{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:21:04Z","timestamp":1784733664420,"version":"3.55.0"},"reference-count":144,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2016,5,1]],"date-time":"2016-05-01T00:00:00Z","timestamp":1462060800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"name":"German Science Foundation"},{"name":"European Union's Seventh Framework Programme","award":["609611"],"award-info":[{"award-number":["609611"]}]},{"name":"Intel Collaborative Research Institute for Secure Computing (ICRI-SC)"},{"DOI":"10.13039\/100004752","name":"Consolidated Edison, Inc.","doi-asserted-by":"crossref","award":["4265141"],"award-info":[{"award-number":["4265141"]}],"id":[{"id":"10.13039\/100004752","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/100000006","name":"U.S. Office of Naval Research","doi-asserted-by":"crossref","award":["N00014-15-1-2182"],"award-info":[{"award-number":["N00014-15-1-2182"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"crossref"}]},{"name":"NYU Center for Cyber Security (New York and Abu Dhabi)"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. IEEE"],"published-print":{"date-parts":[[2016,5]]},"DOI":"10.1109\/jproc.2015.2512235","type":"journal-article","created":{"date-parts":[[2016,3,16]],"date-time":"2016-03-16T20:21:45Z","timestamp":1458159705000},"page":"1039-1057","source":"Crossref","is-referenced-by-count":338,"title":["The Cybersecurity Landscape in Industrial Control Systems"],"prefix":"10.1109","volume":"104","author":[{"given":"Stephen","family":"McLaughlin","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xueyang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lucas","family":"Davi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmad-Reza","family":"Sadeghi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michail","family":"Maniatakos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ramesh","family":"Karri","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","year":"2010","journal-title":"Cyber security assessments of industrial control systems"},{"key":"ref38","article-title":"Cyberphyseclab: A testbed for modeling, detecting and responding to security attacks on cyber physical systems","author":"shetty","year":"0","journal-title":"Proc ASE Int Conf Cyber Security"},{"key":"ref33","year":"2011","journal-title":"Common Cybersecurity Vulnerabilities in Industrial Control Systems"},{"key":"ref32","year":"0","journal-title":"Crisalis Project EU Deliverable D2 2 Final Requirement Definition"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2015.7372617"},{"key":"ref30","first-page":"1","article-title":"Gangrene: Exploring the mortality of flash memory","volume":"12","author":"templeman","year":"2012","journal-title":"HOTSEC"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1201\/b11352"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41485-5_22"},{"key":"ref35","year":"0","journal-title":"CVE-2011-2367"},{"key":"ref34","author":"beresford","year":"2011","journal-title":"The Sauce of Utter Pwnage"},{"key":"ref28","year":"0","journal-title":"The exploration and exploitation of an SD memory card"},{"key":"ref27","year":"0","journal-title":"USB Killer"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15031-9_11"},{"key":"ref20","author":"thomas","year":"2015","journal-title":"Hackers demo Jeep security hack"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2012.6378629"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2596668"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2006.01.003"},{"key":"ref23","author":"rosenfeld","year":"2010","journal-title":"Attacks and Defenses for JTAG"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1145\/2508148.2485970"},{"key":"ref26","author":"schneider","year":"0","journal-title":"USB flash drives are more dangerous than you think"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_5"},{"key":"ref25","author":"barnaby","year":"2006","journal-title":"Exploiting embedded systems Black Hat 2006"},{"key":"ref50","year":"0","journal-title":"Block diagram modeler\/simulator"},{"key":"ref51","first-page":"48??109","article-title":"Review of hardware-in-the-loop simulation and its prospects in the automotive area","volume":"1001","author":"fathy","year":"2006","journal-title":"Ann Arbor"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-012-0164-7"},{"key":"ref58","year":"0","journal-title":"Project basecamp"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2012.2226919"},{"key":"ref56","year":"0","journal-title":"National SCADA Test Bed (NSTB) Program"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/HSI.2010.5514494"},{"key":"ref54","year":"2014","journal-title":"Workshop Measurement Challenges and Opportunities in Developing Smart Grid Testbeds"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CPRE.2011.6035612"},{"key":"ref52","year":"2014","journal-title":"A cybersecurity testbed for industrial control systems"},{"key":"ref40","year":"2008","journal-title":"Cyber Security Issues for Protective Relays"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2011.115"},{"key":"ref3","year":"2011","journal-title":"Protecting industrial control systems&#x2014;Recommendations for Europe and member states"},{"key":"ref6","author":"weiss","year":"0","journal-title":"Assuring industrial control system (ICS) cyber security"},{"key":"ref5","author":"muncaster","year":"2011","journal-title":"Stuxnet-like attacks beckon as 50 new Scada threats discovered"},{"key":"ref8","year":"2014","journal-title":"Energy market review 2014&#x2014;Cyber-attacks Can the market respond?"},{"key":"ref49","year":"0","journal-title":"Open source and cross-platform platform"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39498-0_12"},{"key":"ref9","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1109\/JPROC.2011.2161428","article-title":"Cyber-physical security of a smart grid infrastructure","volume":"100","author":"mo","year":"2012","journal-title":"Proc IEEE"},{"key":"ref46","year":"2013","journal-title":"Good practice guide for certs in the area of industrial control systems"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-40r3"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ETS.2015.7138763"},{"key":"ref47","first-page":"61","article-title":"Position paper: Safety and security monitoring in ICS\/SCADA systems","author":"nicholson","year":"0","journal-title":"Proc 2nd Int Symp ICS SCADA Cyber Security Res"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.2172\/911827"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.2172\/1030885"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2015.7436314"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/FIE.1999.841594"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660309"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.23"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1007\/11576280_9"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.52"},{"key":"ref73","article-title":"Exploiting Siemens Simatic S7 PLCs","author":"beresford","year":"0","journal-title":"Proc Black Hat USA"},{"key":"ref72","article-title":"Are the NERC CIPS making the grid less reliable","author":"weiss","year":"0","journal-title":"Proc Control Global"},{"key":"ref129","article-title":"Stateful policy enforcement for control system device usage","author":"mclaughlin","year":"0","journal-title":"Proc 29th Annu Comput Security Appl Conf"},{"key":"ref71","year":"2006","journal-title":"NERC CIP 002 1&#x2014;Critical cyber asset identification"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23271"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRD.2010.2061872"},{"key":"ref76","author":"king","year":"2001","journal-title":"The economics of real-time and time-of-use pricing for residential consumers"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1145\/2461446.2461456"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14379-3_15"},{"key":"ref74","author":"newman","year":"2011","journal-title":"SCADA and PLC Vulnerabilities in Correctional Facilities"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1016\/j.energy.2011.07.054"},{"key":"ref133","article-title":"SCADA-specific intrusion detection\/prevention systems: A survey and tanomy","author":"zhu","year":"0","journal-title":"Proc 1st Workshop Secure Control Syst"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1109\/PRDC.2011.30"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1109\/ICCPS.2011.25"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920277"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2747913"},{"key":"ref79","year":"2011","journal-title":"Duqu A Stuxnet-like Malware Found in the Wild"},{"key":"ref136","article-title":"Detecting false data injection attacks on dc state estimation","author":"bobba","year":"0","journal-title":"Proc 1st Workshop Secure Control Syst"},{"key":"ref135","article-title":"Through the eye of the PLC: Semantic security monitoring for industrial processes","author":"hadziosmanovi?","year":"0","journal-title":"Proc 31st Annu Comput Security Appl Conf"},{"key":"ref138","article-title":"A trust based distributed Kalman filtering approach for mode estimation in power systems","author":"jiang","year":"0","journal-title":"Proc 1st Workshop Secure Control Syst"},{"key":"ref137","article-title":"On security indices for state estimators in power networks","author":"sandberg","year":"0","journal-title":"Proc 1st Workshop Secure Control Syst"},{"key":"ref60","author":"roberts","year":"2008","journal-title":"Zotob PnP Worms Slam 13 DaimlerChrysler Plants"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/MCS.2014.2364709"},{"key":"ref62","article-title":"Cyber incident blamed for nuclear power plant shutdown","author":"krebs","year":"2008","journal-title":"The Washington Post"},{"key":"ref61","article-title":"Computer viruses make it to orbit","year":"2008","journal-title":"BBC News"},{"key":"ref63","article-title":"Engineers who hacked into L.A. traffic signal computer, jamming streets, sentenced","author":"grad","year":"0","journal-title":"Los Angeles Times"},{"key":"ref64","author":"leall","year":"2009","journal-title":"Lessons from an Insider Attack on SCADA Systems"},{"key":"ref140","doi-asserted-by":"publisher","DOI":"10.1109\/TAC.2013.2266831"},{"key":"ref65","article-title":"Clues suggest Stuxnet virus was built for subtle nuclear sabotage","author":"zetter","year":"2010","journal-title":"Wired"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1145\/1755952.1755976"},{"key":"ref66","article-title":"Polish teen derails tram after hacking train network","author":"leyden","year":"2008","journal-title":"The Register"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1109\/ALLERTON.2009.5394956"},{"key":"ref67","article-title":"Sources: Staged cyber attack reveals vulnerability in power grid","author":"meserve","year":"2007","journal-title":"CNN"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1016\/j.automatica.2012.09.007"},{"key":"ref68","article-title":"The myths and facts behind cyber security risks for industrial control systems","author":"byres","year":"0","journal-title":"Proc ISA Process Control Conf"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/TAC.2013.2294618"},{"key":"ref2","author":"hayden","year":"2014","journal-title":"An abbreviated history of automation & industrial controls systems and cybersecurity"},{"key":"ref69","article-title":"Electricity for free? the dirty underbelly of SCADA and smart meters","author":"pollet","year":"0","journal-title":"Proc Black Hat USA"},{"key":"ref1","author":"stouffer","year":"2011","journal-title":"Guide to industrial control systems (ICS) security"},{"key":"ref109","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_7"},{"key":"ref95","author":"fratric","year":"2012","journal-title":"ROPGuard Runtime prevention of return-oriented programming attacks"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.51"},{"key":"ref94","article-title":"Control flow integrity for COTS binaries","author":"zhang","year":"0","journal-title":"Proc 22nd USENIX Security Symp"},{"key":"ref107","article-title":"HAFIX: Hardware-assisted flow integrity extension","author":"arias","year":"0","journal-title":"Proc 52nd Annu Design Autom Conf"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23156"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1145\/2593069.2596656"},{"key":"ref92","article-title":"Transparent ROP exploit mitigation using indirect branch tracing","author":"pappas","year":"0","journal-title":"Proc 22nd USENIX Security Symp"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1145\/1181309.1181316"},{"key":"ref91","article-title":"Compiler-based CFI for iOS","author":"pewny","year":"0","journal-title":"Proc 29th Annu Comput Security Appl Conf"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_19"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/1609956.1609960"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1145\/2463209.2488831"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_6"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1109\/HOTOS.1997.595185"},{"key":"ref112","year":"0","journal-title":"PaX address space layout randomization (ASLR)"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(93)90054-9"},{"key":"ref98","article-title":"Stitching the gadgets: On the ineffectiveness of coarse-grained control-flow integrity protection","author":"davi","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref99","article-title":"ROP is still dangerous: Breaking modern defenses","author":"carlini","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref96","article-title":"Practical control flow integrity & randomization for binary executables","author":"zhang","year":"0","journal-title":"Proc 34th IEEE Symp Security Privacy"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.43"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2010.175"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCST.2012.2211873"},{"key":"ref12","year":"0","journal-title":"What is a programmable logic controller (PLC)?"},{"key":"ref13","author":"scott","year":"0","journal-title":"What is a distributed control system (DCS)?"},{"key":"ref14","year":"2014","journal-title":"Cyperthreats to ICS systems"},{"key":"ref15","article-title":"Mouse click could plunge city into darkness, experts say","author":"meserve","year":"2007","journal-title":"CNN"},{"key":"ref118","article-title":"Gadge me if you can&#x2014;Secure and efficient ad-hoc instruction-level randomization for x86 and ARM","author":"davi","year":"0","journal-title":"Proc 8th ACM Symp Inf Comput Commun Security"},{"key":"ref16","year":"0","journal-title":"The Aurora attack"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-69100-6_24"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382216"},{"key":"ref17","author":"kushner","year":"2013","journal-title":"The Real Story of Stuxnet"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23043"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/2667190.2667192"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382244"},{"key":"ref119","article-title":"Efficient techniques for comprehensive protection from memory error exploits","author":"bhatkar","year":"0","journal-title":"Proc 14th USENIX Security Symp"},{"key":"ref19","author":"miller","year":"2015","journal-title":"Remote exploitation of an unaltered passenger vehicle"},{"key":"ref83","year":"2010","journal-title":"IMS research estimates top position for PROFINET"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-0977-9_4"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1145\/1900546.1900550"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.39"},{"key":"ref80","article-title":"On dynamic malware payloads aimed at programmable logic controllers","author":"mclaughlin","year":"0","journal-title":"Proc Usenix Workshop Hot Topics in Security"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.41"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2006.9"},{"key":"ref89","author":"matrosov","year":"2011","journal-title":"Stuxnet Under the Microscope"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.45"},{"key":"ref122","article-title":"Oxymoron: Making fine-grained memory randomization practical by allowing code sharing","author":"backes","year":"0","journal-title":"Proc 23rd USENIX Secur Symp"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660378"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653666"},{"key":"ref86","article-title":"False data injection attacks in control systems","author":"mo","year":"0","journal-title":"Proc 1st Workshop Secure Control Syst"},{"key":"ref87","article-title":"Smashing the stack for fun and profit","volume":"49","author":"one","year":"2000","journal-title":"Phrack Mag"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1145\/2133375.2133377"}],"container-title":["Proceedings of the IEEE"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/5\/7456363\/07434576.pdf?arnumber=7434576","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:40:16Z","timestamp":1642005616000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7434576\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,5]]},"references-count":144,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/jproc.2015.2512235","relation":{},"ISSN":["0018-9219","1558-2256"],"issn-type":[{"value":"0018-9219","type":"print"},{"value":"1558-2256","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,5]]}}}