
This paper proposes the use of n-grams to enhance anomaly detection in operational technology (OT) networks using byte-histograms. Byte histograms are highly effective at detecting anomalies but they often require domain-specific optimization techniques for reliable performance without an abundance of false alarms. The proposed technique does not require deep-packet inspection or protocol-specific information (beyond the physical and datalink layer), making the approach transferable and generalizable. Five different weighting schemes are used with similarity scores to fine tune n-gram evaluation and optimize anomaly detection. Furthermore, experimental results using an OT network traffic dataset show that it is possible to achieve good anomaly detection rates without any protocol-specific knowledge. Testing our generalized approach against this dataset shows an F1 score of 93.9
Security Operations Centers (SOCs) grapple with analyst fatigue driven by over-whelming alert volumes and repetitive, low-value notifications. This work investigates whether verified Cyber Threat Intelligence (CTI) feeds can be leveraged, in real time, to suppress noise and surface genuine risk across a distributed Network Intrusion Detection System (NIDS) of Suricata sensors. We present a streaming methodology that (i) correlates each alert group with curated, verified CTI indicators (e.g., URL, Domains, IPv4, IPv6, SHA256, MD5 etc.) and (ii) deduplicates and groups recurrent, identical alerts across sensors within a configurable time window, to adjust triage priority. Suricata’s native severities (1–3, with 3 being lowest) are treated as an initial signal that can be dynamically recalibrated by CTI context, campaign prevalence, indicator freshness, and observed recurrence across sites. Using this approach, we demonstrate that the total number of alerts presented to analysts can be reduced to a small fraction of the baseline over the same interval—without sacrificing coverage—by suppressing groups with negative or stale CTI evidence and by collapsing duplicates. Conversely, we show that alerts initially labeled with severity 3 can warrant promotion when corroborated by high-confidence CTI (e.g., active infrastructure, recent sightings, or linkage to ongoing campaigns), thereby preventing critical misses hidden among “low” severity events. The results suggest that real-time CTI correlation paired with alert grouping meaningfully lowers cognitive load, improves prioritization fidelity, and provides a principled path to balancing recall and workload in production SOCs.
As connectivity increases in automotive and rail transport, operators need comprehensive security monitoring solutions. This paper presents a multi modal Vehicle Security Operations Center architecture that covers automotive and rail systems across vendors and integrates the VATT EK framework for standardized attack classification. It implements a five step data processing model from raw data collection through Electronic Control Unit and domain monitoring to vehicle and fleet specific analysis. The model uses intelligent sensors, a Vehicle Security Event Center and a central VSOC. New cross vendor security event and alert formats extend existing AUTOSAR standards with forensic fields such as rule_id, severity and confidence to enable GDPR compliant resource and data efficient monitoring. Scenario-based evaluations demonstrate that the architecture meets defined VSOC requirements. The solution provides a scalable foundation for future autonomous transport applications.
Software vulnerabilities in critical infrastructure components can lead to severe disruptions. While fuzzing effectively identifies such weaknesses, the quality of initial seed inputs significantly impacts its effectiveness. This study evaluates how large language models (LLMs) can generate better fuzzing seeds for critical infrastructure software. We compared seven LLMs—ChatGPT-4-Turbo, Claude 3.0 Opus, Claude 3.7 Sonnet, DeepSeek-V3, Gemini 2.0 Flash, Grok 3, and Mistral 7B—with manual baselines across six programs, including industrial control libraries, routing components, and network firmware. Over 20 independent 24-h campaigns per model and program, LLM-generated seeds achieved 14.8 .
This paper proposes a novel workflow to prevent software and test report tampering. This plays a crucial role in industries operating in critical infrastructures where special emphasis is placed on the reliability of these reports for audits. Looking at the state-of-the-art, we identify tampering with test code, pseudo-accountability, and error-prone manual testing as problems that need to be dealt with. Our proposed workflow can be regularly initiated by a supervisor. It identifies every contributor to a project in a set time and asks them to verify their contributions and ultimately sign off on these contributions. This allows for straightforward and thorough reviews of a release and leads to enhanced tamper resistance, protecting the project against malicious alterations.
The demands increasingly placed on distribution grids by moving from simple distribution to bidirectional flows of future smart distribution grids that must also be constrained to ensure robust operation require a substantial increase in instrumentation for distribution networks. This instrumentation represents a possible target for both isolated and coordinated attacks, given the large number of nodes and distribution. In this paper we therefore study mechanisms for enhanced resilience for the control and communication (C2) paths as the topology of the actual power network is assumed to involve greater cost in modification. We explore algorithms over a hierarchical multilayer graph model in which multiple distant adversaries can manipulate C2 paths and vertices in future smart distribution grids and study how the grid operator can retain full or partial control over the distribution network under these circumstances, discussing different scenarios under different adversarial capability assumptions, study both static and dynamic adversaries, as well as conservative and risk taking defense approaches a grid operator can take.
Structural shifts in the Incident Command System (ICS) and communication networks during cyber incidents were analyzed through six Tabletop Exercises (TTXs) simulating a scenario with evolving priorities, from cybersecurity to operational safety. The early phase featured centralized coordination by the Computer Security Incident Response Team (CSIRT), while later phases exhibited a transition toward field-led, decentralized responses as safety threats emerged. Analysis of communication logs and participant surveys indicated that tools such as organizational charts and predefined workflows, although effective for cybersecurity phases, may become bottlenecks in safety-critical situations. Exercises involving culturally neutral, mixed-role participants enabled observation of ideal ICS transitions, free from organizational bias or authority constraints. Findings suggest that adaptive ICS frameworks, incorporating clear authority-transfer triggers and flexible communication patterns, are essential for timely incident response. Emphasis is also placed on psychological safety, which supports effective leadership transitions in high-stress scenarios. These insights contribute to the design of cyber-physical incident training and enhance resilience through phase-specific coordination models and human-centered preparedness strategies.
The increasing complexity and volume of cybersecurity threats present significant challenges for CISO function (hereafter, “CISO function”: the CISO and delegated security leadership teams such as SOC/IR, risk, compliance, and security architecture) tasked with protecting critical information infrastructure. Traditional risk assessment methods often struggle to keep pace with the rapidly evolving threat landscape, leading to potential gaps in coverage and regulatory non-compliance. To address this, this paper proposes a novel method that integrates Generative Artificial Intelligence (GenAI) into threat risk management. The proposed dual GenAI architecture, consisting of a primary risk analysis engine and an independent verification layer, demonstrated high alignment with expert evaluations in experimental testing, achieving high accuracy in certain risk scenarios. This method also reduces the risk of hallucinations and ensures compliance with evolving regulatory frameworks through a structured, prompt-driven analysis workflow. The achieved results indicate that the proposed method can significantly improve the precision of risk assessments, providing a scalable and legally defensible solution for CISO function. This work represents a substantial advancement in the integration of GenAI for critical infrastructure protection, offering a practical, data-driven alternative to conventional risk management approaches.
This paper presents a summary and comparison of leading secure Industrial Control System (ICS) communication protocols. We find two categories of ICS protocols: those that run an insecure ICS protocol over TLS and those that use a bespoke security protocol. We assess the key properties of bespoke ICS protocols using formal modelling, for OPC-UA and DNP3-SAv5 we use existing models, and we build formal models for S7Comm-Plus and SSP-21; this lets us make a full comparison between these protocols. For ICS protocols based on TLS, we compare the versions and configurations of TLS specified, and any access control add-ons. This leads to a detailed picture of the security provided and best use cases for each protocol.
This paper investigates how information classification is conducted in practice. Despite being a foundation of risk management work, information classification remains understudied from a practical perspective. This study uses semi-structured interviews and a small-scale experiment with professionals from a consultancy firm operating at a national level to explore how information assets are identified, valued and classified. The findings show that information classification is not a purely formalized process, but a collaborative and interpretative activity in which formal models are often adapted or bypassed in favor of context-specific reasoning. Key challenges in practice include inconsistent use of terminology, subjective judgments, and the limitations of classification schemes. The study highlights a need for a shared understanding and trust among participants, which were important factors for successful classification activities, especially in inter-organizational contexts. A three-step approach is thus proposed that emphasizes the value of information in organizational processes before assessing its protection needs. This new approach contributes to a more value-oriented understanding of assets instead of viewing them solely from the perspective of loss or damage. Future research could extend the findings presented.
The increasing complexity of cyber threats, particularly in critical infrastructure sectors, has amplified the need for a skilled and adaptable cybersecurity workforce. While frameworks such as the European Cybersecurity Skills Framework (ECSF) and the Cyber Security Body of Knowledge (CyBOK) offer structured representations of professional cyber career roles, skills and foundational knowledge areas, practical guidance on how to use them together for designing industry-aligned training programs remains limited. This paper addresses this gap by demonstrating how the compatibility between ECSF and CyBOK can inform the development of targeted, role-based training programs aimed at accelerating the upskilling of the cybersecurity workforce. Building on our recent compatibility study that mapped ECSF career role profiles to CyBOK knowledge areas, we present a practical use case focused on the Cyber Threat Intelligence Specialist career role. We detail a methodology for translating ECSF-CyBOK mappings into a modular training program, showcasing the design approach and the practical value of “joining the dots” between career roles, skills and knowledge. The proposed approach offers a replicable methodology to be applied to other roles and sectors, supporting the systematic design of tailored training programs aligned with evolving industry needs and regulatory requirements.
The increasing digitalization of power systems into “smart grids” has introduced complex cybersecurity challenges. Although technical solutions dominate research in this area, non-technical factors crucial to smart grid cybersecurity remain unknown. This paper presents a systematic review of 27 studies examining how human and organizational factors are addressed in the smart grid cybersecurity literature. Our analysis reveals three key limitations: (1) a disconnect between proposed solutions and real-world challenges; (2) an overemphasis on individual operator decision-making during cyber incidents, despite empirical evidence supporting collaborative approaches; and (3) the imprecise use of concepts like “cybersecurity awareness” and “security culture”, neglecting established human factors literature developed around these concepts. Future research should ground interventions in real-world operational complexities, ensuring alignment between empirical and methodological approaches.
Cyber-physical systems requires threat models that account for cyber and physical vulnerabilities alike. We present the CPSTRIDE framework, which extends the classic STRIDE model with a novel Cyber-Physical Flow Diagram and updated Security Property and Threat definitions. We demonstrate CPSTRIDE’s utility by modeling threats beyond STRIDE’s capabilities, and employ LLM assistance to identify threats in an additive manufacturing context.
The exponential growth of Android smartphone usage has elevated the relevance of Android-focused mobile forensics in both criminal investigations and cybersecurity domains. This paper presents a systematic literature review (SLR) of methodologies, tools, and challenges associated with forensic investigations of Android applications. The review synthesizes current practices in data acquisition and evaluates the performance of widely used forensic tools, while also discussing emerging trends and critical limitations. This study aims to provide a comprehensive reference for practitioners and researchers, to highlight best practices, and to propose future directions to enhance reliability, reproducibility, and legal defensibility in Android forensic investigations.
Designing high-quality cyber exercises requires more than technical fidelity, it demands credible narratives, immersive scenarios and expert-driven coordination. In this paper, we present a case study from the 2024 Austrian National Cybersecurity Exercise, exploring how ChatGPT was integrated into scenario design, infrastructure development and content creation. We identify four core quality criteria for cyber exercises (credibility, immersion, technical fidelity and expertise) and examine how AI-supported workflows influenced each criterion. Our findings show that ChatGPT can accelerate ideation, reduce drafting time and increase creative flexibility, particularly during early-stage design. At the same time, we highlight structural limitations, including hallucinations, lack of temporal state awareness and restricted utility in offensive simulation. We argue that AI does not replace human expertise but reshapes its application, moving expert input downstream into validation and strategic alignment. The paper concludes with a set of practical observations derived from hands-on use, offering insights for practitioners seeking to integrate AI tools into complex simulation environments, such as gains in early-phase efficiency, improved change resilience but also above mentioned risks and the continued need for expert validation.
As cyber threats targeting critical infrastructures grow in complexity and societal impact, the focus of cybersecurity must shift from mere protection to sustained resilience. This paper proposes a conceptual multi-dimensional scoring framework to be utilized by cyber ranges to assess and quantify the cyber resilience of critical infrastructure organizations. The framework is built upon seven interrelated cyber resilience dimensions across the technical, operational, and human spectrum. For each dimension, initial performance indicators are proposed to standardize the evaluation process and enable organizations to benchmark their cyber resilience, identify skill and coordination gaps, and align cybersecurity training with real-world mission continuity requirements. The proposed multi-dimensional approach provides a structured performance evaluation that is aligned with NIS2 regulation requirements, supporting compliance readiness and enabling tailored workforce development interventions. This contribution aims to enhance organizations’ preparedness in safeguarding essential services under adverse conditions.
The increase in cyber attacks impacting critical infrastructure and the economy motivates a focus on cybersecurity defense and awareness. However, a knowledge gap exists in both the technical and non-technical understanding of cybersecurity, creating a weakness in the global and US cybersecurity workforce. Closing this gap requires a multi-faceted approach, but of extreme importance is education. We use the NICE Workforce Framework TKS statements to develop a model of the most generalizable requirements needed to work in cybersecurity. We seek to apply this model to increase the Cybersecurity Language use in all K-12 subjects, walking educators and content developers through a process incorporating cybersecurity into their lessons.
CY-TRUST introduces a federated framework for deploying sectorial Security Operations Centers (SOCs) to enhance national and EU-level cybersecurity resilience. Focused on Cyprus’s critical sectors energy, maritime, government, and SMEs, the architecture supports scalable, standards-based implementations aligned with NIS2 and the Cyber Resilience Act. Each sectorial SOC integrates AI-driven situational awareness, incident response playbooks, and structured Cyber Threat Intelligence (CTI) sharing via Structured Threat Information Expression (STIX). It also integrates Trusted Automated Ex-change of Intelligence Information (TAXII), and the Malware Information Sharing Platform (MISP). A multi domain ICT/Maritime/Industrial cyber range, Cyber Threat Realm (CTR), ensures continuous training and preparedness. Three SOC deployment variants accommodate varying stakeholder maturity, coordinated through a national backend operated by the Digital Security Authority. CY-TRUST aligns with EU initiatives such as JCOP, NG-SOC, and PHOENi2X, and provides a replicable blueprint for federated SOC ecosystems. This paper presents the architecture and implementation approach of CY-TRUST, demonstrating its value as a strategic model for adaptive and collaborative cyber defense.
Autonomous vehicles (AVs) rely on interconnected sensing and communication systems to support navigation, coordination, and decision-making. While this connectivity enhances safety and efficiency, it also broadens the attack surface, exposing AVs to cyber threats that can compromise operational reliability. Among these threats, message spoofing, i.e., injection of falsified or manipulated data into in-vehicle or Vehicle-to-Vehicle (V2V) communication channels—poses a critical risk, as it can mislead vehicle perception, disrupt cooperative behavior, and undermine traffic safety. This systematic literature review analyzes studies published between 2015 and 2025, examining spoofing attacks targeting AV communication layers and surveying the full range of detection and mitigation mechanisms proposed in the literature. The review considers both traditional security techniques and emerging artificial intelligence (AI)–driven approaches, assessing how AI is being incorporated alongside conventional methods. Through a structured review process, the study synthesizes attack vectors, defense strategies, and technological trends, highlighting the growing role of AI in enhancing AV resilience. The review aims to consolidate current knowledge and outline key considerations for designing robust, multi-layered cybersecurity frameworks that support the safe integration of autonomous vehicles into connected transportation ecosystems.
Small-to-Medium-sized Enterprises (SMEs) represent the vast majority of businesses in the UK and many other countries. At the same time, however, SMEs can often lack preparedness in relation to cyber security. This becomes problematic for SMEs in their own right, as well as in the context of supply-chains for larger organisations. Despite the availability of information and resources many SMEs are challenged by a lack of understanding and skills to help address questions and enact advice. Based upon ongoing research into the support available to SMEs, this paper proposes the concept of Cyber Security Communities of Support. The discussion presents the principles of the communities, as well as various practical considerations to be accounted for in operationalizing the approach (including the provision of an online Support Broker platform as an enabler for community dialogue). Finally, attention is given towards the planning for a series of pilot communities, from which it is intended that the findings will help to provide the basis for an ongoing and replicable model of support.