{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:58:59Z","timestamp":1783184339893,"version":"3.54.6"},"reference-count":93,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2023,3,31]],"date-time":"2023-03-31T00:00:00Z","timestamp":1680220800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2023,3,31]]},"abstract":"<jats:p>Assurance techniques such as adversary-centric security testing are an essential part of the risk assessment process for improving risk mitigation and response capabilities against cyber attacks. While the use of these techniques, including vulnerability assessments, penetration tests, and red team engagements, is well established within Information Technology (IT) environments, there are challenges to conducting these within Operational Technology (OT) environments, often due to the critical nature of the OT system. In this article, we provide an analysis of the technical differences between IT and OT from an asset management perspective. This analysis provides a base for identifying how these differences affect the phases of adversary-centric security tests within industrial environments. We then evaluate these findings by using adversary-centric security testing techniques on an industrial control system testbed. Results from this work demonstrate that while legacy OT is highly susceptible to disruption during adversary-centric security testing, modern OT that uses better hardware and more optimised software is significantly more resilient to tools and techniques used for security testing. Clear requirements can, therefore, be identified for ensuring appropriate adversary-centric security testing within OT environments by quantifying the risks that the tools and techniques used during such engagements present to the operational process.<\/jats:p>","DOI":"10.1145\/3569958","type":"journal-article","created":{"date-parts":[[2023,2,9]],"date-time":"2023-02-09T13:44:40Z","timestamp":1675950280000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["An Analysis of Adversary-Centric Security Testing within Information and Operational Technology Environments"],"prefix":"10.1145","volume":"4","author":[{"given":"Alexander","family":"Staves","sequence":"first","affiliation":[{"name":"Lancaster University, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonios","family":"Gouglidis","sequence":"additional","affiliation":[{"name":"Lancaster University, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Hutchison","sequence":"additional","affiliation":[{"name":"Lancaster University, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,31]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/IEEESTD.2010.5518537"},{"key":"e_1_3_1_3_2","unstructured":"AboutSSL. History of the Internet\u2014An Invention That Changed the World. (June 2021). Retrieved June 30 2021 from https:\/\/aboutssl.org\/history-of-the-internet\/."},{"key":"e_1_3_1_4_2","volume-title":"SimaticScan: Towards A Specialised Vulnerability Scanner for Industrial Control Systems","author":"Antrobus Rob","year":"2016","unstructured":"Rob Antrobus, Sylvain Frey, Benjamin Green, and Awais Rashid. 2016. SimaticScan: Towards A Specialised Vulnerability Scanner for Industrial Control Systems. Technical Report."},{"key":"e_1_3_1_5_2","volume-title":"The Industrial Control System Cyber Kill Chain","author":"Assant Michael","year":"2015","unstructured":"Michael Assant and Robert Lee. 2015. The Industrial Control System Cyber Kill Chain. Technical Report. SANS Institute. Last Accessed: 03-21-2022."},{"key":"e_1_3_1_6_2","doi-asserted-by":"crossref","unstructured":"Liron Benbenishti. 2017. SCADA MODBUS Protocol Vulnerabilities. (September 2021). Retrieved September 15 2021 from https:\/\/bit.ly\/3nEeYy6.","DOI":"10.1155\/2021\/8887666"},{"key":"e_1_3_1_7_2","volume-title":"Hacking Exposed Industrial Control Systems: ICS and SCADA Security Secrets & Solutions","author":"Bodungen Clint","year":"2016","unstructured":"Clint Bodungen, Bryan Singer, Aaron Shbeeb, Kyle Wilhoit, and Stephen Hilt. 2016. Hacking Exposed Industrial Control Systems: ICS and SCADA Security Secrets & Solutions. McGraw Hill Professional."},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.5555\/2815510"},{"key":"e_1_3_1_9_2","unstructured":"Eric Byres and Mark Fabro. 2014. RISI - The Repository of Industrial Security Incidents. (November 2021). Retrieved November 01 2021 from https:\/\/www.risidata.com\/Database."},{"key":"e_1_3_1_10_2","unstructured":"Carnegie Mellon University. 2015. Network Security Protocols. Retrieved from https:\/\/bit.ly\/3qNnxX7. (2015)."},{"key":"e_1_3_1_11_2","unstructured":"Sanjay Chhillar. 2021. Common ICS Cybersecurity Myth 1: The Air Gap. (September 2021). Retrieved September 28 2021 from https:\/\/bit.ly\/39JCf9N."},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2016.331"},{"key":"e_1_3_1_13_2","unstructured":"CPNI. 2021. Critical National Infrastructure. (February 2022). Retrieved February 15 2022 from https:\/\/bit.ly\/3ueRgu6. (2021)."},{"key":"e_1_3_1_14_2","unstructured":"Department of Homeland Security. 2020. Emergency Directive 21-01. Retrieved from https:\/\/cyber.dhs.gov\/ed\/21-01\/. (2020). Last Accessed: 11-10-2021."},{"key":"e_1_3_1_15_2","unstructured":"Paul Didier Fernando Macias James Harstad Rick Antholine Scott A. Johnston Sabina Piyevsky Dan Zaniewski Steve Zuponcic Mark Schillace and Gregory Wilcox. 2011. Converged plantwide ethernet (cpwe) design and implementation guide. Technical Report. Rockwell Automation."},{"key":"e_1_3_1_16_2","volume-title":"Penetration Testing of Industrial Control Systems","author":"Duggan David P.","year":"2005","unstructured":"David P. Duggan. 2005. Penetration Testing of Industrial Control Systems. Technical Report. Last Accessed: 16-09-2021."},{"key":"e_1_3_1_17_2","unstructured":"EC-Council. 2021. Certified Ethical Hacker Certification. Retrieved from https:\/\/bit.ly\/3cK7t23. (2021). Last Accessed: 24-11-2021."},{"key":"e_1_3_1_18_2","unstructured":"ENISA. 2018. The NIS Directive. Retrieved from https:\/\/bit.ly\/3D0Bo27. (2018). Last Accessed: 15-06-2021."},{"key":"e_1_3_1_19_2","unstructured":"Barbara Filkins and Doug Wylie. 2019. SANS 2019 State of OT\/ICS Cybersecurity Survey. Retrieved from https:\/\/bit.ly\/3rP9amY. (2019)."},{"key":"e_1_3_1_20_2","unstructured":"Fortinet. n.d.. The CIA Triad. Retrieved from https:\/\/bit.ly\/3CDsEOK. Last Accessed: 01-11-21."},{"key":"e_1_3_1_21_2","unstructured":"Claire Gaving. 2014. Seasonal Variations in Electricity Demand. Retrieved from https:\/\/bit.ly\/3qustQv. (2014)."},{"key":"e_1_3_1_22_2","unstructured":"GIAC. 2021. GIAC Penetration Tester (GPEN). Retrieved from https:\/\/bit.ly\/3G00Rt9. (2021). Last Accessed: 24-11-2021."},{"key":"e_1_3_1_23_2","volume-title":"Security Assessment of the Internet Protocol","author":"Gont Fernando","year":"2008","unstructured":"Fernando Gont. 2008. Security Assessment of the Internet Protocol. Technical Report."},{"key":"e_1_3_1_24_2","unstructured":"Google. n.d. Google Code Archive: plcscan. Retrieved from https:\/\/bit.ly\/3tMnJHw. (N.D). Last Accessed: 16-09-2021."},{"key":"e_1_3_1_25_2","volume-title":"Proceedings of the 13th USENIX Workshop on Cyber Security Experimentation and Test (CSET 20)","author":"Green Benjamin","year":"2020","unstructured":"Benjamin Green, Richard Derbyshire, William Knowles, James Boorman, Pierre Ciholas, Daniel Prince, and David Hutchison. 2020. ICS testbed tetris: Practical building blocks towards a cyber security resource. In Proceedings of the 13th USENIX Workshop on Cyber Security Experimentation and Test (CSET 20)."},{"key":"e_1_3_1_26_2","article-title":"PCaaD: Towards automated determination and exploitation of industrial systems","author":"Green Benjamin","year":"2021","unstructured":"Benjamin Green, Richard Derbyshire, Marina Krotofil, William Knowles, Daniel Prince, and Neeraj Suri. 2021. PCaaD: Towards automated determination and exploitation of industrial systems. Computers & Security 110, 102424 (2021), 1\u201319.","journal-title":"Computers & Security"},{"key":"e_1_3_1_27_2","volume-title":"Proceedings of the10th USENIX Workshop on Cyber Security Experimentation and Test (CSET 17)","author":"Green Benjamin","year":"2017","unstructured":"Benjamin Green, Anhtuan Lee, Rob Antrobus, Utz Roedig, David Hutchison, and Awais Rashid. 2017. Pains, gains and PLCs: Ten lessons from building an industrial control systems testbed for security research. In Proceedings of the10th USENIX Workshop on Cyber Security Experimentation and Test (CSET 17)."},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3140241.3140251"},{"key":"e_1_3_1_29_2","unstructured":"guru99. (n.d.). Real-time operating system (RTOS): Components Types Examples. Retrieved from https:\/\/www.guru99.com\/real-time-operating-system.html. Last Accessed: 28-06-2021."},{"key":"e_1_3_1_30_2","doi-asserted-by":"crossref","DOI":"10.1002\/9781119070740","volume-title":"Building an Effective Security Program for Distributed Energy Resources and Systems","author":"Hentea Mariana","year":"2021","unstructured":"Mariana Hentea. 2021. Building an Effective Security Program for Distributed Energy Resources and Systems. John Wiley & Sons Inc."},{"key":"e_1_3_1_31_2","volume-title":"Intelligence-Driven Computer Network Defense and Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains","author":"Hutchins Eric","unstructured":"Eric Hutchins, Michael Cloppert, and Rohan Amin. Intelligence-Driven Computer Network Defense and Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains. Technical Report. Lockheed Martin. Retrieved from https:\/\/www.lockheedmartin.com\/content\/dam\/lockheed-martin\/rms\/documents\/cyber\/LM-White-Paper-Intel-Driven-Defense.pdf."},{"key":"e_1_3_1_32_2","volume-title":"BS IEC 62443-2-1:2011","year":"2011","unstructured":"IEC. 2011. BS IEC 62443-2-1:2011. Technical Report."},{"key":"e_1_3_1_33_2","volume-title":"IEC 61131-3:2013","year":"2013","unstructured":"IEC. 2013. IEC 61131-3:2013. Technical Report."},{"key":"e_1_3_1_34_2","volume-title":"BS EN IEC 62443-4-2:2019","year":"2019","unstructured":"IEC. 2019. BS EN IEC 62443-4-2:2019. Technical Report."},{"key":"e_1_3_1_35_2","article-title":"ISA Courses","author":"Automation International Society of","year":"2021","unstructured":"International Society of Automation. 2021. ISA Courses. Retrieved from https:\/\/www.isa.org\/store. (2021). Last Accessed: 24-11-2021.","journal-title":"https:\/\/www.isa.org\/store"},{"key":"e_1_3_1_36_2","article-title":"Overview of Penetration Testing for Industrial Control Systems (IC38C)","author":"Automation International Society of","year":"2021","unstructured":"International Society of Automation. 2021. Overview of Penetration Testing for Industrial Control Systems (IC38C). Retrieved from https:\/\/bit.ly\/2ZhvhqO. (2021). Last Accessed: 24-11-2021.","journal-title":"https:\/\/bit.ly\/2ZhvhqO"},{"key":"e_1_3_1_37_2","unstructured":"ISO\/IEC. 2017. BS EN ISO\/IEC 27001:2017. (2017)."},{"key":"e_1_3_1_38_2","unstructured":"ISO\/IEC. 2017. BS EN ISO\/IEC 27002:2017. (2017)."},{"key":"e_1_3_1_39_2","unstructured":"ISO\/IEC. 2017. BS EN ISO\/IEC 27019:2017. (2017)."},{"key":"e_1_3_1_40_2","article-title":"Pompeo Says Russia \u201cPretty Clearly\u201d Behind Cyberattack on US, but Trump Casts Doubts and Downplays Threat","author":"Jornson Kevin","year":"2020","unstructured":"Kevin Jornson and Mike Snider. 2020. Pompeo Says Russia \u201cPretty Clearly\u201d Behind Cyberattack on US, but Trump Casts Doubts and Downplays Threat. Retrieved from https:\/\/bit.ly\/2YGFg8k. (2020). Last Accessed: 11-10-2021.","journal-title":"https:\/\/bit.ly\/2YGFg8k"},{"key":"e_1_3_1_41_2","article-title":"The Social Engineer Toolkit","author":"Kennedy David","year":"2020","unstructured":"David Kennedy. 2020. The Social Engineer Toolkit. Retrieved from https:\/\/bit.ly\/3CsnGDR. (2020). Last Accessed: 20-09-2021.","journal-title":"https:\/\/bit.ly\/3CsnGDR"},{"key":"e_1_3_1_42_2","volume-title":"Industrial Network Security","author":"Knapp Eric D.","year":"2015","unstructured":"Eric D. Knapp and Joel Thomas Langill. 2015. Industrial Network Security. Elsevier Ltd."},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/2808705.2808710"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.67"},{"key":"e_1_3_1_45_2","article-title":"German steel mill cyber attack","author":"Lee Robert M.","year":"2014","unstructured":"Robert M. Lee, Michael J. Assante, and Tim Conway. 2014. German steel mill cyber attack. Industrial Control Systems 30, 62 (2014), 1\u201315.","journal-title":"Industrial Control Systems"},{"key":"e_1_3_1_46_2","article-title":"Nmap: the Network Mapper","author":"Lyon Gordon","year":"1997","unstructured":"Gordon Lyon. 1997. Nmap: the Network Mapper. Retrieved from https:\/\/nmap.org\/. (1997). Last Accessed: 15-09-2021.","journal-title":"https:\/\/nmap.org\/"},{"key":"e_1_3_1_47_2","article-title":"Shodan Search Engine","author":"Matherly John","year":"2009","unstructured":"John Matherly. 2009. Shodan Search Engine. Retrieved from https:\/\/www.shodan.io\/. (2009). Last Accessed: 15-09-2021.","journal-title":"https:\/\/www.shodan.io\/"},{"key":"e_1_3_1_48_2","article-title":"Windows Comprehensive Security","unstructured":"Microsoft. (n.d.). Windows Comprehensive Security. Retrieved from https:\/\/bit.ly\/3qnouGx. Last Accessed: 26-06-2021.","journal-title":"https:\/\/bit.ly\/3qnouGx"},{"key":"e_1_3_1_49_2","article-title":"Windows Server","unstructured":"Microsoft. (n.d.). Windows Server. Retrieved from https:\/\/bit.ly\/3CXOspc. Last Accessed: 26-06-2021.","journal-title":"https:\/\/bit.ly\/3CXOspc"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2021.100464"},{"key":"e_1_3_1_51_2","article-title":"Siemens S7 Communication - Part 1 General Structure","author":"Miru Gyorgy","year":"2017","unstructured":"Gyorgy Miru. 2017. Siemens S7 Communication - Part 1 General Structure. Retrieved from http:\/\/gmiru.com\/article\/s7comm\/. (2017). Last Accessed: 08-07-2021.","journal-title":"http:\/\/gmiru.com\/article\/s7comm\/"},{"key":"e_1_3_1_52_2","article-title":"ATT&CK for Industrial Control Systems","year":"2020","unstructured":"MITRE. 2020. ATT&CK for Industrial Control Systems. Retrieved fromhttps:\/\/collaborate.mitre.org\/attackics\/index.php\/Main_Page. (2020).","journal-title":"https:\/\/collaborate.mitre.org\/attackics\/index.php\/Main_Page"},{"key":"e_1_3_1_53_2","article-title":"ATT&CK Matrix for Enterprise","year":"2021","unstructured":"MITRE. 2021. ATT&CK Matrix for Enterprise. Retrieved from https:\/\/attack.mitre.org\/. (2021). Last Accessed: 22-12-2021.","journal-title":"https:\/\/attack.mitre.org\/"},{"key":"e_1_3_1_54_2","article-title":"MITRE Common Vulnerability and Exposures","year":"2021","unstructured":"MITRE. 2021. MITRE Common Vulnerability and Exposures. Retrieved from https:\/\/cve.mitre.org\/. (2021). Last Accessed: 21-09-2021.","journal-title":"https:\/\/cve.mitre.org\/"},{"key":"e_1_3_1_55_2","unstructured":"MITRE. 2022. Adversary Emulation Plans. (2022). Retrieved from https:\/\/attack.mitre.org\/resources\/adversary-emulation-plans. Last Accessed: 24-09-2022."},{"key":"e_1_3_1_56_2","volume-title":"MELSEC Communication Protocol Reference Manual","author":"Electric Mitsubishi","unstructured":"Mitsubishi Electric. MELSEC Communication Protocol Reference Manual. Technical Report. Last Accessed: 08-07-2021."},{"key":"e_1_3_1_57_2","unstructured":"Gordon E. Moore et\u00a0al. 1965. Cramming more components onto integrated circuits. Electronics 38 8 (1965) 1\u20134."},{"key":"e_1_3_1_58_2","unstructured":"Glenn Murray Michael N. Johnstone and Craig Valli. 2017. The convergence of IT and OT in critical infrastructure."},{"key":"e_1_3_1_59_2","article-title":"NCSC CAF Guidance","author":"Centre National Cyber Security","year":"2021","unstructured":"National Cyber Security Centre. 2021. NCSC CAF Guidance. Retrieved from https:\/\/www.ncsc.gov.uk\/collection\/caf. (2021). Last Accessed: 15-06-2021.","journal-title":"https:\/\/www.ncsc.gov.uk\/collection\/caf"},{"key":"e_1_3_1_60_2","volume-title":"Framework for Improving Critical Infrastructure Cybersecurity","author":"Technology National Institute of Standards and","year":"2018","unstructured":"National Institute of Standards and Technology. 2018. Framework for Improving Critical Infrastructure Cybersecurity. Technical Report."},{"key":"e_1_3_1_61_2","volume-title":"NIST Special Publication 1800-5","author":"Technology National Institute of Standards and","year":"2018","unstructured":"National Institute of Standards and Technology. 2018. NIST Special Publication 1800-5. Technical Report."},{"key":"e_1_3_1_62_2","article-title":"CHECK - Penetration Testing","year":"2019","unstructured":"NCSC. 2019. CHECK - Penetration Testing. Retrieved from https:\/\/bit.ly\/3xfOIx0. (2019).","journal-title":"https:\/\/bit.ly\/3xfOIx0"},{"key":"e_1_3_1_63_2","article-title":"W32.Stuxnet Dossier Version 1.3","author":"Nicolas Falliere","year":"2010","unstructured":"Falliere Nicolas, Liam Murchu, and Eric Chien. 2010. W32.Stuxnet Dossier Version 1.3. Retrieved from https:\/\/bit.ly\/3aqefqg. (2010). Last Accessed: 14-06-2021.","journal-title":"https:\/\/bit.ly\/3aqefqg"},{"key":"e_1_3_1_64_2","article-title":"The National Vulnerability Database","year":"2021","unstructured":"NIST. 2021. The National Vulnerability Database. Retrieved from https:\/\/nvd.nist.gov\/. (2021). Last Accessed: 21-09-2021.","journal-title":"https:\/\/nvd.nist.gov\/"},{"key":"e_1_3_1_65_2","volume-title":"ODVA Specifications","unstructured":"ODVA. ODVA Specifications. Technical Report. Last Accessed: 08-07-2021."},{"key":"e_1_3_1_66_2","unstructured":"Offensive Security. 2021. Courses and Certifications. (2021). Retrieved from https:\/\/www.offensive-security.com\/courses-and-certifications. Last Accessed: 14-06-2021."},{"key":"e_1_3_1_67_2","article-title":"Introduction to PLCs and Ladder Logic","unstructured":"PenTestPartners. (n.d.). Introduction to PLCs and Ladder Logic. Retrieved from https:\/\/bit.ly\/3hoxXIv. Last Accessed: 26-06-2021.","journal-title":"https:\/\/bit.ly\/3hoxXIv"},{"key":"e_1_3_1_68_2","article-title":"Snakes and Ladder Logic","unstructured":"PenTestPartners. (n.d.). Snakes and Ladder Logic. Retrieved from https:\/\/bit.ly\/2U3sz5x. Last Accessed: 26-06-2021.","journal-title":"https:\/\/bit.ly\/2U3sz5x"},{"key":"e_1_3_1_69_2","article-title":"The Metasploit Framework","year":"2003","unstructured":"Rapid7. 2003. The Metasploit Framework. Retrieved from https:\/\/bit.ly\/3AFSVdW. (2003). Last Accessed: 21-09-2021.","journal-title":"https:\/\/bit.ly\/3AFSVdW"},{"key":"e_1_3_1_70_2","article-title":"\u201cDangerous Stuff\u201d: Hackers Tried to Poison Water Supply of Florida Town","author":"Robles Frances","year":"2021","unstructured":"Frances Robles and Nicole Perlroth. 2021. \u201cDangerous Stuff\u201d: Hackers Tried to Poison Water Supply of Florida Town. Retrieved from https:\/\/nyti.ms\/38PzNye. (2021). Last Accessed: 15-06-2021.","journal-title":"https:\/\/nyti.ms\/38PzNye"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2202.01604"},{"key":"e_1_3_1_72_2","article-title":"Network Security Reference Architecture","author":"Samonte Alex","unstructured":"Alex Samonte. (n.d.). Network Security Reference Architecture. Retrieved from https:\/\/bit.ly\/3Ahn5o7. Last Accessed: 30-06-2021.","journal-title":"https:\/\/bit.ly\/3Ahn5o7"},{"key":"e_1_3_1_73_2","article-title":"Assessing and Exploiting Control Systems","author":"Institute SANS","year":"2021","unstructured":"SANS Institute. 2021. Assessing and Exploiting Control Systems. Retrieved from https:\/\/bit.ly\/3oVGhTM. (2021). Last Accessed: 24-11-2021.","journal-title":"https:\/\/bit.ly\/3oVGhTM"},{"key":"e_1_3_1_74_2","article-title":"Cybersecurity Courses & Certifications","author":"Institute SANS","year":"2021","unstructured":"SANS Institute. 2021. Cybersecurity Courses & Certifications. Retrieved from https:\/\/bit.ly\/3nLLZYQ. (2021). Last Accessed: 24-11-2021.","journal-title":"https:\/\/bit.ly\/3nLLZYQ"},{"key":"e_1_3_1_75_2","article-title":"Control Things I\/O","author":"Searle Justine","year":"2021","unstructured":"Justine Searle. 2021. Control Things I\/O. Retrieved from https:\/\/www.controlthings.io\/home. (2021). Last Accessed: 27-06-2022.","journal-title":"https:\/\/www.controlthings.io\/home"},{"key":"e_1_3_1_76_2","article-title":"Kali Linux","author":"Security Offensive","year":"2022","unstructured":"Offensive Security. 2022. Kali Linux. Retrieved from https:\/\/www.kali.org\/. (2022). Last Accessed: 25-09-2022.","journal-title":"https:\/\/www.kali.org\/"},{"key":"e_1_3_1_77_2","unstructured":"Chris Sherry. 2020. Advantages and Disadvantages of Active vs. Passive Scanning in IT and OT Environments. (2020). Retrieved from https:\/\/bit.ly\/3trOgL. Last Accessed: 14-06-2021."},{"key":"e_1_3_1_78_2","unstructured":"Siemens. 2020. SIMATIC S7-300 - Proven Multiple Times! (2020). Retrieved from https:\/\/sie.ag\/3ol428k."},{"key":"e_1_3_1_79_2","article-title":"SIMATIC S7-1200 CPU 1212C - Data Sheet","year":"2022","unstructured":"Siemens. 2022. SIMATIC S7-1200 CPU 1212C - Data Sheet. Retrieved from https:\/\/sie.ag\/3MSWnIX. (2022). Last Accessed: 16-03-2022.","journal-title":"https:\/\/sie.ag\/3MSWnIX"},{"key":"e_1_3_1_80_2","article-title":"Destruction and Integrity Cyber Attacks on the Rise","author":"Skelton Sebastian Klovig","year":"2021","unstructured":"Sebastian Klovig Skelton. 2021. Destruction and Integrity Cyber Attacks on the Rise. Retrieved from https:\/\/bit.ly\/3ByOrWn. (2021). Last Accessed: 01-11-21.","journal-title":"https:\/\/bit.ly\/3ByOrWn"},{"key":"e_1_3_1_81_2","unstructured":"William Smart. 2018. Lessons Learned Review of the WannaCry Ransomware Cyber Attack. Retrieved from https:\/\/bit.ly\/2UIg1AL. (2018)."},{"key":"e_1_3_1_82_2","doi-asserted-by":"publisher","DOI":"10.5516\/NET.04.2011.065"},{"key":"e_1_3_1_83_2","article-title":"Network Security Architecture","author":"Spisak Mike","unstructured":"Mike Spisak and James Darwin. (n.d.). Network Security Architecture. Retrieved from https:\/\/ibm.co\/3hBztHl. Last Accessed: 30-06-2021.","journal-title":"https:\/\/ibm.co\/3hBztHl"},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2021.100505"},{"key":"e_1_3_1_85_2","article-title":"Nessus Vulnerability Scanner","year":"2021","unstructured":"Tenable. 2021. Nessus Vulnerability Scanner. Retrieved from https:\/\/bit.ly\/399yave. (2021). Last Accessed: 16-09-2021.","journal-title":"https:\/\/bit.ly\/399yave"},{"key":"e_1_3_1_86_2","article-title":"Regulation (EU) 2016\/679","author":"Council The European Parliament and","year":"2016","unstructured":"The European Parliament and Council. 2016. Regulation (EU) 2016\/679. Retrieved from https:\/\/bit.ly\/3bsAIpB. (2016). Last Accessed: 01-11-21.","journal-title":"https:\/\/bit.ly\/3bsAIpB"},{"key":"e_1_3_1_87_2","article-title":"British Airways Fined 20m Pounds Sterling over Data Breach","author":"Tidy Joe","year":"2020","unstructured":"Joe Tidy. 2020. British Airways Fined 20m Pounds Sterling over Data Breach. Retrieved from https:\/\/bbc.in\/3pRTejv. (2020). Last Accessed: 01-11-21.","journal-title":"https:\/\/bbc.in\/3pRTejv"},{"key":"e_1_3_1_88_2","unstructured":"Joe Tidy. 2021. Colonial Hack: How Did Cyber-Attackers Shut Off Pipeline? Retrieved from https:\/\/bbc.in\/3tClpod. (2021). Last Accessed: 15-06-2021."},{"key":"e_1_3_1_89_2","article-title":"Cybersecurity Guidance is Available, but More Can Be Done to Promote Its Use","author":"Office United States Government Accountability","year":"2011","unstructured":"United States Government Accountability Office. 2011. Cybersecurity Guidance is Available, but More Can Be Done to Promote Its Use. Retrieved from https:\/\/www.gao.gov\/assets\/gao-12-92.pdf. (2011).","journal-title":"https:\/\/www.gao.gov\/assets\/gao-12-92.pdf"},{"key":"e_1_3_1_90_2","article-title":"S.1353 - Cybersecurity Enhancement Act of 2014","author":"Office U.S Government Publishing","year":"2014","unstructured":"U.S Government Publishing Office. 2014. S.1353 - Cybersecurity Enhancement Act of 2014. Retrieved from https:\/\/bit.ly\/35JFUm3. (2014).","journal-title":"https:\/\/bit.ly\/35JFUm3"},{"key":"e_1_3_1_91_2","article-title":"Industrial Protocols Cheat Sheet v1.0","author":"Weber Don C.","year":"2021","unstructured":"Don C. Weber and Just Searle. 2021. Industrial Protocols Cheat Sheet v1.0. Retrieved from https:\/\/bit.ly\/3IAHPKM. (2021). Last Accessed: 08-07-2021.","journal-title":"https:\/\/bit.ly\/3IAHPKM"},{"key":"e_1_3_1_92_2","article-title":"Governance of Enterprise Security: CyLab 2021 Report","author":"Westby Jody R.","year":"2012","unstructured":"Jody R. Westby. 2012. Governance of Enterprise Security: CyLab 2021 Report. Retrieved from https:\/\/bit.ly\/3BdDefs. (2012).","journal-title":"https:\/\/bit.ly\/3BdDefs"},{"key":"e_1_3_1_93_2","unstructured":"Weider D. Yu Dipti Baheti and Jeremy Wai. 2010. Real-Time Operating System Security. Technical Report. San Jose State University."},{"key":"e_1_3_1_94_2","article-title":"SolarWinds, Probably Hacked by Russia, Serves White House, Pentagon, NASA","author":"Zhao Christina","year":"2020","unstructured":"Christina Zhao. 2020. SolarWinds, Probably Hacked by Russia, Serves White House, Pentagon, NASA. Retrieved from https:\/\/bit.ly\/3FB5U3H. (2020). Last Accessed: 11-10-2021.","journal-title":"https:\/\/bit.ly\/3FB5U3H"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3569958","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3569958","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:19Z","timestamp":1750182559000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3569958"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,31]]},"references-count":93,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2023,3,31]]}},"alternative-id":["10.1145\/3569958"],"URL":"https:\/\/doi.org\/10.1145\/3569958","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,31]]},"assertion":[{"value":"2022-04-05","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-10-25","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-31","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}