{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T04:46:29Z","timestamp":1782535589115,"version":"3.54.5"},"reference-count":21,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T00:00:00Z","timestamp":1782172800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100014786","name":"Northern Border University","doi-asserted-by":"crossref","award":["NBU-FFR-2025-2119-06"],"award-info":[{"award-number":["NBU-FFR-2025-2119-06"]}],"id":[{"id":"10.13039\/501100014786","id-type":"DOI","asserted-by":"crossref"}]},{"award":["NBU-FFR-2025-2119-06"],"award-info":[{"award-number":["NBU-FFR-2025-2119-06"]}],"id":[{"id":"https:\/\/ror.org\/03j9tzj20","id-type":"ROR","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network"],"abstract":"<jats:p>Cyber-physical smart infrastructures integrate sensing devices, communication networks, control components, and service platforms, which makes them vulnerable to malicious activities that may evolve gradually through several attack stages. The objective of this study is to develop and evaluate a simulation-based cybersecurity framework capable of detecting a proposed novel multi-stage cyber attack and identifying its internal progression within a realistic smart infrastructure environment. To achieve this objective, a NetSim-based cyber-physical smart infrastructure was modeled to generate both normal operational traffic and staged malicious traffic. The generated traffic was captured, processed, labeled, and transformed into a stage-aware cybersecurity dataset. An artificial neural network (ANN) model was then trained and evaluated for two detection tasks: binary classification of normal versus attack traffic and multi-class classification of compromise, coordination, and execution attack stages. Twenty experimental configurations were designed to examine the model under progressively broader infrastructure contexts, including sensing, service, gateway, control, backbone, and full-span operational scenarios. The best binary testing performance was achieved in the eighteenth experimental configuration, representing a broad full-span infrastructure scenario, with 97.96% accuracy, 97.80% precision, 97.65% recall, 97.72% F1-score, and 1.06% false positive rate. For stage-aware multi-class detection, the ANN model achieved 96.97% accuracy, 96.36% macro-averaged precision, 96.20% macro-averaged recall, 96.28% macro-averaged F1-score, and 96.55% weighted F1-score. Macro-averaged metrics report the unweighted average performance across classes, while weighted F1-score accounts for class support. These results show that the proposed simulation-based framework can generate realistic attack-aware traffic data and support reliable ANN-based detection of both attack presence and attack-stage progression.<\/jats:p>","DOI":"10.3390\/network6030042","type":"journal-article","created":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T01:03:23Z","timestamp":1782263003000},"page":"42","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Simulation-Driven Cybersecurity Framework for Detecting Novel Multi-Stage Attacks in Cyber-Physical Smart Infrastructure"],"prefix":"10.3390","volume":"6","author":[{"given":"Nadera","family":"Aljawabrah","sequence":"first","affiliation":[{"name":"Department of Information Technology, Faculty of Prince Al-Hussein bin Abdullah II of Information Technology, The Hashemite University, Zarqa 13110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nedal Y.","family":"Al-Tamimi","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Science and Information Technology, Irbid National University, Irbid 21110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ayoub","family":"Alsarhan","sequence":"additional","affiliation":[{"name":"Department of Data Science and Artificial Intelligence, Faculty of Information Technology, Al-Ahliyya Amman University, Amman 19111, Jordan"},{"name":"Department of Information Technology, Faculty of Prince Al-Hussien bin Abdullah, The Hashemite University, Zarqa 13133, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5389-6778","authenticated-orcid":false,"given":"Mahmoud","family":"Aljamal","sequence":"additional","affiliation":[{"name":"Department of Cybersecurity, Science and Information Technology, Irbid National University, Irbid 21110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3610-961X","authenticated-orcid":false,"given":"Bashar S.","family":"Khassawneh","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Information Systems, College of Computer Sciences and Informatics, Amman Arab University, Amman 11953, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0884-7885","authenticated-orcid":false,"given":"Sami Aziz","family":"Alshammari","sequence":"additional","affiliation":[{"name":"Department of Information Technology, Faculty of Computing and Information Technology, Northern Border University, Rafha 73213, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5739-0589","authenticated-orcid":false,"given":"Nayef H.","family":"Alshammari","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Faculty of Computers and Information Technology, University of Tabuk, Tabuk 47512, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1570-8274","authenticated-orcid":false,"given":"Khalid Hamad","family":"Alnafisah","sequence":"additional","affiliation":[{"name":"Department of Computer Sciences, Faculty of Computing and Information Technology, Northern Border University, Rafha 73213, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,6,23]]},"reference":[{"key":"ref_1","first-page":"2347","article-title":"Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications","volume":"17","author":"Guizani","year":"2024","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_2","unstructured":"Amutha, K.P., Mehanathen, N., Karthikeyan, K., Sakthi Saravanakumar, P., and Shanmuganeethi, V. (2026). Internet of Things Applications for Real-Time Monitoring and Tracking: IoT Insights and Real-Time Tracking. Industry 6.0 and Digital Transformation in Supply Chain, Assets, and Services, IGI Global Scientific Publishing."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Alokdeh, S.K., Al-Sulaiti, I., Shwedeh, F., Alzoubi, H.M., and Ahmed, G. (2026). Transforming Smart Manufacturing: The Pivotal Role of IoT and Data Integration in Enhancing Operational Efficiency in Manufacturing Sector. Integrating 4IR and 5IR Technologies for Digital Business Innovation, Emerald Publishing Limited.","DOI":"10.1108\/978-1-83608-578-220251023"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Rahman, M.A., Alam, S.B., Gupta, K.D., George, R., Siddique, S., and Kobayashi, K. (2026). Mitigating the ICS Attack Surface: Identifying Attack Vectors, Reducing Vulnerabilities, and Security Mapping Techniques. Securing Industrial Control Systems: Advanced Strategies and Technologies, Springer.","DOI":"10.1007\/978-3-032-03018-4_5"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"15250","DOI":"10.1109\/JIOT.2026.3652009","article-title":"Lightweight Federated Few-Shot Learning-Based Network Intrusion Detection for Resource-Constrained IoT Devices","volume":"13","author":"Saleem","year":"2026","journal-title":"IEEE Internet Things J."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"114761","DOI":"10.1016\/j.asoc.2026.114761","article-title":"A Survey on Recent Recurrent Neural Networks based Intrusion Detection Systems","volume":"192","author":"Zameer","year":"2026","journal-title":"Appl. Soft Comput."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"20","DOI":"10.71222\/bvjsn889","article-title":"A Dynamic Intrusion Detection System Integrating Concept Drift Detection and Incremental Learning","volume":"3","author":"Liao","year":"2026","journal-title":"J. Comput. Signal Syst. Res."},{"key":"ref_8","first-page":"387","article-title":"Whale Optimization Algorithm for Feature Selection Enhances Classification in Malware Datasets","volume":"4","author":"Ibrahim","year":"2025","journal-title":"J. Comput. Cogn. Eng."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"775","DOI":"10.1002\/oca.3230","article-title":"Integrated Local Search Technique with Reptile Search Algorithm for Solving Large-Scale Bound Constrained Global Optimization Problems","volume":"46","author":"Shehab","year":"2025","journal-title":"Optim. Control Appl. Methods"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Khater, B.S., Abdul Wahab, A.W., Idris, M.Y.I., Hussain, M.A., Ibrahim, A.A., Amin, M.A., and Shehadeh, H.A. (2021). Classifier Performance Evaluation for Lightweight IDS Using Fog Computing in IoT Security. Electronics, 10.","DOI":"10.3390\/electronics10141633"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Aljamal, Q., AlJamal, M., Al-Jamal, M.Q., Jawasreh, Z., Alsarhan, A., Alshammari, S.A., and Alshammari, R.R. (2025). A Novel Deep Hybrid Learning Framework for Structural Reliability Under Civil and Mechanical Constraints. Mathematics, 13.","DOI":"10.3390\/math13233834"},{"key":"ref_12","first-page":"5287","article-title":"Transfer Learning-Based Approach with an Ensemble Classifier for Detecting Keylogging Attack on the Internet of Things","volume":"85","author":"Anbar","year":"2025","journal-title":"Comput. Mater. Contin."},{"key":"ref_13","first-page":"336","article-title":"Android Malware Detection Using a Modified Dwarf Mongoose Algorithm","volume":"18","author":"Alabdallat","year":"2025","journal-title":"Int. J. Intell. Eng. Syst."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1007\/s13042-025-02873-w","article-title":"Targeted adversarial traffic generation: Black-box approach to evade intrusion detection systems in IoT networks","volume":"17","author":"Debicha","year":"2026","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Hashmi, S.A.A., and Tiwari, P. (2026). A Digital Twin-Integrated Framework for Dual Insider and External Cyber Threat Detection in Critical Infrastructure. Res. Sq.","DOI":"10.21203\/rs.3.rs-8860486\/v1"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Panda, N., and Muthuraman, S. (2026). A Multiclass Machine Learning Framework for Detecting Routing Attacks in RPL-Based IoT Networks Using a Novel Simulation-Driven Dataset. Future Internet, 18.","DOI":"10.3390\/fi18010035"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"24970","DOI":"10.1109\/ACCESS.2025.3532895","article-title":"A comprehensive approach to intrusion detection in IoT environments using hybrid feature selection and multi-stage classification techniques","volume":"13","author":"Logeswari","year":"2025","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Abou Elasaad, M.M., Sayed, S.G., and El-Dakroury, M.M. (2025). AegisGuard: A Multi-Stage Hybrid Intrusion Detection System with Optimized Feature Selection for Industrial IoT Security. Sensors, 25.","DOI":"10.3390\/s25226958"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1803","DOI":"10.1109\/TNSM.2020.3014929","article-title":"Multi-stage optimized machine learning framework for network intrusion detection","volume":"18","author":"Injadat","year":"2020","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"27058","DOI":"10.1038\/s41598-025-96303-0","article-title":"Machine learning based multi-stage intrusion detection system and feature selection ensemble security in cloud assisted vehicular ad hoc networks","volume":"15","author":"Christy","year":"2025","journal-title":"Sci. Rep."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Al-Jamal, M.Q., Alsarhan, A., AlJamal, M., Aljamal, Q., Khassawneh, B.S., Salhi, A., and Hayat, H. (2026). Integrating Generative Design and Artificial Intelligence for Optimized Energy-Efficient Composite Facades in Next-Generation Smart Buildings. Sustainability, 18.","DOI":"10.3390\/su18052379"}],"container-title":["Network"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2673-8732\/6\/3\/42\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T04:15:20Z","timestamp":1782533720000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2673-8732\/6\/3\/42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,23]]},"references-count":21,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,9]]}},"alternative-id":["network6030042"],"URL":"https:\/\/doi.org\/10.3390\/network6030042","relation":{},"ISSN":["2673-8732"],"issn-type":[{"value":"2673-8732","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,23]]}}}