<?xml version="1.0" encoding="UTF-8"?>
<doi_batch xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.crossref.org/schema/5.5.0 https://www.crossref.org/schemas/crossref5.5.0.xsd" xmlns="http://www.crossref.org/schema/5.5.0" xmlns:jats="http://www.ncbi.nlm.nih.gov/JATS1" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:ai="http://www.crossref.org/AccessIndicators.xsd" version="5.5.0">
  <head>
    <doi_batch_id>wseas-12115-20260930070730-6dd41d</doi_batch_id>
    <timestamp>20260930070730022</timestamp>
    <depositor>
      <depositor_name>wseas/wseas</depositor_name>
      <email_address>wseas.group@gmail.com</email_address>
    </depositor>
    <registrant>WSEAS</registrant>
  </head>
  <body>
    <journal>
      <journal_metadata language="en">
        <full_title>International Journal of Applied Mathematics, Computational Science and Systems Engineering</full_title>
        <issn media_type="electronic">2766-9823</issn>
      </journal_metadata>
      <journal_issue>
        <publication_date media_type="online">
          <month>06</month>
          <day>29</day>
          <year>2026</year>
        </publication_date>
        <publication_date media_type="print">
          <month>06</month>
          <day>29</day>
          <year>2026</year>
        </publication_date>
        <journal_volume>
          <volume>8</volume>
        </journal_volume>
      </journal_issue>
      <journal_article publication_type="full_text" language="en">
        <titles>
          <title>A Comprehensive Review of Cybersecurity Frameworks and Defense Mechanisms for Modbus and HTTP in Industrial Control Systems</title>
        </titles>
        <contributors>
          <person_name sequence="first" contributor_role="author">
            <given_name>Lukumba</given_name>
            <surname>Phiri</surname>
            <affiliations>
              <institution>
                <institution_name>Department of Electrical Engineering, University of Zambia, Lusaka, ZAMBIA</institution_name>
              </institution>
            </affiliations>
          </person_name>
          <person_name sequence="additional" contributor_role="author">
            <given_name>Mukubesa</given_name>
            <surname>Kamutumwa</surname>
            <affiliations>
              <institution>
                <institution_name>Department of Electrical Engineering, University of Zambia, Lusaka, ZAMBIA</institution_name>
              </institution>
            </affiliations>
          </person_name>
        </contributors>
        <jats:abstract xml:lang="en"><jats:p>Industrial Control Systems (ICS) form the backbone of critical infrastructure, enabling automation and control in sectors such as energy, water, and manufacturing. The convergence of Operational Technology (OT) and Information Technology (IT) has introduced significant cybersecurity challenges, particularly for legacy communication protocols like Modbus and HTTP, which were not designed with security in mind. This paper provides a comprehensive framework for understanding the attack and defense mechanisms associated with two protocols i.e., Modbus and HTTP, used in ICS. We systematically analyze the inherent vulnerabilities of these protocols, survey proposed security enhancements including cryptographic solutions, intrusion detection systems, and security-by-design approaches, and evaluate existing cybersecurity frameworks such as MITRE ATT&amp;CK, NIST CSF, and the Cyber Kill Chain. The review identifies a persistent gap in integrated, protocol-specific frameworks that address both attack simulation and defense validation in virtualized ICS environments. By synthesizing current research, this study highlights trends in threat modeling, machine learning-based anomaly detection, and the evolution of testbeds, providing a foundation for future work aimed at developing holistic security frameworks for Modbus and HTTP-based industrial networks.</jats:p></jats:abstract>
        <publication_date media_type="online">
          <month>09</month>
          <day>30</day>
          <year>2026</year>
        </publication_date>
        <publication_date media_type="print">
          <month>09</month>
          <day>30</day>
          <year>2026</year>
        </publication_date>
        <pages>
          <first_page>155</first_page>
        </pages>
        <publisher_item>
          <item_number item_number_type="article_number">16</item_number>
        </publisher_item>
        <ai:program name="AccessIndicators">
          <ai:free_to_read/>
          <ai:license_ref applies_to="vor" start_date="2026-09-30">https://creativecommons.org/licenses/by/4.0/</ai:license_ref>
        </ai:program>
        <doi_data>
          <doi>10.37394/232026.2026.8.16</doi>
          <resource>https://wseas.com/journals/articles.php?id=12115</resource>
        </doi_data>
        <citation_list>
          <citation type="journal_article" key="ref1"><unstructured_citation>M. U. Ali, M. Akhtar, and H. Durad, “Industrial Control and Building Automation System Penetrating Testing using Modbus TCP Testbed,” VFAST Transactions on Software Engineering, vol. 10, no. 3, pp. 37–42, Sep. 2022, doi: 10.21015/vtse.v10i3.1113.</unstructured_citation></citation>
          <citation type="journal_article" key="ref2"><unstructured_citation>E. Amer, B. A. S. Al-rimy, and S. El-Sappagh, “Strengthening ICS defense: Modbus-NFA behavior model for enhanced anomaly detection,” Journal of Information Security and Applications, vol. 89, p. 103990, Mar. 2025, doi: 10.1016/J.JISA.2025.103990.</unstructured_citation></citation>
          <citation type="journal_article" key="ref3"><unstructured_citation>K. Stouffer et al., “Guide to Operational Technology (OT) security,” Sep. 2023. doi: 10.6028/NIST.SP.800-82r3.</unstructured_citation></citation>
          <citation type="journal_article" key="ref4"><unstructured_citation>M. Nankya, R. Chataut, and R. Akl, “Securing Industrial Control Systems: Components, Cyber Threats, and Machine Learning-Driven Defense Strategies,” Sensors, vol. 23, no. 21, p. 8840, Oct. 2023, doi: 10.3390/s23218840.</unstructured_citation></citation>
          <citation type="journal_article" key="ref5"><unstructured_citation>F. Katulić, D. Sumina, S. Groš, and I. Erceg, “Protecting Modbus/TCP-Based Industrial Automation and Control Systems Using Message Authentication Codes,” IEEE Access, vol. 11, pp. 47007–47023, 2023, doi: 10.1109/ACCESS.2023.3275443.</unstructured_citation></citation>
          <citation type="journal_article" key="ref6"><unstructured_citation>Y. Hu, A. Yang, H. Li, Y. Sun, and L. Sun, “A survey of intrusion detection on industrial control systems,” Int. J. Distrib. Sens. Netw., vol. 14, no. 8, p. 155014771879461, Aug. 2018, doi: 10.1177/1550147718794615.</unstructured_citation></citation>
          <citation type="journal_article" key="ref7"><unstructured_citation>Q. Wanying, W. Weimin, Z. Surong, and Z. Yan, “The Study of Security Issues for the Industrial Control Systems Communication Protocols,” in Proceedings of the 2015 Joint International Mechanical, Electronic and Information Technology Conference, Paris, France: Atlantis Press, 2015. doi: 10.2991/jimet-15.2015.129.</unstructured_citation></citation>
          <citation type="journal_article" key="ref8"><unstructured_citation>C. Parian, T. Guldimann, and S. Bhatia, “Fooling the Master: Exploiting Weaknesses in the Modbus Protocol,” Procedia Comput. Sci., vol. 171, pp. 2453–2458, 2020, doi: 10.1016/j.procs.2020.04.265.</unstructured_citation></citation>
          <citation type="journal_article" key="ref9"><unstructured_citation>A. A. Murthy, P. Mabel John, and R. M. Babu Kasturi Nagappasetty, “Hypertext transfer protocol performance analysis in traditional and software defined networks during Slowloris attack,” International Journal of Electrical and Computer Engineering (IJECE), vol. 13, no. 4, p. 4268, Aug. 2023, doi: 10.11591/ijece.v13i4.pp4268-4279.</unstructured_citation></citation>
          <citation type="journal_article" key="ref10"><unstructured_citation>D. M. Djekic, “The Industrial Control Systems and The Internet of Things,” Cyber Defense Magazine, Aug. 27, 2023. Accessed: May 04, 2025. [Online]. Available: https://www.cyberdefensemagazine.com/the-industrial-control-systems-and-the-internet-of-things/#</unstructured_citation></citation>
          <citation type="journal_article" key="ref11"><unstructured_citation>S. Jaloudi, “Communication protocols of an industrial internet of things environment: A comparative study,” Future Internet, vol. 11, no. 3, 2019, doi: 10.3390/fi11030066.</unstructured_citation></citation>
          <citation type="journal_article" key="ref12"><unstructured_citation>K.-C. Lu, I.-H. Liu, and J.-S. Li, “A Survey of the Offensive and defensive in Industrial Control System.” [Online]. Available: www.bncss.org,</unstructured_citation></citation>
          <citation type="journal_article" key="ref13"><unstructured_citation>X. Qin, F. Jiang, X. Qin, L. Ge, M. Lu, and R. Doss, “CGAN-based cyber deception framework against reconnaissance attacks in ICS,” Computer Networks, vol. 251, p. 110655, Sep. 2024, doi: 10.1016/J.COMNET.2024.110655.</unstructured_citation></citation>
          <citation type="journal_article" key="ref14"><unstructured_citation>F. J. Folgado, D. Calderón, I. González, and A. J. Calderón, “Review of Industry 4.0 from the Perspective of Automation and Supervision Systems: Definitions, Architectures and Recent Trends,” Feb. 01, 2024, Multidisciplinary Digital Publishing Institute (MDPI). doi: 10.3390/electronics13040782.</unstructured_citation></citation>
          <citation type="journal_article" key="ref15"><unstructured_citation>A. Dima, “The Four Industrial Revolutions: Transforming Manufacturing Across Centuries,” K. Factory, Accessed: May 04, 2025. [Online]. Available: https://kfactory.eu/the-industrial-revolution-short-history-of-manufacturing/</unstructured_citation></citation>
          <citation type="journal_article" key="ref16"><unstructured_citation>C. Urrea, C. Morales, and J. Kern, “Implementation of error detection and correction in the Modbus-RTU serial protocol,” International Journal of Critical Infrastructure Protection, vol. 15, pp. 27–37, Dec. 2016, doi: 10.1016/J.IJCIP.2016.07.001.</unstructured_citation></citation>
          <citation type="journal_article" key="ref17"><unstructured_citation>I. Zagan and V. G. Găitan, “Enhancing the Modbus Communication Protocol to Minimize Acquisition Times Based on an STM32-Embedded Device,” Mathematics, vol. 10, no. 24, p. 4686, Dec. 2022, doi: 10.3390/math10244686.</unstructured_citation></citation>
          <citation type="journal_article" key="ref18"><unstructured_citation>N. C. Găitan, I. Zagan, and V. G. Găitan, “Proposed Modbus Extension Protocol and Real-Time Communication Timing Requirements for Distributed Embedded Systems,” Technologies (Basel)., vol. 12, no. 10, p. 187, Oct. 2024, doi: 10.3390/technologies12100187.</unstructured_citation></citation>
          <citation type="journal_article" key="ref19"><unstructured_citation>D. N. Patel and S. B. Somani, “A Review on Implementation of MODBUS Communication Protocol and its Applications,” International Journal of Electronics Engineering Research, vol. 9, no. 4, 2017.</unstructured_citation></citation>
          <citation type="journal_article" key="ref20"><unstructured_citation>G. Yadav and K. Paul, “Architecture and Security of SCADA Systems: A Review,” Jan. 2020.</unstructured_citation></citation>
          <citation type="journal_article" key="ref21"><unstructured_citation>Q.-T. Dao, L.-T. Nguyen, T.-K. Ha, V.-H. Nguyen, and T.-A. Nguyen, “Investigation of Secure Communication of Modbus TCP/IP Protocol: Siemens S7 PLC Series Case Study,” Applied System Innovation, vol. 8, no. 3, p. 65, May 2025, doi: 10.3390/asi8030065.</unstructured_citation></citation>
          <citation type="journal_article" key="ref22"><unstructured_citation>A. A. Murthy, P. Mabel John, and R. M. Babu Kasturi Nagappasetty, “Hypertext transfer protocol performance analysis in traditional and software defined networks during Slowloris attack,” International Journal of Electrical and Computer Engineering (IJECE), vol. 13, no. 4, p. 4268, Aug. 2023, doi: 10.11591/ijece.v13i4.pp4268-4279.</unstructured_citation></citation>
          <citation type="journal_article" key="ref23"><unstructured_citation>CosmasEkoSuharyanto and PastimaSimanjuntak, “Potential Threat Analysis Hypertext Transfer Protocol and Secure Hypertext Transfer Protocol of Public WiFi Users (Batam Case) CosmasEkoSuharyanto, PastimaSimanjuntak,” 2017, [Online]. Available: http://www.ijser.org</unstructured_citation></citation>
          <citation type="journal_article" key="ref24"><unstructured_citation>X. Etxezarreta, I. Garitano, M. Iturbe, and U. Zurutuza, “Software-Defined Networking approaches for intrusion response in Industrial Control Systems: A survey,” International Journal of Critical Infrastructure Protection, vol. 42, Sep. 2023, doi: 10.1016/j.ijcip.2023.100615.</unstructured_citation></citation>
          <citation type="journal_article" key="ref25"><unstructured_citation>A. S. George, “Partners Universal International Innovation Journal (PUIIJ) The Impact of IT/OT Convergence on Digital Transformation in Manufacturing,” 2024, doi: 10.5281/zenodo.10895704.</unstructured_citation></citation>
          <citation type="journal_article" key="ref26"><unstructured_citation>R. Venanzi, G. Di Modica, L. Foschini, and P. Bellavista, “Towards IT/OT integration in industry digitalization: A comprehensive survey,” Journal of Network and Computer Applications, vol. 245, p. 104373, Jan. 2026, doi: 10.1016/J.JNCA.2025.104373.</unstructured_citation></citation>
          <citation type="journal_article" key="ref27"><unstructured_citation>C. - Clara Morlière, “IT/OT convergence: A fruitful integration of information systems and operational systems.”</unstructured_citation></citation>
          <citation type="journal_article" key="ref28"><unstructured_citation>T. Martins and S. V. G. Oliveira, “Enhanced Modbus/TCP Security Protocol: Authentication and Authorization Functions Supported,” Sensors, vol. 22, no. 20, p. 8024, Oct. 2022, doi: 10.3390/s22208024.</unstructured_citation></citation>
          <citation type="journal_article" key="ref29"><unstructured_citation>R. Kumar, R. Kela, S. Singh, and R. Trujillo-Rasua, “APT attacks on industrial control systems: A tale of three incidents,” International Journal of Critical Infrastructure Protection, vol. 37, p. 100521, Jul. 2022, doi: 10.1016/j.ijcip.2022.100521.</unstructured_citation></citation>
          <citation type="journal_article" key="ref30"><unstructured_citation>R. Buchta, G. Gkoktsis, F. Heine, and C. Kleiner, “Advanced Persistent Threat Attack Detection Systems: A Review of Approaches, Challenges, and Trends,” Digital Threats: Research and Practice, vol. 5, no. 4, pp. 1–37, Dec. 2024, doi: 10.1145/3696014.</unstructured_citation></citation>
          <citation type="journal_article" key="ref31"><unstructured_citation>V. Pedreira, D. Barros, and P. Pinto, “A Review of Attacks, Vulnerabilities, and Defenses in Industry 4.0 with New Challenges on Data Sovereignty Ahead,” Sensors, vol. 21, no. 15, p. 5189, Jul. 2021, doi: 10.3390/s21155189.</unstructured_citation></citation>
          <citation type="journal_article" key="ref32"><unstructured_citation>T. J. Olorunlana and H. Mohammed, “Analysis of the Colonial Pipeline Cybersecurity Incident,” International Journal of Science, Architecture, Technology and Environment, pp. 9–13, Apr. 2025, doi: 10.63680/jngh0767as.</unstructured_citation></citation>
          <citation type="journal_article" key="ref33"><unstructured_citation>W. Alsabbagh, S. Amogbonjaye, D. Urrego, and P. Langendörfer, “A Stealthy False Command Injection Attack on Modbus based SCADA Systems.” [Online]. Available: http://www.scadabr.com.br/</unstructured_citation></citation>
          <citation type="journal_article" key="ref34"><unstructured_citation>V. Kampourakis, G. Kambourakis, E. Chatzoglou, and C. Zaroliagis, “Revisiting man-in-the-middle attacks against HTTPS,” Network Security, vol. 2022, no. 3, Mar. 2022, doi: 10.12968/S1353-4858(22)70028-1.</unstructured_citation></citation>
          <citation type="journal_article" key="ref35"><unstructured_citation>C. Singh and A. K. Jain, “A comprehensive survey on DDoS attacks detection &amp; mitigation in SDN-IoT network,” e-Prime -Advances in Electrical Engineering, Electronics and Energy, vol. 8, no. 3, p. 100543, Jun. 2024, doi: 10.1016/j.prime.2024.100543.</unstructured_citation></citation>
          <citation type="journal_article" key="ref36"><unstructured_citation>I. Odun-Ayo et al., “Evaluating Common Reconnaissance Tools and Techniques for Information Gathering,” Journal of Computer Science, vol. 18, no. 2, pp. 103–115, Feb. 2022, doi: 10.3844/jcssp.2022.103.115.</unstructured_citation></citation>
          <citation type="journal_article" key="ref37"><unstructured_citation>M. M. Alani and E. Damiani, “XRecon: An Explainbale IoT Reconnaissance Attack Detection System Based on Ensemble Learning,” Sensors, vol. 23, no. 11, p. 5298, Jun. 2023, doi: 10.3390/s23115298.</unstructured_citation></citation>
          <citation type="journal_article" key="ref38"><unstructured_citation>V. Vajrobol et al., “Identify spoofing attacks in Internet of Things (IoT) environments using machine learning algorithms,” Journal of High Speed Networks, vol. 31, no. 1, pp. 61–70, Feb. 2025, doi: 10.1177/09266801241295886.</unstructured_citation></citation>
          <citation type="journal_article" key="ref39"><unstructured_citation>B. Khaund, “The Evolution of Denial-of-Service Attacks: From DoS to DDoS –Mechanisms, Impacts, and Defensive Strategies,” European Journal of Computer Science and Information Technology, vol. 13, no. 47, pp. 134–146, Jun. 2025, doi: 10.37745/ejcsit.2013/vol13n47134146.</unstructured_citation></citation>
          <citation type="journal_article" key="ref40"><unstructured_citation>P. Radoglou-Grammatikis, I. Siniosoglou, T. Liatifis, A. Kourouniadis, K. Rompolos, and P. Sarigiannidis, “Implementation and Detection of Modbus Cyberattacks,” in 2020 9th International Conference on Modern Circuits and Systems Technologies (MOCAST), IEEE, Sep. 2020, pp. 1–4. doi: 10.1109/MOCAST49295.2020.9200287.</unstructured_citation></citation>
          <citation type="journal_article" key="ref41"><unstructured_citation>M. A. Al-Shareeda, S. Manickam, S. A. Laghari, and A. Jaisan, “Replay-Attack Detection and Prevention Mechanism in Industry 4.0 Landscape for Secure SECS/GEM Communications,” Sustainability, vol. 14, no. 23, p. 15900, Nov. 2022, doi: 10.3390/su142315900.</unstructured_citation></citation>
          <citation type="journal_article" key="ref42"><unstructured_citation>F. Trungadi et al., “Securing Modbus in legacy industrial control systems: A decentralized approach using proxies, Post-Quantum Cryptography and Self-Sovereign Identity,” Journal of Information Security and Applications, vol. 94, p. 104199, Nov. 2025, doi: 10.1016/J.JISA.2025.104199.</unstructured_citation></citation>
          <citation type="journal_article" key="ref43"><unstructured_citation>D. Upadhyay, S. Ghosh, H. Ohno, M. Zaman, and S. Sampalli, “Securing industrial control systems: Developing a SCADA/IoT test bench and evaluating lightweight cipher performance on hardware simulator,” International Journal of Critical Infrastructure Protection, vol. 47, p. 100705, Dec. 2024, doi: 10.1016/J.IJCIP.2024.100705.</unstructured_citation></citation>
          <citation type="journal_article" key="ref44"><unstructured_citation>V. Varadharajan, U. Tupakula, and K. K. Karmakar, “Techniques for Enhancing Security in Industrial Control Systems,” ACM Transactions on Cyber-Physical Systems, vol. 8, no. 1, pp. 1–36, Jan. 2024, doi: 10.1145/3630103.</unstructured_citation></citation>
          <citation type="journal_article" key="ref45"><unstructured_citation>A. Fielder, T. Li, and C. Hankin, “Defense-in-depth vs. Critical Component Defense for Industrial Control Systems,” Oct. 2016. doi: 10.14236/ewic/ICS2016.1.</unstructured_citation></citation>
          <citation type="journal_article" key="ref46"><unstructured_citation>Y. Li, S. Wu, and Q. Pan, “Network Security in the Industrial Control System: A Survey,” Aug. 2023, [Online]. Available: http://arxiv.org/abs/2308.03478</unstructured_citation></citation>
          <citation type="journal_article" key="ref47"><unstructured_citation>E. Wai and C. K. M. Lee, “Depth in Defense: A Multi-layered Approach to Cybersecurity for SCADA Systems in Industry 4.0,” in Science and Technology: Recent Updates and Future Prospects Vol. 2, B P International, 2024, pp. 124–144. doi: 10.9734/bpi/strufp/v2/12542F.</unstructured_citation></citation>
          <citation type="journal_article" key="ref48"><unstructured_citation>Z. Yang et al., “A systematic literature review of methods and datasets for anomaly-based network intrusion detection,” Comput. Secur., vol. 116, p. 102675, May 2022, doi: 10.1016/J.COSE.2022.102675.</unstructured_citation></citation>
          <citation type="journal_article" key="ref49"><unstructured_citation>L. Diana, P. Dini, and D. Paolini, “Overview on Intrusion Detection Systems for Computers Networking Security,” Computers, vol. 14, no. 3, p. 87, Mar. 2025, doi: 10.3390/computers14030087.</unstructured_citation></citation>
          <citation type="journal_article" key="ref50"><unstructured_citation>S. Dilshan Ranwadana, “Anomaly Detection in Intrusion Detection and Prevention Systems.”</unstructured_citation></citation>
          <citation type="journal_article" key="ref51"><unstructured_citation>S. Maesschalck, V. Giotsas, B. Green, and N. Race, “Don’t get stung, cover your ICS in honey: How do honeypots fit within industrial control system security,” Comput. Secur., vol. 114, p. 102598, Mar. 2022, doi: 10.1016/J.COSE.2021.102598.</unstructured_citation></citation>
          <citation type="journal_article" key="ref52"><unstructured_citation>C. Zanasi, F. Magnanini, S. Russo, and M. Colajanni, “A Zero Trust approach for the cybersecurity of Industrial Control Systems,” in 2022 IEEE 21st International Symposium on Network Computing and Applications (NCA), IEEE, Dec. 2022, pp. 1–7. doi: 10.1109/NCA57778.2022.10013559.</unstructured_citation></citation>
          <citation type="journal_article" key="ref53"><unstructured_citation>W. Yeoh, M. Liu, M. Shore, and F. Jiang, “Zero trust cybersecurity: Critical success factors and A maturity assessment framework,” Comput. Secur., vol. 133, p. 103412, Oct. 2023, doi: 10.1016/J.COSE.2023.103412.</unstructured_citation></citation>
          <citation type="journal_article" key="ref54"><unstructured_citation>A. Pigola and F. de S. Meirelles, “Zero trust in cybersecurity: managing critical challenges for effective implementation,” Journal of Systems and Information Technology, Apr. 2025, doi: 10.1108/JSIT-08-2024-0326.</unstructured_citation></citation>
          <citation type="journal_article" key="ref55"><unstructured_citation>A. Elmarkez, S. Mesli-Kesraoui, P. Berruet, and F. Oquendo, “Security by Design for Industrial Control Systems from a Cyber–Physical System Perspective: A Systematic Mapping Study,” Machines, vol. 13, no. 7, p. 538, Jun. 2025, doi: 10.3390/machines13070538.</unstructured_citation></citation>
          <citation type="journal_article" key="ref56"><unstructured_citation>X. Niu, M. M. Cook, and D. Pezaros, “Examining the Suitability of Stream Ciphers for Modbus-TCP Encryption on Resource Constrained Devices,” in Proceedings of the 17th European Workshop on Systems Security, New York, NY, USA: ACM, Apr. 2024, pp. 51–57. doi: 10.1145/3642974.3652287.</unstructured_citation></citation>
          <citation type="journal_article" key="ref57"><unstructured_citation>S. Figueroa-Lorenzo, J. Añorga, and S. Arrizabalaga, “A Role-Based Access Control Model in Modbus SCADA Systems. A Centralized Model Approach.,” Sensors (Basel), vol. 19, no. 20, Oct. 2019, doi: 10.3390/s19204455.</unstructured_citation></citation>
          <citation type="journal_article" key="ref58"><unstructured_citation>A. Dehlaghi-Ghadim, A. Balador, M. H. Moghadam, H. Hansson, and M. Conti, “ICSSIM — A framework for building industrial control systems security testbeds,” Comput. Ind., vol. 148, p. 103906, Jun. 2023, doi: 10.1016/J.COMPIND.2023.103906.</unstructured_citation></citation>
          <citation type="journal_article" key="ref59"><unstructured_citation>Y. Jiang et al., “MITRE ATT&amp;CK Applications in Cybersecurity and The Way Forward,” Feb. 2025, [Online]. Available: http://arxiv.org/abs/2502.10825</unstructured_citation></citation>
          <citation type="journal_article" key="ref60"><unstructured_citation>B. Al-Sada, A. Sadighian, and G. Oligeri, “Analysis and Characterization of Cyber Threats Leveraging the MITRE ATT&amp;amp;CK Database,” IEEE Access, vol. 12, pp. 1217–1234, 2024, doi: 10.1109/ACCESS.2023.3344680.</unstructured_citation></citation>
          <citation type="journal_article" key="ref61"><unstructured_citation>A. Georgiadou, S. Mouzakitis, and D. Askounis, “Assessing MITRE ATT&amp;CK Risk Using a Cyber-Security Culture Framework.,” Sensors (Basel), vol. 21, no. 9, May 2021, doi: 10.3390/s21093267.</unstructured_citation></citation>
          <citation type="journal_article" key="ref62"><unstructured_citation>B. Al-Sada, A. Sadighian, and G. Oligeri, “MITRE ATT&amp;amp;CK: State of the Art and Way Forward,” ACM Comput. Surv., vol. 57, no. 1, pp. 1–37, Jan. 2025, doi: 10.1145/3687300.</unstructured_citation></citation>
          <citation type="journal_article" key="ref63"><unstructured_citation>A.-S. Bader, A. Sadighian, and G. Oligeri, “MITRE ATT&amp;CK: State of the Art and Way Forward.” doi: XXXXXXX.XXXXXXX.</unstructured_citation></citation>
          <citation type="journal_article" key="ref64"><unstructured_citation>A. F. Syifa and M. Salman, “Cyber Kill Chain Framework Approach to Map Potential Attack Vectors on Windows-based OS,” International Journal of Electrical, Computer, and Biomedical Engineering, vol. 3, no. 1, May 2025, doi: 10.62146/ijecbe.v3i1.107.</unstructured_citation></citation>
          <citation type="journal_article" key="ref65"><unstructured_citation>X. Qin, F. Jiang, M. Cen, and R. Doss, “Hybrid cyber defense strategies using Honey-X: A survey,” Computer Networks, vol. 230, p. 109776, Jul. 2023, doi: 10.1016/J.COMNET.2023.109776.</unstructured_citation></citation>
          <citation type="journal_article" key="ref66"><unstructured_citation>M. Sprengers and J. van Haaster, “Organization of #operations,” Cyber Guerilla, pp. 41–109, 2016, doi: 10.1016/B978-0-12-805197-9.00003-6.</unstructured_citation></citation>
          <citation type="journal_article" key="ref67"><unstructured_citation>S. M. Khalil, H. Bahsi, and T. Korõtko, “Threat modeling of industrial control systems: A systematic literature review,” Comput. Secur., vol. 136, p. 103543, Jan. 2024, doi: 10.1016/J.COSE.2023.103543.</unstructured_citation></citation>
          <citation type="journal_article" key="ref68"><unstructured_citation>K. H. Kim, K. Kim, and H. K. Kim, “STRIDE‐based threat modeling and DREAD evaluation for the distributed control system in the oil refinery,” ETRI Journal, vol. 44, no. 6, pp. 991–1003, Dec. 2022, doi: 10.4218/etrij.2021-0181.</unstructured_citation></citation>
          <citation type="journal_article" key="ref69"><unstructured_citation>Z. Nadifi, M. Ouaissa, M. Ouaissa, M. Alhyan, and A. Kartit, “STRIDE-Based Threat Modeling and Risk Assessment Framework for IoT-enabled Smart Healthcare Systems,” International Journal of Online and Biomedical Engineering (iJOE), vol. 21, no. 09, pp. 63–80, Jul. 2025, doi: 10.3991/ijoe.v21i09.55517.</unstructured_citation></citation>
          <citation type="journal_article" key="ref70"><unstructured_citation>S. A. Khan and R. A. Khan, “Confidentiality Quantification Model at Design Phase,” International Journal of Information and Education Technology, pp. 535–537, 2012, doi: 10.7763/ijiet.2012.v2.199.</unstructured_citation></citation>
          <citation type="journal_article" key="ref71"><unstructured_citation>J. De and L. Cruz, “Security Chaos Engineering and the Application of Threat Modeling.”</unstructured_citation></citation>
          <citation type="journal_article" key="ref72"><unstructured_citation>M. Pendleton and J.-H. Cho, “A A Survey on Systems Security Metrics 1.”</unstructured_citation></citation>
          <citation type="journal_article" key="ref73"><unstructured_citation>A. Z. Zaidi, C. Y. Chong, Z. Jin, R. Parthiban, and A. S. Sadiq, “Touch-based continuous mobile device authentication: State-of-the-art, challenges and opportunities,” Journal of Network and Computer Applications, vol. 191, p. 103162, Oct. 2021, doi: 10.1016/J.JNCA.2021.103162.</unstructured_citation></citation>
          <citation type="journal_article" key="ref74"><unstructured_citation>L. Song, X. Ju, Z. Zhu, and M. Li, “An access control model for the Internet of Things based on zero-knowledge token and blockchain,” EURASIP J. Wirel. Commun. Netw., vol. 2021, no. 1, Dec. 2021, doi: 10.1186/s13638-021-01986-4.</unstructured_citation></citation>
          <citation type="journal_article" key="ref75"><unstructured_citation>S. M. Khalil, H. Bahsi, H. O. Dola, T. Korõtko, K. McLaughlin, and V. Kotkas, “Threat Modeling of Cyber-Physical Systems - A Case Study of a Microgrid System,” Comput. Secur., vol. 124, p. 102950, Jan. 2023, doi: 10.1016/J.COSE.2022.102950.</unstructured_citation></citation>
          <citation type="journal_article" key="ref76"><unstructured_citation>L. Mauri and E. Damiani, “Modeling Threats to AI-ML Systems Using STRIDE,” Sensors, vol. 22, no. 17, p. 6662, Sep. 2022, doi: 10.3390/s22176662.</unstructured_citation></citation>
          <citation type="journal_article" key="ref77"><unstructured_citation>J. L. Salas-Riega, Y. Riega-Virú, M. Ninaquispe-Soto, and J. M. Salas-Riega, “Cybersecurity and the NIST Framework: A Systematic Review of its Implementation and Effectiveness Against Cyber Threats,” International Journal of Advanced Computer Science and Applications, vol. 16, no. 6, 2025, doi: 10.14569/IJACSA.2025.0160672.</unstructured_citation></citation>
          <citation type="journal_article" key="ref78"><unstructured_citation>“The NIST Cybersecurity Framework (CSF) 2.0,” Feb. 2024. doi: 10.6028/NIST.CSWP.29.</unstructured_citation></citation>
          <citation type="journal_article" key="ref79"><unstructured_citation>A. Hahn, R. K. Thomas, I. Lozano, and A. Cardenas, “A multi-layered and kill-chain based security analysis framework for cyber-physical systems,” International Journal of Critical Infrastructure Protection, vol. 11, pp. 39–50, Dec. 2015, doi: 10.1016/J.IJCIP.2015.08.003.</unstructured_citation></citation>
          <citation type="journal_article" key="ref80"><unstructured_citation>A. Robles-Durazno, N. Moradpoor, J. McWhinnie, G. Russell, and J. Porcel-Bustamante, “Implementation and Evaluation of Physical, Hybrid, and Virtual Testbeds for Cybersecurity Analysis of Industrial Control Systems,” Symmetry (Basel)., vol. 13, no. 3, p. 519, Mar. 2021, doi: 10.3390/sym13030519.</unstructured_citation></citation>
          <citation type="journal_article" key="ref81"><unstructured_citation>H. Cui, F. Li, and K. Tomsovic, “Cyber‐physical system testbed for power system monitoring and wide‐ area control verification,” IET Energy Systems Integration, vol. 2, no. 1, pp. 32–39, Mar. 2020, doi: 10.1049/iet-esi.2019.0084.</unstructured_citation></citation>
          <citation type="journal_article" key="ref82"><unstructured_citation>M. Alanazi, A. Mahmood, and M. J. M. Chowdhury, “SCADA vulnerabilities and attacks: A review of the state‐ of‐ the‐ art and open issues,” Feb. 01, 2023, Elsevier Ltd. doi: 10.1016/j.cose.2022.103028.</unstructured_citation></citation>
          <citation type="journal_article" key="ref83"><unstructured_citation>M. S. Abdelrahman, I. Kharchouf, T. L. Nguyen, and O. A. Mohammed, “A Hybrid Physical Co-Simulation Smart Grid Testbed for Testing and Impact Analysis of Cyber-Attacks on Power Systems: Framework and Attack Scenarios,” Energies (Basel)., vol. 16, no. 23, p. 7771, Nov. 2023, doi: 10.3390/en16237771.</unstructured_citation></citation>
        </citation_list>
      </journal_article>
    </journal>
  </body>
</doi_batch>
