{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T15:15:19Z","timestamp":1784214919136,"version":"3.55.0"},"reference-count":67,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016,1]]},"DOI":"10.1109\/aspdac.2016.7428063","type":"proceedings-article","created":{"date-parts":[[2016,3,10]],"date-time":"2016-03-10T21:48:08Z","timestamp":1457646488000},"page":"511-518","source":"Crossref","is-referenced-by-count":11,"title":["Enabling multi-layer cyber-security assessment of Industrial Control Systems through Hardware-In-The-Loop testbeds"],"prefix":"10.1109","author":[{"given":"Anastasis","family":"Keliris","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nektarios Georgios","family":"Tsoutsos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raghad","family":"Baiad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michail","family":"Maniatakos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","first-page":"957","article-title":"ret2dir: Rethinking kernel isolation","author":"kemerlis","year":"2014","journal-title":"USENIX Security Symposium"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.51"},{"key":"ref33","article-title":"A large-scale analysis of the security of embedded firmwares","author":"costin","year":"2014","journal-title":"USENIX Security Symposium"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2015.7372617"},{"key":"ref31","article-title":"Introduction to embedded reverse engineering for PC reversers","author":"slochinsky","year":"2010","journal-title":"RECON Conference"},{"key":"ref30","author":"ferguson","year":"2008","journal-title":"Reverse Engineering Code with IDA Pro"},{"key":"ref37","first-page":"552","article-title":"The geometry of innocent flesh on the bone: Return-into-libc without function calls (on the x86)","author":"shacham","year":"2007","journal-title":"ACM Computer and Communications Security (CCS)"},{"key":"ref36","first-page":"1","article-title":"Leveraging ethernet card vulnerabilities in field devices","author":"peck","year":"2009","journal-title":"SCADA Security Scientific Symposium"},{"key":"ref35","article-title":"Exploiting siemens simatic S7 PLCs","author":"beresford","year":"2011","journal-title":"Black Hat USA"},{"key":"ref34","article-title":"Creating a weapon of mass disruption: Attacking programmable logic controllers","author":"gjendemsj?","year":"2013"},{"key":"ref60","first-page":"670","article-title":"Industrial control systems security: What is happening?","author":"krotofil","year":"2013","journal-title":"Industrial Informatics (INDIN)"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1016\/0098-1354(93)80018-I"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2015.7436314"},{"key":"ref63","first-page":"48109","article-title":"Review of hardware-in-t.he-loop simulation and its prospects in the automotive area","volume":"1001","author":"fathy","year":"2006","journal-title":"Ann Arbor"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44371-2_25"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/FIE.1999.841594"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"388","DOI":"10.1007\/3-540-48405-1_25","article-title":"Differential power analysis","author":"kocher","year":"1999","journal-title":"Advances in Cryptology-CRYPTO"},{"key":"ref65","article-title":"A Cybersecurity Testbed for Industrial Control Systems","year":"2014"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/HSI.2010.5514494"},{"key":"ref29","article-title":"Reversing industrial firmware for fun and backdoors i","author":"santamarta","year":"2011"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2012.2226919"},{"key":"ref2","article-title":"IT security for industrial control systems: Requirements specification and performance testing","author":"falco","year":"2004","journal-title":"NDIA Homeland Security Symposium & Exhibition"},{"key":"ref1","article-title":"An abbreviated history of automation & industrial controls systems and cy-bersecurity","author":"gicsp","year":"2014"},{"key":"ref20","article-title":"Havex malware strikes industrial sector via watering hole attacks","author":"walker","year":"2014"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.299"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2013.2287186"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2012.2188769"},{"key":"ref23","doi-asserted-by":"crossref","first-page":"370","DOI":"10.1109\/JPROC.2005.862424","article-title":"The sorcerer's apprentice guide to fault attacks","volume":"94","author":"bar-ei","year":"2006","journal-title":"Proceedings of the IEEE"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1007\/3-540-68697-5_9","article-title":"Timing attacks on implementations of diffie-hellman, rsa, dss, and other systems","author":"kocher","year":"1996","journal-title":"Advances in Cryptology-CRYPTO"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-36400-5_4"},{"key":"ref50","article-title":"Control system devices: Architecture and supply channels overview","year":"2010","journal-title":"Sandia"},{"key":"ref51","article-title":"The use of attack trees in assessing vulnerabilities in scada systems","author":"byres","year":"0","journal-title":"CiteSeer"},{"key":"ref59","article-title":"Measurement challenges and opportunities for developing Smart Grid testbeds","year":"2014","journal-title":"NIST"},{"key":"ref58","article-title":"Cyber Security Assessments of Industrial Control Systems: A good practice guide","year":"2011","journal-title":"Centre for the Protection of National Infrastructure"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41488-6_12"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382244"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/1952982.1952995"},{"key":"ref54","article-title":"The aurora attack","year":"2007"},{"key":"ref53","article-title":"Distinguishing internet-facing ics devices using plc programming information","author":"williams","year":"2014","journal-title":"DTIC Document Tech Rep"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04798-5_5"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39498-0_12"},{"key":"ref11","article-title":"Global Industrial Control Systems (ICS) Security Market","year":"2015","journal-title":"Infinity Research"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.45"},{"key":"ref12","article-title":"Research challenges for the security of control systems","author":"cardenas","year":"2008","journal-title":"HOTSEC"},{"key":"ref13","article-title":"W32. stuxnet dossier","author":"falliere","year":"2011","journal-title":"White Paper Symantec Corporation"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.3390\/fi4040971","article-title":"The cousins of stuxnet: Duqu, flame, and gauss","author":"benes\u00e1th","year":"2012","journal-title":"Future Internet"},{"key":"ref15","article-title":"Mysterious 08 Turkey pipeline blast opened new cyberwar","author":"robertson","year":"2014","journal-title":"Bloomberg Business"},{"key":"ref16","author":"slay","year":"2008","journal-title":"Lessons Learned From the Maroochy Water Breach"},{"key":"ref17","article-title":"Cyber incidents involving control systems","author":"turk","year":"2005","journal-title":"CiteSeer"},{"key":"ref18","article-title":"Zotob, PnP worms slam 13 DaimlerChrysler plants","author":"roberts","year":"2005"},{"key":"ref19","article-title":"Slammer worm crashed ohio nuke plant network","volume":"19","author":"poulsen","year":"2003","journal-title":"Security Focus"},{"key":"ref4","article-title":"Protecting industrial control systems: Recommendations for europe and member states","author":"leszczyna","year":"2011"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2012.071812.00124"},{"key":"ref6","first-page":"213","article-title":"The myths and facts behind cyber security risks for industrial control systems","volume":"116","author":"byres","year":"2004","journal-title":"Proceedings of the VDE Kongress"},{"key":"ref5","article-title":"Guide to industrial control systems (ICS) security","author":"stouffer","year":"2011","journal-title":"NIST Special Publication 800&#x2013;82"},{"key":"ref8","article-title":"ICS-CERT Year in Review: 2014","year":"2014","journal-title":"ICS-CERT"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1049\/et.2014.0810"},{"key":"ref49","article-title":"Hacking Team: a zero-day market case study","author":"tsyrklevich","year":"2015"},{"key":"ref9","article-title":"Dell Annual Threat report 2015","year":"2015","journal-title":"Dell Security"},{"key":"ref46","article-title":"Comprehensive multi-vector penetration testing","year":"0","journal-title":"Core Security"},{"key":"ref45","article-title":"Xenotix XSS Exploit Framework","year":"0"},{"key":"ref48","article-title":"New Dark-Web market is selling zero-day exploits to hackers","author":"greenberg","year":"2015"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SAI.2014.6918247"},{"key":"ref42","article-title":"25 years of vulnerabilities: 1988-2012","author":"younan","year":"2013","journal-title":"Sourcefire Vulnerability Research Tech Rep"},{"key":"ref41","first-page":"161","article-title":"Control-flow bending: On the effectiveness of control-flow integrity","author":"carlini","year":"2015","journal-title":"USENIX Security Symposium"},{"key":"ref44","article-title":"Browser Exploitation Framework","year":"0","journal-title":"B Project"},{"key":"ref43","author":"maynor","year":"2011","journal-title":"Metasploit Toolkit for Penetration Testing Exploit Development and Vulnerability Research"}],"event":{"name":"2016 21st Asia and South Pacific Design Automation Conference (ASP-DAC)","location":"Macao, Macao","start":{"date-parts":[[2016,1,25]]},"end":{"date-parts":[[2016,1,28]]}},"container-title":["2016 21st Asia and South Pacific Design Automation Conference (ASP-DAC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/7422345\/7427971\/7428063.pdf?arnumber=7428063","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,5]],"date-time":"2019-09-05T12:07:30Z","timestamp":1567685250000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7428063\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,1]]},"references-count":67,"URL":"https:\/\/doi.org\/10.1109\/aspdac.2016.7428063","relation":{},"subject":[],"published":{"date-parts":[[2016,1]]}}}