COMSATS University Islamabad, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8839-593X","authenticated-orcid":false,"given":"Masoom","family":"Alam","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Cyber Security Laboratory, COMSATS University Islamabad, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3439-6256","authenticated-orcid":false,"given":"Awais Abdul","family":"Khaliq","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Cyber Security Laboratory, COMSATS University Islamabad, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5952-8502","authenticated-orcid":false,"given":"Shawal","family":"Khan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Cyber Security Laboratory, COMSATS University Islamabad, Islamabad, Pakistan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9596-1765","authenticated-orcid":false,"given":"Zakria","family":"Qadir","sequence":"additional","affiliation":[{"name":"School of Computing Engineering and Mathematics, Western Sydney University, Penrith, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1905-6800","authenticated-orcid":false,"given":"M. A. Parvez","family":"Mahmud","sequence":"additional","affiliation":[{"name":"School of Engineering, Deakin University, Geelong, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","article-title":"The evolution of cyber threat intelligence (CTI): 2019 SANS CTI survey","author":"brown","year":"2019"},{"key":"ref38","author":"mundas","year":"2019","journal-title":"Core of Threat Hunting"},{"key":"ref33","article-title":"Launching threat hunting from almost nothing","author":"kakumaru","year":"2018"},{"key":"ref32","first-page":"110","article-title":"Microsoft terminates its Tay AI chatbot after she turns into a Nazi","volume":"24","author":"bright","year":"2016","journal-title":"ARS Technica"},{"key":"ref31","year":"2016","journal-title":"Cost of data breach study Global analysis"},{"key":"ref30","year":"2021","journal-title":"Malicious Traffic Detection System"},{"key":"ref37","author":"devon kerr","year":"2018","journal-title":"The Endgame Guide to Threat Hunting Practitioners"},{"key":"ref36","author":"klimkowski","year":"2017","journal-title":"Using bro to hunt persistent threats"},{"key":"ref35","year":"2021","journal-title":"zeek Bro Network Threat Hunting Utility"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2018.8422083"},{"key":"ref28","year":"2021","journal-title":"ICS\/SCADA Honeypot"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CompComm.2017.8322746"},{"key":"ref29","year":"2021","journal-title":"Activecmrita Real Intelligence Threat Analytics (Rita) is a Framework for Detecting Command and Control Communication Through Network Traffic Analysis"},{"key":"ref2","author":"ismail","year":"2017","journal-title":"The Rise of Cybercrime Continues to Accelerate"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2380790.2380805"},{"key":"ref20","article-title":"The diamond model of intrusion analysis","author":"caltagirone","year":"2013"},{"key":"ref22","article-title":"Simulation of cyber attacks against SCADA systems","author":"parcharidis","year":"2018"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1051\/matecconf\/201817301013"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(19)30074-1"},{"key":"ref23","article-title":"Simulating industrial control systems using mininet","author":"masset","year":"2018"},{"key":"ref26","year":"2021","journal-title":"Mininet\/Mininet Emulator for Rapid Prototyping of Software Defined Networks"},{"key":"ref25","author":"gunter","year":"2018","journal-title":"A practical model for conducting cyber threat hunting"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICACCS48705.2020.9074217"},{"key":"ref51","author":"monnappa","year":"2018","journal-title":"Learning Malware Analysis Explore the Concepts Tools and Techniques to Analyze and Investigate Windows Malware"},{"key":"ref53","year":"2021","journal-title":"Activecm Real Intelligence Threat Analytics (rita) is a Framework for Detecting Command and Control Communication Through Network Traffic Analysis"},{"key":"ref52","article-title":"Methods and systems for encoding computer processes for malware detection","author":"mainieri","year":"2018"},{"key":"ref10","first-page":"2653","article-title":"A security model of SCADA system based on attack tree","author":"tian","year":"2019","journal-title":"Proc IEEE 3rd Conf Energy Internet Energy Syst Integr (EI2)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CSCI49370.2019.00230"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(18)30065-4"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2994961"},{"key":"ref13","first-page":"1","article-title":"Distributed intrusion detection system using semantic-based rules for SCADA in smart grid","author":"mohan","year":"2020","journal-title":"IEEE\/PES Trans Distrib Conf Expo (T&D)"},{"key":"ref14","article-title":"Rogue7: Rogue engineering-station attacks on S7 Simatic PLCs","author":"biham","year":"2019","journal-title":"Proc Black Hat USA"},{"key":"ref15","article-title":"VLAN to VXLAN translation using VLAN-aware virtual machines","author":"sudhakaran","year":"2019"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.15622\/sp.2019.18.6.1333-1356"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2019.2893675"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3104260"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3134302.3134319"},{"key":"ref4","first-page":"151","article-title":"Host-oriented approach to cyber security for the scada systems","author":"lee","year":"2020","journal-title":"Proc 6th IEEE Congr Inf Sci Technol (CiSt)"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101666"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(19)30008-9"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2983179"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2016.2599841"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/3794603"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA.2018.8502495"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/NCG.2018.8593143"},{"key":"ref46","first-page":"259","article-title":"Analysis of link discovery service attacks in SDN controller","author":"nguyen","year":"2017","journal-title":"Proc Int Conf Inf Netw (ICOIN)"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICDIS.2018.00028"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICIN.2018.8401617"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ATNAC.2017.8215418"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-04537-1_12"},{"key":"ref41","first-page":"1","article-title":"TRITON: The first ICS cyber attack on safety instrument systems","author":"di pinto","year":"2018","journal-title":"Proc Black Hat USA"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICOASE.2018.8548783"},{"key":"ref43","first-page":"93","article-title":"Stealthy deception attacks against SCADA systems","author":"kleinmann","year":"2017","journal-title":"Computing Security"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9312710\/09531651.pdf?arnumber=9531651","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T20:47:32Z","timestamp":1756154852000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9531651\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/access.2021.3111420","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}