{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:56:54Z","timestamp":1781287014060,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":24,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,23]]},"DOI":"10.1145\/3806008.3811709","type":"proceedings-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:05:21Z","timestamp":1781283921000},"page":"102-106","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Work-in-Progress: Experimentation with Clustering Analysis on Industrial Control Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3764-2360","authenticated-orcid":false,"given":"Shivanjali","family":"Khare","sequence":"first","affiliation":[{"name":"Electrical Engineering and Computer Science, University of New Haven, West Haven, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1914-711X","authenticated-orcid":false,"given":"Tirthankar","family":"Ghosh","sequence":"additional","affiliation":[{"name":"Electrical Engineering and Computer Science, University of New Haven, West Haven, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-6156-0252","authenticated-orcid":false,"given":"Sreya","family":"Jagarapu","sequence":"additional","affiliation":[{"name":"Electrical Engineering and Computer Science, University of New Haven, West Haven, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"59","volume-title":"Proceedings of the Singapore Cyber-Security Conference (SG-CRC)","author":"Adepu S.","year":"2016","unstructured":"S. Adepu and A. Mathur. 2016. Detecting multi-point attacks in a water treatment system using intermittent control actions. In Proceedings of the Singapore Cyber-Security Conference (SG-CRC) 2016. IOS Press, 59-74."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.3390\/electronics9061017"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2016.02.004"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2024.111023"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.3390\/e17042367"},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 2020 In-ternational Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC). IEEE, 375-378","author":"Chang H. C.","unstructured":"H. C. Chang, C. Y. Lin, D. J. Liao, and T. M. Koo. 2020. The Modbus protocol vulnerability test in industrial control systems. In Proceedings of the 2020 In-ternational Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC). IEEE, 375-378."},{"key":"e_1_3_2_1_7_1","volume-title":"Accessed","author":"G.","year":"2007","unstructured":"Combs, G. (2007). 2026. Wireshark. http:\/\/www.wireshark.org\/. Accessed: April 19, 2026."},{"key":"e_1_3_2_1_8_1","first-page":"63","volume-title":"Proceedings of 37th International Conference on Computers and Their Applications","volume":"82","author":"Day L.","unstructured":"L. Day, T. Ghosh, S. Bagui, and S. Bagui. 2022. Entropy Analysis for Modbus Traffic over TCP\/IP in Industrial Control Systems. In Proceedings of 37th International Conference on Computers and Their Applications, Vol. 82. 63-71."},{"key":"e_1_3_2_1_9_1","first-page":"3439","article-title":"A Systematic Review of Data-Driven Intrusion Detection for Industrial Control Systems","volume":"20","author":"Ferrag M. A.","year":"2018","unstructured":"M. A. Ferrag, L. Maglaras, H. Janicke, J. Jiang, and L. Shu. 2018. A Systematic Review of Data-Driven Intrusion Detection for Industrial Control Systems. IEEE Communications Surveys & Tutorials 20 (2018), 3439-3468.","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the International Conference on Critical Information Infrastructures Security. Springer, 230-235","author":"Fraz\u00e3o I.","unstructured":"I. Fraz\u00e3o, P. H. Abreu, T. Cruz, H. Ara\u00fajo, and P. Sim\u00f5es. 2018. Denial of service attacks: Detecting the frailties of machine learning algorithms in the classification process. In Proceedings of the International Conference on Critical Information Infrastructures Security. Springer, 230-235."},{"key":"e_1_3_2_1_11_1","article-title":"On cyber attacks and signature based intrusion detection for modbus based industrial control systems","volume":"9","author":"Gao W.","year":"2014","unstructured":"W. Gao and T. H. Morris. 2014. On cyber attacks and signature based intrusion detection for modbus based industrial control systems. Journal of Digital Forensics, Security and Law 9, 3 (2014).","journal-title":"Journal of Digital Forensics, Security and Law"},{"key":"e_1_3_2_1_12_1","unstructured":"T. Ghosh S. Bagui S. Bagui M. Kadzis L. Day and J. Bare. 2022. Univariate and Bivariate Entropy Analysis for Modbus Traffic over TCP\/IP in Industrial Control Systems. International Journal for Computers & Their Applications 29 (2022)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2013.05.001"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Trevor Hastie Robert Tibshirani Jerome Friedman et al. 2009. The elements of statistical learning.","DOI":"10.1007\/978-0-387-84858-7"},{"key":"e_1_3_2_1_15_1","volume-title":"Mutia Nur Estri, et al","author":"Herdiana Indra","year":"2025","unstructured":"Indra Herdiana, M Alfin Kamal, Mutia Nur Estri, et al. 2025. A more precise elbow method for optimum K-means clustering. arXiv preprint arXiv:2502.00851 (2025)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1002\/9780470316801"},{"key":"e_1_3_2_1_17_1","volume-title":"Manuel Gil P\u00e9rez, and Pantaleone Nespoli","author":"L\u00f3pez Pedro Beltr\u00e1n","year":"2026","unstructured":"Pedro Beltr\u00e1n L\u00f3pez, Manuel Gil P\u00e9rez, and Pantaleone Nespoli. 2026. Enhancing Strategic Decision-Making via Semantic Inference: An Adaptive Framework for Threat Actor Profiling. Information Fusion (2026), 104359."},{"key":"e_1_3_2_1_18_1","volume-title":"Proc. of 5th Berkeley Symposium on Math. Stat. and Prob. 281-297","author":"McQueen James B","year":"1967","unstructured":"James B McQueen. 1967. Some methods of classification and analysis of multi-variate observations. In Proc. of 5th Berkeley Symposium on Math. Stat. and Prob. 281-297."},{"key":"e_1_3_2_1_19_1","volume-title":"Accessed","author":"MITRE Corporation","year":"2026","unstructured":"MITRE Corporation. 2026. MITRE ATT&CK Framework. https:\/\/attack.mitre.org\/. Accessed: April 19, 2026."},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 2020 ACM Southeast Conference. 188-196","author":"Phillips B.","unstructured":"B. Phillips, E. Gamess, and S. Krishnaprasad. 2020. An evaluation of machine learning-based anomaly detection in a SCADA system using the modbus protocol. In Proceedings of the 2020 ACM Southeast Conference. 188-196."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3198992"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3078381"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 2018 IEEE International Conference on Applied System Invention (ICASI). IEEE, 255-258","author":"Wang P. H.","unstructured":"P. H. Wang, I. E. Liao, K. F. Kao, and J. Y. Huang. 2018. An intrusion detection method based on log sequence clustering of honeypot for modbus tcp protocol. In Proceedings of the 2018 IEEE International Conference on Applied System Invention (ICASI). IEEE, 255-258."},{"key":"e_1_3_2_1_24_1","first-page":"2211","article-title":"Intrusion Detection System for Industrial Control Systems Based on Machine Learning","volume":"10","author":"Yang Y.","year":"2014","unstructured":"Y. Yang, K. McLaughlin, S. Sezer, X. Yuan, W. Huang, and J. Wan. 2014. Intrusion Detection System for Industrial Control Systems Based on Machine Learning. IEEE Transactions on Industrial Informatics 10 (2014), 2211-2221.","journal-title":"IEEE Transactions on Industrial Informatics"}],"event":{"name":"CODASPY '26: Sixteenth ACM Conference on Data and Application Security and Privacy","location":"Frankfurt am Main Germany","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 6th ACM Workshop on Secure and Trustworthy Cyber-Physical Systems"],"original-title":[],"deposited":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T17:05:36Z","timestamp":1781283936000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3806008.3811709"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":24,"alternative-id":["10.1145\/3806008.3811709","10.1145\/3806008"],"URL":"https:\/\/doi.org\/10.1145\/3806008.3811709","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}