{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T18:39:48Z","timestamp":1784918388401,"version":"3.55.0"},"reference-count":163,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,4,19]],"date-time":"2023-04-19T00:00:00Z","timestamp":1681862400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Cyber-Phys. Syst."],"published-print":{"date-parts":[[2023,4,30]]},"abstract":"<jats:p>Numerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs\u2019 by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken.<\/jats:p>","DOI":"10.1145\/3587255","type":"journal-article","created":{"date-parts":[[2023,3,14]],"date-time":"2023-03-14T12:10:27Z","timestamp":1678795827000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":65,"title":["Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security Perspective"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7809-3796","authenticated-orcid":false,"given":"Mohammed","family":"Asiri","sequence":"first","affiliation":[{"name":"Cardiff University, Cardiff, Cardiff, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6437-0807","authenticated-orcid":false,"given":"Neetesh","family":"Saxena","sequence":"additional","affiliation":[{"name":"Cardiff University, Cardiff, Cardiff, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-3715-077X","authenticated-orcid":false,"given":"Rigel","family":"Gjomemo","sequence":"additional","affiliation":[{"name":"University of Illinois at Chicago, Chicago, Illinois, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0396-633X","authenticated-orcid":false,"given":"Pete","family":"Burnap","sequence":"additional","affiliation":[{"name":"Cardiff University, Cardiff, Cardiff, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,19]]},"reference":[{"key":"e_1_3_1_2_2","volume-title":"Malicious Control System Cyber Security Attack Case Study-Maroochy Water Services, Australia","author":"Abrams Marshall","year":"2008","unstructured":"Marshall Abrams and Joe Weiss. 2008. Malicious Control System Cyber Security Attack Case Study-Maroochy Water Services, Australia. Technical Report. The MITRE Corporation, McLean, VA."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2012.325"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.4251102"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40294-020-00070-w"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/WoWMoM.2019.8792986"},{"key":"e_1_3_1_7_2","article-title":"MITRE ATT&CK for Industrial Control Systems: Design and Philosophy","author":"Alexander Otis","year":"2020","unstructured":"Otis Alexander, Misha Belisle, and Jacob Steele. 2020. MITRE ATT&CK for Industrial Control Systems: Design and Philosophy. The MITRE Corporation, McLean, VA.","journal-title":"The MITRE Corporation, McLean, VA"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCNT51525.2021.9579611"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.03.007"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2891891"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-26601-1_9"},{"key":"e_1_3_1_12_2","unstructured":"Andrew Ginter. 2019. The Top 20 Cyberattacks on Industrial Control Systems . Waterfall Security Solutions LTD Englewood Cliffs NJ. https:\/\/waterfall-security.com\/20-attacks\/."},{"key":"e_1_3_1_13_2","article-title":"Investigating usable indicators against cyber-attacks in industrial control systems","author":"Asiri Mohammed","year":"2021","unstructured":"Mohammed Asiri, Neetesh Saxena, and Peter Burnap. 2021. Investigating usable indicators against cyber-attacks in industrial control systems. In Proceedings of the 17th Symposium on Usable Privacy and Security (SOUPS\u201921) (2021).","journal-title":"Proceedings of the 17th Symposium on Usable Privacy and Security (SOUPS\u201921)"},{"key":"e_1_3_1_14_2","unstructured":"Michael J. Assante and Robert M. Lee. 2015. The Industrial Control System Cyber Kill Chain . SANS Institute InfoSec Reading Room North Bethesda MD. https:\/\/www.sans.org\/white-papers\/36297\/."},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/SoutheastCon45413.2021.9401809"},{"key":"e_1_3_1_16_2","unstructured":"Cyber Security Benchmark Process Automation. 2021. Retrieved February 2 2022 from https:\/\/new.abb.com\/process-automation\/process-automation-service\/advanced-digital-services\/cyber-security\/collaborative-operations."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3295453.3295454"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3355300"},{"key":"e_1_3_1_19_2","first-page":"1","article-title":"Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (STIX)","volume":"11","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum. 2012. Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (STIX). The MITRE Corporation, 11, 1\u201322.","journal-title":"The MITRE Corporation"},{"key":"e_1_3_1_20_2","article-title":"The Cybox Language Specification","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum, Robert Martin, Bryan Worrell, and Ivan Kirillov. 2012. The Cybox Language Specification. The MITRE Corporation.","journal-title":"The MITRE Corporation"},{"key":"e_1_3_1_21_2","article-title":"Mcafee Labs Threats Report: August 2019","author":"Beek C.","year":"2019","unstructured":"C. Beek, T. Dunton, J. Fokker, S. Grobman, T. Hux, T. Polzer, M. Rivero, T. Roccia, J. Saavedra-Morales, R. Samani, et\u00a0al. 2019. Mcafee Labs Threats Report: August 2019. McAfee Labs.","journal-title":"McAfee Labs"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.3390\/fi4040971"},{"key":"e_1_3_1_23_2","unstructured":"David Bianco. 2013. The pyramid of pain. http:\/\/detect-respond.blogspot.com\/2013\/03\/the-pyramid-of-pain.html. Accessed March 29 2023."},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/NAECON46414.2019.9057860"},{"key":"e_1_3_1_25_2","volume-title":"Preprints of the First Workshop on Secure Control Systems (CPSWEEK\u201910)","author":"Bobba Rakesh B.","year":"2010","unstructured":"Rakesh B. Bobba, Katherine M. Rogers, Qiyan Wang, Himanshu Khurana, Klara Nahrstedt, and Thomas J. Overbye. 2010. Detecting false data injection attacks on dc state estimation. In Preprints of the First Workshop on Secure Control Systems (CPSWEEK\u201910), Vol. 2010."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10209-016-0473-0"},{"key":"e_1_3_1_27_2","volume-title":"A SANS 2021 Survey: OT\/ICS Cybersecurity","author":"Bristow Mark","year":"2021","unstructured":"Mark Bristow. 2021. A SANS 2021 Survey: OT\/ICS Cybersecurity. Technical Report."},{"key":"e_1_3_1_28_2","unstructured":"Scott Steele Buchanan. 2022. Cyber-attacks to industrial control systems since stuxnet: A systematic review. (2022)."},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/2663876.2663883"},{"key":"e_1_3_1_30_2","article-title":"Industrial Control Threat Intelligence","author":"Caltagirone Sergio","year":"2017","unstructured":"Sergio Caltagirone. 2017. Industrial Control Threat Intelligence. Dragos Threat Intelligence Whitepaper.","journal-title":"Dragos Threat Intelligence Whitepaper"},{"key":"e_1_3_1_31_2","volume-title":"Development of a Tailored Methodology and Forensic Toolkit for Industrial Control Systems Incident Response","author":"Carr Nicholas B.","year":"2014","unstructured":"Nicholas B. Carr. 2014. Development of a Tailored Methodology and Forensic Toolkit for Industrial Control Systems Incident Response. Technical Report. Naval Postgraduate School, Monterey, CA."},{"key":"e_1_3_1_32_2","article-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid","volume":"388","author":"Case Defense Use","year":"2016","unstructured":"Defense Use Case. 2016. Analysis of the Cyber Attack on the Ukrainian Power Grid. Electricity Information Sharing and Analysis Center, 388.","journal-title":"Electricity Information Sharing and Analysis Center,"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-75462-8_16"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/2872427.2883056"},{"key":"e_1_3_1_35_2","unstructured":"The Only Managed OT\/ICS Security Platform Verve Security Center. 2021. Retrieved Feburary 3 2022 from https:\/\/verveindustrial.com\/verve-security-center\/."},{"key":"e_1_3_1_36_2","unstructured":"Mike Cloppert. 2009. Security intelligence: Attacking the cyber kill chain. https:\/\/www.sans.org\/blog\/security-intelligence-attacking-the-cyber-kill-chain\/. Accessed March 29 2023."},{"key":"e_1_3_1_37_2","first-page":"1","article-title":"The Trusted Automated Exchange of Indicator Information (TAXII)","author":"Connolly Julie","year":"2014","unstructured":"Julie Connolly, Mark Davidson, and Charles Schmidt. 2014. The Trusted Automated Exchange of Indicator Information (TAXII). The MITRE Corporation, 1\u201320.","journal-title":"The MITRE Corporation"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.07.009"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.2172\/944209"},{"key":"e_1_3_1_40_2","unstructured":"Home AT&T Cybersecurity. 2021. Retrieved Feburary 3 2022 from https:\/\/cybersecurity.att.com\/products\/ossim."},{"key":"e_1_3_1_41_2","article-title":"The Incident Object Description Exchange Format (IODEF)","author":"Danyliw Roman","year":"2007","unstructured":"Roman Danyliw, Jan Meijer, and Yuri Demchenko. 2007. The Incident Object Description Exchange Format (IODEF). Internet Engineering Task Force, RFC-5070.","journal-title":"Internet Engineering Task Force, RFC-5070"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2013.6578789"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.005"},{"key":"e_1_3_1_44_2","volume-title":"Defcon 15 Hacking Conference","author":"Devarajan Ganesh","year":"2007","unstructured":"Ganesh Devarajan. 2007. Unraveling SCADA protocols: Using sulley fuzzer. In Defcon 15 Hacking Conference."},{"key":"e_1_3_1_45_2","first-page":"1","volume-title":"Proceeding of the Black Hat USA Conference","volume":"2018","author":"Pinto Alessandro Di","year":"2018","unstructured":"Alessandro Di Pinto, Younes Dragoni, and Andrea Carcano. 2018. TRITON: The first ICS cyber attack on safety instrument systems. In Proceeding of the Black Hat USA Conference, Vol. 2018. 1\u201326."},{"key":"e_1_3_1_46_2","unstructured":"Threat Detection Dragos. 2021. Retrieved Feburary 3 2022 from https:\/\/www.dragos.com\/platform\/threat-detection\/."},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/ETFA.2019.8869197"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICS2016.16"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-50660-9_4"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-32125-7_6"},{"key":"e_1_3_1_51_2","unstructured":"Nicolas Falliere Liam O. Murchu and Eric Chien. 2011. W32. Stuxnet Dossier . Symantec Corp. Security Response Cupertino CA."},{"key":"e_1_3_1_52_2","article-title":"Tools and Standards for Cyber Threat Intelligence Projects","author":"Farnham Greg","year":"2013","unstructured":"Greg Farnham and Kees Leune. 2013. Tools and Standards for Cyber Threat Intelligence Projects. SANS Institute.","journal-title":"SANS Institute"},{"key":"e_1_3_1_53_2","unstructured":"IOC Editor: Free Security Software FireEye. 2021. Retrieved Feburary 3 2022 from https:\/\/www.fireeye.com\/services\/freeware\/ioc-editor.html."},{"key":"e_1_3_1_54_2","unstructured":"IOC Finder: Free Security Software FireEye. 2021. Retrieved Feburary 3 2022 from https:\/\/www.fireeye.com\/services\/freeware\/ioc-finder.html."},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2021.100487"},{"key":"e_1_3_1_56_2","article-title":"Forensic Analysis of Industrial Control Systems","author":"Folkerth Lew","year":"2015","unstructured":"Lew Folkerth. 2015. Forensic Analysis of Industrial Control Systems. Technical Report. SANS Institute InfoSec Reading Room.","journal-title":"SANS Institute InfoSec Reading Room"},{"key":"e_1_3_1_57_2","unstructured":"eyeInspect\u2013Device Visibility for OT Networks Forescout. 2021. Retrieved Feburary 3 2022 from https:\/\/www.forescout.com\/products\/eyeinspect\/."},{"issue":"1","key":"e_1_3_1_58_2","first-page":"3","article-title":"On cyber attacks and signature based intrusion detection for modbus based industrial control systems","volume":"9","author":"Gao Wei","year":"2014","unstructured":"Wei Gao and Thomas H. Morris. 2014. On cyber attacks and signature based intrusion detection for modbus based industrial control systems. J. Digit. Forens. Secur. Law 9, 1 (2014), 3.","journal-title":"J. Digit. Forens. Secur. Law"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37228-6_12"},{"key":"e_1_3_1_60_2","unstructured":"Andrew Ginter. 2017. The Top 20 Cyberattacks on Industrial Control Systems. Waterfall Security Solutions."},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101955"},{"key":"e_1_3_1_62_2","first-page":"110","volume-title":"Computer Security","author":"Govil Naman","year":"2017","unstructured":"Naman Govil, Anand Agrawal, and Nils Ole Tippenhauer. 2017. On ladder logic bombs in industrial control systems. In Computer Security. Springer, 110\u2013126."},{"key":"e_1_3_1_63_2","volume-title":"Analyzing Network Traffic with Basic Linux Tools","author":"Green T.","year":"2012","unstructured":"T. Green and R. VandenBrink. 2012. Analyzing Network Traffic with Basic Linux Tools. Technical Report. SANS Institute InfoSec Reading Room."},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-5165-2_9"},{"key":"e_1_3_1_65_2","unstructured":"Mohammad Hadi Sultani and Lu Han. 2019. Indicators of compromise of vehicular systems."},{"key":"e_1_3_1_66_2","doi-asserted-by":"crossref","unstructured":"Amin Hassanzadeh Amin Rasekh Stefano Galelli Mohsen Aghashahi Riccardo Taormina Avi Ostfeld and Katherine M. Banks. 2020. A review of cybersecurity incidents in the water sector. Journal of Environmental Engineering 146 5 (2020) 03120003.","DOI":"10.1061\/(ASCE)EE.1943-7870.0001686"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.2172\/1505628"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1177\/1550147718794615"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.2172\/1376870"},{"issue":"1","key":"e_1_3_1_70_2","first-page":"80","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","volume":"1","author":"Hutchins Eric M.","year":"2011","unstructured":"Eric M. Hutchins, Michael J. Cloppert, Rohan M. Amin, et\u00a0al. 2011. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lead. Issues Inf. Warf. Secur. Res. 1, 1 (2011), 80.","journal-title":"Lead. Issues Inf. Warf. Secur. Res."},{"key":"e_1_3_1_71_2","volume-title":"Collecting Cyberattack Data for Industrial Control Systems Using Honeypots","author":"Hyun Dahae","year":"2018","unstructured":"Dahae Hyun. 2018. Collecting Cyberattack Data for Industrial Control Systems Using Honeypots. Ph. D. Dissertation. Naval Postgraduate School, Monterey, CA."},{"issue":"4","key":"e_1_3_1_72_2","article-title":"Security challenges of industrial communication protocols: Threats vulnerabilities and solutions","volume":"10","author":"Imtiaz Khalid","year":"2019","unstructured":"Khalid Imtiaz and M. Junaid Arshad. 2019. Security challenges of industrial communication protocols: Threats vulnerabilities and solutions. Int. J. Comput. Sci. Telecommun. 10, 4 (2019).","journal-title":"Int. J. Comput. Sci. Telecommun."},{"key":"e_1_3_1_73_2","doi-asserted-by":"crossref","unstructured":"Ponemon Institute. 2021. Cost of a Data Breach Report 2021.","DOI":"10.1016\/S1361-3723(21)00082-8"},{"key":"e_1_3_1_74_2","unstructured":"OASIS Cyber Threat Intelligence Technical Committee et\u00a0al. 2017. Structured Threat Information eXpression (STIX)."},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8258360"},{"issue":"150","key":"e_1_3_1_76_2","article-title":"Guide to cyber threat information sharing","volume":"800","author":"Johnson Chris","year":"2016","unstructured":"Chris Johnson, Lee Badger, David Waltermire, Julie Snyder, and Clem Skorupka. 2016. Guide to cyber threat information sharing. NIST Spec. Publ. 800, 150 (2016).","journal-title":"NIST Spec. Publ."},{"key":"e_1_3_1_77_2","doi-asserted-by":"crossref","unstructured":"T. Takahashi K. Landfield and Y. Kadobayashi. 2014. An Incident Object Description Exchange Format (iodef) Extension for Structured Cybersecurity Information . Internet Engineering Task Force (IETF) RFC-7203 Wilmington DC.","DOI":"10.17487\/rfc7203"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.99"},{"issue":"14","key":"e_1_3_1_79_2","article-title":"Guide to integrating forensic techniques into incident response","volume":"10","author":"Kent Karen","year":"2006","unstructured":"Karen Kent, Suzanne Chevalier, Tim Grance, and Hung Dang. 2006. Guide to integrating forensic techniques into incident response. NIST Spec. Publ. 10, 14 (2006), 800\u201386.","journal-title":"NIST Spec. Publ."},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-36891-4_22"},{"key":"e_1_3_1_81_2","article-title":"Malware Attribute Enumeration and Characterization","author":"Kirillov Ivan","year":"2011","unstructured":"Ivan Kirillov, Desiree Beck, Penny Chase, and Robert Martin. 2011. Malware Attribute Enumeration and Characterization. The MITRE Corporation.","journal-title":"The MITRE Corporation"},{"key":"e_1_3_1_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/CYCONUS.2017.8167507"},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2875529"},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978315"},{"key":"e_1_3_1_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2011.122111.00145"},{"key":"e_1_3_1_86_2","article-title":"Using IOC (Indicators of Compromise) in Malware Forensics","author":"Lock Hun-Ya","year":"2013","unstructured":"Hun-Ya Lock and Adam Kliarsky. 2013. Using IOC (Indicators of Compromise) in Malware Forensics. Technical Report. SANS Institute InfoSec Reading Room.","journal-title":"Technical Report. SANS Institute InfoSec Reading Room"},{"key":"e_1_3_1_87_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-31328-9_4"},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICAICST53116.2021.9497829"},{"key":"e_1_3_1_89_2","unstructured":"Mandiant. 2021. mandiant\/ioc-writer. Retrieved Feburary 3 2022 from https:\/\/github.com\/mandiant\/ioc_writer."},{"key":"e_1_3_1_90_2","unstructured":"OpenIOC Mandiant. 2014. An Open Framework for Sharing Threat Intelligence. Retrieved from www.openioc.org."},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(20)30141-0"},{"key":"e_1_3_1_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/WAINA.2012.135"},{"key":"e_1_3_1_93_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35764-0_5"},{"key":"e_1_3_1_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"e_1_3_1_95_2","first-page":"1","volume-title":"Preprints of the 1st Workshop on Secure Control Systems","author":"Mo Yilin","year":"2010","unstructured":"Yilin Mo and Bruno Sinopoli. 2010. False data injection attacks in control systems. In Preprints of the 1st Workshop on Secure Control Systems. 1\u20136."},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.3390\/jsan9030037"},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.17487\/rfc6045"},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICSCSR2013.3"},{"key":"e_1_3_1_99_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(12)70102-1"},{"key":"e_1_3_1_100_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.06.002"},{"key":"e_1_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-50660-9_8"},{"key":"e_1_3_1_102_2","doi-asserted-by":"publisher","DOI":"10.1016\/B978-0-12-815032-0.00011-1"},{"key":"e_1_3_1_103_2","doi-asserted-by":"publisher","DOI":"10.1145\/3212687.3212866"},{"key":"e_1_3_1_104_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.02.009"},{"key":"e_1_3_1_105_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.02.013"},{"key":"e_1_3_1_106_2","doi-asserted-by":"publisher","DOI":"10.5555\/2588191"},{"key":"e_1_3_1_107_2","volume-title":"igen: Toward Automatic Generation and Analysis of Indicators of Compromise (IOCS) Using Convolutional Neural Network","author":"Panwar Anupam","year":"2017","unstructured":"Anupam Panwar. 2017. igen: Toward Automatic Generation and Analysis of Indicators of Compromise (IOCS) Using Convolutional Neural Network. Ph. D. Dissertation. Arizona State University."},{"key":"e_1_3_1_108_2","unstructured":"YARA. 2021. The Pattern Matching Swiss Knife for Malware Researchers. Retrieved Feburary 3 2022 from https:\/\/virustotal.github.io\/yara\/\/."},{"key":"e_1_3_1_109_2","doi-asserted-by":"crossref","unstructured":"Lukumba Phiri and Simon Tembo. 2022. Evaluating the security posture and protection of critical assets of industrial control systems in Zambia.","DOI":"10.31695\/IJASRE.2022.8.5.1"},{"key":"e_1_3_1_110_2","doi-asserted-by":"publisher","DOI":"10.1049\/et.2016.0116"},{"key":"e_1_3_1_111_2","unstructured":"Industrial\/OT Threat Detection Radiflow. 2021. Retrieved Feburary 3 2022 from https:\/\/radiflow.com\/products\/isid-industrial-threat-detection\/."},{"key":"e_1_3_1_112_2","first-page":"33","article-title":"SCADA\/Control Systems Security","author":"Radvanovsky Robert","year":"2013","unstructured":"Robert Radvanovsky and Jacob Brodsky. 2013. SCADA\/Control Systems Security, Vol. 31. CRC Press, Boca Raton, FL,33.","journal-title":"CRC Press, Boca Raton, FL,"},{"key":"e_1_3_1_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/IOTA.2016.7562693"},{"key":"e_1_3_1_114_2","volume-title":"Energetic Bear\u2014Crouching Yetia","author":"Research Kaspersky Lab Global","year":"2014","unstructured":"Kaspersky Lab Global Research and Analysis Team. 2014. Energetic Bear\u2014Crouching Yetia. Technical Report."},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1080\/01402390.2014.977382"},{"key":"e_1_3_1_116_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(14)70469-5"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSA.2016.7802932"},{"key":"e_1_3_1_118_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-23781-3_8"},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00046"},{"key":"e_1_3_1_120_2","article-title":"Detection and blocking of replay, false command, and false access injection commands in scada systems with modbus protocol","author":"Satyanarayana Penke","year":"2021","unstructured":"Penke Satyanarayana et\u00a0al. 2021. Detection and blocking of replay, false command, and false access injection commands in scada systems with modbus protocol. Secur. Commun. Netw. (2021).","journal-title":"Secur. Commun. Netw."},{"key":"e_1_3_1_121_2","doi-asserted-by":"publisher","DOI":"10.1145\/3140241.3140246"},{"key":"e_1_3_1_122_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics9091460"},{"key":"e_1_3_1_123_2","unstructured":"Neetesh Saxena Vasilis Katos and Neeraj Kumar. 2017. Cyber-physical smart grid security tool for education and training purposes. International Workshops: Realigning Cyber Security Education Canberra 1\u20136."},{"key":"e_1_3_1_124_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2018.2879670"},{"key":"e_1_3_1_125_2","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3342112"},{"key":"e_1_3_1_126_2","unstructured":"The Mission Secure Platform: Complete OT Cybersecurity Protection Mission Secure. 2021. Retrieved Feburary 3 2022 from https:\/\/www.missionsecure.com\/cyber-security-solutions\/platform\/overview."},{"key":"e_1_3_1_127_2","unstructured":"Security Information and Event Management (SIEM). 2021. Retrieved Feburary 3 2022 from https:\/\/www.mcafee.com\/enterprise\/en-gb\/products\/siem-products.html."},{"key":"e_1_3_1_128_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.012"},{"key":"e_1_3_1_129_2","article-title":"Cyber Threat Intelligence Uses, Successes and Failures: The Sans 2017 cti Survey","author":"Shackleford Dave","year":"2017","unstructured":"Dave Shackleford. 2017. Cyber Threat Intelligence Uses, Successes and Failures: The Sans 2017 cti Survey. SANS Institute.","journal-title":"SANS Institute"},{"key":"e_1_3_1_130_2","unstructured":"Matthew P. Sibiga. 2017. Applying cyber threat intelligence to industrial control systems."},{"key":"e_1_3_1_131_2","unstructured":"Joe Slowik. 2018. Anatomy of an attack: Detecting and defeating crashoverride. VB\u201918 October (2018) 1\u201323."},{"key":"e_1_3_1_132_2","article-title":"Crashoverride: Reassessing the 2016 Ukraine Slectric Power Event as a Protection-focused Attack","author":"Slowik Joe","year":"2019","unstructured":"Joe Slowik. 2019. Crashoverride: Reassessing the 2016 Ukraine Slectric Power Event as a Protection-focused Attack. Dragos, Inc.","journal-title":"Dragos, Inc"},{"key":"e_1_3_1_133_2","article-title":"Evolution of ICS Attacks and the Prospects for Future Disruptive Events","author":"Slowik Joseph","year":"2019","unstructured":"Joseph Slowik. 2019. Evolution of ICS Attacks and the Prospects for Future Disruptive Events. Threat Intelligence Centre, Dragos Inc.","journal-title":"Threat Intelligence Centre, Dragos Inc"},{"key":"e_1_3_1_134_2","unstructured":"Open source network intrusion detection system and intrusion prevention system Snort. 2021. Retrieved Feburary 3 2022 from https:\/\/www.snort.org\/."},{"key":"e_1_3_1_135_2","unstructured":"Advanced Network Threat Prevention Check Point Software. 2021. Retrieved Feburary 3 2022 from https:\/\/www.checkpoint.com\/quantum\/advanced-network-threat-prevention\/."},{"key":"e_1_3_1_136_2","doi-asserted-by":"publisher","DOI":"10.1049\/cp.2013.1720"},{"key":"e_1_3_1_137_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-12330-7_3"},{"key":"e_1_3_1_138_2","first-page":"98","volume-title":"Proceedings of the International Conference on Information Security and Cyber Forensics (InfoSec\u201914). The Society of Digital Information and Wireless Communication","author":"Stirland Joe","year":"2014","unstructured":"Joe Stirland, Kevin Jones, Helge Janicke, Tina Wu, et\u00a0al. 2014. Developing cyber forensics for SCADA industrial control systems. In Proceedings of the International Conference on Information Security and Cyber Forensics (InfoSec\u201914). The Society of Digital Information and Wireless Communication. 98\u2013111."},{"issue":"82","key":"e_1_3_1_139_2","first-page":"16","article-title":"Guide to industrial control systems (ICS) security","volume":"800","author":"Stouffer Keith","year":"2011","unstructured":"Keith Stouffer, Joe Falco, and Karen Scarfone. 2011. Guide to industrial control systems (ICS) security. NIST Spec. Publ. 800, 82 (2011), 16\u201316.","journal-title":"NIST Spec. Publ."},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.108261"},{"issue":"21","key":"e_1_3_1_141_2","article-title":"SCADA live forensics: Real time data acquisition process to detect, prevent or evaluate critical situations","volume":"9","author":"Taveras Pedro","year":"2013","unstructured":"Pedro Taveras. 2013. SCADA live forensics: Real time data acquisition process to detect, prevent or evaluate critical situations. Eur. Sci. J. 9, 21 (2013).","journal-title":"Eur. Sci. J."},{"key":"e_1_3_1_142_2","unstructured":"Nessus Vulnerability Assessment Tenable. 2021. Retrieved Feburary 3 2022 from https:\/\/www.tenable.com\/products\/nessus."},{"key":"e_1_3_1_143_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.09.001"},{"key":"e_1_3_1_144_2","unstructured":"ICS Security: Critical Infrastructure Security Tripwire. 2021. Retrieved Feburary 3 2022 from https:\/\/www.tripwire.com\/solutions\/industrial-control-systems."},{"key":"e_1_3_1_145_2","article-title":"Threat intelligence library-a new revolutionary technology to enhance the soc battle rhythm!","author":"Trost Ryan","year":"2014","unstructured":"Ryan Trost. 2014. Threat intelligence library-a new revolutionary technology to enhance the soc battle rhythm! In Proceedings of theBlack Hat USA Conference.","journal-title":"Black Hat USA Conference"},{"key":"e_1_3_1_146_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101666"},{"key":"e_1_3_1_147_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2014.06.007"},{"key":"e_1_3_1_148_2","first-page":"147","volume-title":"Security of Industrial Control Systems and Cyber Physical Systems","author":"Vliet Pieter Van","year":"2015","unstructured":"Pieter Van Vliet, M.-T. Kechadi, and Nhien-An Le-Khac. 2015. Forensics in industrial control system: A case study. In Security of Industrial Control Systems and Cyber Physical Systems. Springer, 147\u2013156."},{"key":"e_1_3_1_149_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2018.8587409"},{"key":"e_1_3_1_150_2","unstructured":"Verzion. 2021. Vocabulary for Event Recording and Incident Sharing. Retrieved from http:\/\/veriscommunity.net\/."},{"key":"e_1_3_1_151_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics11030416"},{"key":"e_1_3_1_152_2","unstructured":"Will Gibb and Devon Kerr. 2013. OpenIOC: Back to the Basics . https:\/\/www.mandiant.com\/resources\/blog\/openioc-basics. Accessed March 29 2023."},{"key":"e_1_3_1_153_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.proeng.2017.03.197"},{"key":"e_1_3_1_154_2","doi-asserted-by":"publisher","DOI":"10.5555\/2735338.2735340"},{"issue":"4","key":"e_1_3_1_155_2","first-page":"7","article-title":"Exploring the use of PLC debugging tools for digital forensic investigations on SCADA systems","volume":"10","author":"Wu Tina","year":"2015","unstructured":"Tina Wu and Jason R. C. Nurse. 2015. Exploring the use of PLC debugging tools for digital forensic investigations on SCADA systems. J. Digit. Forens. Secur. Law 10, 4 (2015), 7.","journal-title":"J. Digit. Forens. Secur. Law"},{"key":"e_1_3_1_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900091"},{"key":"e_1_3_1_157_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2020.103201"},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.36227\/techrxiv.15147171.v1"},{"key":"e_1_3_1_159_2","doi-asserted-by":"publisher","DOI":"10.1109\/SGCF.2018.8408947"},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102221"},{"key":"e_1_3_1_161_2","unstructured":"Alberto Zanutto Ben Shreeve Karolina Follis Jerry S. Busby and Awais Rashid. 2017. The shadow warriors: In the no man\u2019s land between industrial control systems and enterprise IT systems. Thirteenth Symposium on Usable Privacy and Security (SOUPS\u201917) USENIX Association 1\u20136."},{"key":"e_1_3_1_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC47284.2019.8969570"},{"key":"e_1_3_1_163_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101867"},{"key":"e_1_3_1_164_2","doi-asserted-by":"publisher","DOI":"10.1145\/3339252.3340528"}],"container-title":["ACM Transactions on Cyber-Physical Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587255","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3587255","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:16Z","timestamp":1750178836000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3587255"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,19]]},"references-count":163,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2023,4,30]]}},"alternative-id":["10.1145\/3587255"],"URL":"https:\/\/doi.org\/10.1145\/3587255","relation":{},"ISSN":["2378-962X","2378-9638"],"issn-type":[{"value":"2378-962X","type":"print"},{"value":"2378-9638","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,4,19]]},"assertion":[{"value":"2022-08-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-03","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-04-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}