<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>The Attack Vector on the Critical Information Infrastructure of the Fuel and Energy Complex Ecosystem</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Nikolai Korneev</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>All-Russian Research Institute for Civil Defence of the EMERCOM of Russia</institution>
          ,
          <addr-line>7 Davydkovskaya Street, Moscow, 121352</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Financial University under the Government of the Russian Federation</institution>
          ,
          <addr-line>49 Leningradsky Prospekt, Moscow, 125993</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>National University of Oil and Gas Gubkin University</institution>
          ,
          <addr-line>65 Leninsky Prospekt, Moscow, 119991</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>59</fpage>
      <lpage>65</lpage>
      <abstract>
        <p>There was carried out a comprehensive analysis and determined digital transformation tasks of the existing infrastructure for the fuel and energy market participants. Considering digital transformations of the existing infrastructure there were proposed ecosystem components for major participants of the fuel and energy market. A new concept of the attack vector on the infrastructure (in particular, the critical information infrastructure) was formulated on the basis of the information and energy approach and there was shown its relevance in the information security field of Automated Process Control System (APCS) and SCADA. Practical examples demonstrated how to get an attack vector on the infrastructure using the classical testing theory on the example of Web-Applications and Modbus serial communication protocol. The OWASP Web-Application Security Testing Guide was used as a guideline. It was proposed to deliberately limit the space of the attack vector on the infrastructure by the Descartes basis of information leaks and digital footprints. Separate Google Dorks have been developed for each manufacturer of embedded systems for APCS and SCADA. Penetration testing was performed as an example of APCS and SCADA on port 502 of the modbus protocol using Nmap.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Complex security</kwd>
        <kwd>APCS</kwd>
        <kwd>SCADA</kwd>
        <kwd>digital trace</kwd>
        <kwd>digital transformation</kwd>
        <kwd>industry 5</kwd>
        <kwd>0</kwd>
        <kwd>cyberattack</kwd>
        <kwd>society 5</kwd>
        <kwd>0</kwd>
        <kwd>OWASP</kwd>
        <kwd>Nmap</kwd>
        <kwd>Google Dorks</kwd>
        <kwd>ecosystem</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The structure of information processing systems changes fundamentally which is now based on
distributed information-computing networks, connected to global data networks, convergent,
hyperconverged, neuromorphic and quantum computing systems. At the same time, regulatory
requirements are toughen, especially, in terms of complex object security: physical, economic, fire,
informational, psychological, intellectual property security, technogenic, security against terrorism,
ecological safety and power security.</p>
      <p>
        For the fuel and energy complex (FEC) – this is first and foremost Energy security doctrine of the
Russian Federation (Decree of the President of the Russian Federation 13.05.2019 № 216), new
version of the information security Doctrine (Decree of the President of the Russian Federation
05.12.2016 № 646), Federal law July 26, 2017 № 187-FL "On the Security of the Russian Federation
Critical Data Infrastructure, Federal law July 21, 2011 № 256-FL "On the safety of fuel and energy
complex facilities", Federal law July 27, 2006 № 149-FL "About information, information technology
and data security ". In these documents, the priority is given to the fuel and energy complex facilities
safety, including through continuous monitoring of object operation threats [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>Considering the National Strategy for the development of artificial intelligence for the period up to
2030 (Decree of the President of the Russian Federation No. 490 of 10.10.2019), security issues of
critical facilities of the fuel and energy complex should be solved using data mining, where the
digitalization of business processes of the fuel and energy complex plays a central role.</p>
      <p>In this regard, all fuel and energy market participants have to solve digital transformation problems
of the existing infrastructure.</p>
      <p>Experience shows that such an approach leads to the creation of its own artificial ecosystems that
can solve a whole range of problems, including the safety of fuel and energy complex facilities. The
example of such a system is the Sberbank ecosystem, where the services integration is achieved by
the effective use of digital technologies, taking into account financial and economic goals of digital
transformation. Major fuel and energy market players will have to similarly solve their digital
transformation tasks of the existing infrastructure.</p>
    </sec>
    <sec id="sec-2">
      <title>2. The materials and approach</title>
      <p>As ecosystem components for major players of the fuel and energy market, considering digital
transformations of the existing infrastructure, we can distinguish the following transformation tasks:
• digital means of labor, for example, digital birthplaces, digital seismic reflection, unmanned
aerial vehicles, etc.;
• digital tools, such as digital oil refineries;
• smart employees who use the ecosystem to perform their job responsibilities effectively.</p>
      <p>Due to the dynamic development of the facility and its environment, the components composition
is not limited to the above.</p>
      <p>
        Modern or large automated process control systems (APCS) are not possible without
supervisory dispatch control and data acquisition (SCADA) systems. APCS examples can be such
critical information infrastructures (CII) as: transport management systems and networks, power
supply management systems and networks, heat supply management systems and networks, fuel and
energy complex (FEC) management systems and networks, nuclear power plant management systems
and networks, etc. On the one hand, all these modern systems and networks are based on automatic
control principles [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] and use digital data in APCS and SCADA [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. On the other hand, they are
represented as an information processing system [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] that is vulnerable to the corresponding
destabilizing factors [
        <xref ref-type="bibr" rid="ref4 ref5 ref6">4, 5, 6</xref>
        ] according to the ISO/IEC 27002 standard, including cyber attacks,
malware, such as "Triton" [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], "Irongate" [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and modules for frameworks, such as "Autosploit" [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ],
"ICSSPLOIT", "Metasploit", "Core Impact", and "Immunity Canvas".
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Results</title>
      <p>There are several communication protocols that are used in APCS and SCADA. Unlike Ethernet or
Internet Protocols (IP), automated control system uses several protocols that are often unique to the
PLC-controller manufacturer. The most popular are Modbus, dnp, dnp3, fieldbus, Ethernet/IP,
EtherCAT and profinet.</p>
      <p>
        Primarily, such a wide specification determines the need to form a unique vector to directly
display the object and the environment state [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], based on diagnostic information on the object and
the most complete information of the environment state – available for APCS and SCADA. Further,
we will call such diagnostic information – an attack vector on the infrastructure, for example, CII.
      </p>
      <p>
        At the same time, we cannot assume that this information is identical to the equation given in the
work [
        <xref ref-type="bibr" rid="ref10 ref3">3, 10</xref>
        ], for this reason:
      </p>
      <p>[k + 1] = Ф  ,  ,  ,   [ ] + Г[ ] [ ] +  [ ] [ ] [ + 1],
where  [k + 1],  [ ] – the most accurate possible vectors evaluations of the object state and
environment; Ф  ,  ,  ,  – state transition function determined by the most accurately known
parameters of the object state and environment;  [ ] – vector evaluation of direct environmental
impacts; Г[ ] [ ],  [ ] [ ] – integral transformations of the most accurately represented controlling
and disturbing influences.</p>
      <p>(1)</p>
      <p>
        Secondly, given specification of unique PLC-controllers for the manufacturer requires adequate
"unique" methods of information security (corresponding to the APCS and SCADA) from
destabilizing factors [
        <xref ref-type="bibr" rid="ref11 ref12 ref13 ref14 ref4 ref5">4, 5, 11, 12, 13, 14</xref>
        ] (cyberattack, malware), which consider the specified attack
vector on the infrastructure, for example, on the basis of the integrated security core [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ].
      </p>
      <p>
        Finally, it is necessary to implement proposed information security methods in the projects on
information and integrated security of CII. Methodological basis of this approach was set out in [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref3 ref5">3, 5,
10, 11, 12</xref>
        ]. In this article we will demonstrate how to practically get such an attack vector on the
infrastructure, using the classical testing theory on the example of Web-applications and the Modbus
serial communication protocol. For this purpose, we will develop separate Google Dorks for each
manufacturer of embedded systems for APCS. In order to form the attack vector on the infrastructure,
we will conduct penetration testing for APCS and SCADA using Nmap.
      </p>
      <p>Modbus – is a serial communication protocol originally published by Modicon (now Schneider
Electric) in 1979 to be used with its PLC-controllers. In fact, Modbus became a standard
communication protocol in APCS/SCADA.</p>
      <p>
        As a methodological guide we use the OWASP Web-application security testing guide [
        <xref ref-type="bibr" rid="ref15 ref16 ref17 ref18">15, 16, 17,
18</xref>
        ], paragraphs 4.1.1. "Search engines usage for information leaks", 4.1.2. (4.1.9) "Web-server
fingerprints (application)". Thus, we will deliberately limit the space of the attack vector on the
infrastructure [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] by the Descartes basis of information leaks and digital footprints.
      </p>
      <p>
        To form the information leaks basis we use the Shodan search engine which allows to identify
banners and information or parameters that they disclose [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ]. Since Modbus works on port 502, in
the search box we write "port:502" (Figure 1).
      </p>
      <p>Although there is no guarantee that all these IP-addresses work with Modbus, but most of them do,
because 502 is a popular port, but not the only for Modbus. The protocol can be also identified by
"Modbus Bridge", "ModbusGW", "HMS AnyBus-S WebServer", "title:'Carel pCOWeb Home Page'".
However, SCADA systems are mostly used in the global Internet. They can be determined not only
by the port, but also by the manufacturer. The "SCADA" query gives 2.925 results, but you can find
27 Schneider Electric servers with the "ClearSCADA" query.</p>
      <p>Also, queries that can find APCS or SCADA have the following format: "port:2404 asdu address",
"I20100 port:10001", «"port:789 product:""Red Lion Controls"""», "ISC SCADA Service
HTTPserv:00001", «port:4800 'Moxa Nport'», "Reliance 4 Control Server", "Welcome to the
Windows CE Telnet Service on HMI_Panel", "Schneider Electric EGX300", etc.</p>
      <p>
        To form the basis of digital footprints we use Google dorks. It is well known that Google stores
and indexes the information which finds on websites. However, Google has its own language to
extract the information [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] which we used to form Google dorks.
      </p>
      <p>
        As an example we use Google Dork for PLC-controllers Siemens S7. It is almost the same
generation of controllers that was the target of the Stuxnet attack on Iran's uranium enrichment plants
in 2010, and probably, is the most complex attack on APCS in history [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]. Google Dork for this
controller: «inurl:/Portal/Portal.mwsl». Figure 2 shows an example of the query.
      </p>
      <p>There is no single Google Docs that would disclose every SCADA interface, instead, you need to
learn about the manufacturer and used products. Each company creates its own embedded systems for
automated process control systems. They use common protocols and procedures, but in general they
are unique. In addition, each of these companies produces several products. To find these products
used in APCS together with Google, we have developed separate Google Docs for each manufacturer
and product. In Table 1, there is a short list according to manufacturers, products and developed
Google Dorks.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Experiment and Discussion</title>
      <p>
        We will conduct penetration testing for APCS and SCADA using Nmap. Nmap – is one of the
main hacker tools, security researcher and penetration tester. Although Nmap has lots of features,
including Nmap (NSE) scripts, it was started as a simple port scanner and remains the best port
scanner ever. Nmap is a representative of the active method to obtain the information [
        <xref ref-type="bibr" rid="ref22 ref23 ref24 ref25">22, 23, 24, 25</xref>
        ].
      </p>
      <p>As an aim, we chose shodan results by the search of "port:502 modbus", obtained earlier in Figure
1. Further, there is a fragment of the Nmap output in Figure 3.</p>
      <p>As we can see, Nmap can identify nodes as HMS Anybus-CC Modbus-TCP (2-Port) 1.04.01 and
detected each of the nodes. It provides the intruder with valuable information, not only identifying the
PLC-controller and version, but also the communication protocol and structure. Since attacks require
deep knowledge of the automated control system technology, this information is sufficient to create
an attack vector on the infrastructure.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Conclusion</title>
      <p>There was formulated a new concept of the attack vector on the infrastructure (in particular,
critical information infrastructure) on the basis of the information and energy approach and
demonstrated its relevance in the field of information security of APCS and SCADA. It was proposed
to deliberately limit the space of the attack vector on the infrastructure by the Descartes basis of
information leaks and digital footprints. We developed separate Google Dorks for each manufacturer
of embedded systems for APCS and SCADA. Penetration testing was performed as an example of
APCS and SCADA on port 502 of the modbus protocol using Nmap. We obtained practical results
that are valuable for any specialist in the information security field, as they allow to create an
information security subsystem and its components for an intelligent integrated security management
system, such as the fuel and energy complex.</p>
    </sec>
    <sec id="sec-6">
      <title>6. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>I.</given-names>
            <surname>Kolosok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Gurina</surname>
          </string-name>
          .
          <article-title>Improvement of Cybersecurity of Smart Grid by State Estimation Methods</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <year>2018</year>
          , N
          <volume>3</volume>
          (
          <issue>27</issue>
          ). P.
          <volume>63</volume>
          -
          <fpage>69</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2018-3-
          <fpage>63</fpage>
          -
          <lpage>69</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Petrenko</surname>
          </string-name>
          .
          <article-title>Cyber resilient platform for internet of things (IIoT/IoT)ed systems: survey of architecture patterns</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2021. N</source>
          <volume>2</volume>
          (
          <issue>42</issue>
          ). P.
          <volume>81</volume>
          -
          <fpage>91</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2021-2-
          <fpage>81</fpage>
          -
          <lpage>91</lpage>
          . (In Russ.)
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>N. V.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Yu. S.</given-names>
            <surname>Kustarev</surname>
          </string-name>
          , Yu.
          <string-name>
            <given-names>Y.</given-names>
            <surname>Morgovsky</surname>
          </string-name>
          ,
          <article-title>Teoriya avtomaticheskogo upravleniya s praktikumom [</article-title>
          <source>Theory automatic control with workshop]</source>
          , Academia, Moscow,
          <year>2008</year>
          . URL: https://www.academia-moscow.ru/ftp_share/_books/fragments/fragment_21122.pdf. (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Shrestha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Johansen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Noll</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Roverso</surname>
          </string-name>
          ,
          <article-title>A methodology for security classification applied to smart grid infrastructures</article-title>
          ,
          <source>International Journal of Critical Infrastructure Protection</source>
          <volume>28</volume>
          (
          <year>2020</year>
          )
          <article-title>100342</article-title>
          . doi:
          <volume>10</volume>
          .1016/j.ijcip.
          <year>2020</year>
          .
          <volume>100342</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>N. V.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <article-title>Algorithmic both program methods and tools estimation of alternative projects of the guard data reduction system of firm on the basis of the multicriteria analysis</article-title>
          ,
          <source>Sputnik+</source>
          , Moscow,
          <year>2013</year>
          . (In Russ.).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>A.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Tsirlov</surname>
          </string-name>
          .
          <article-title>Procedure for Substantiated Development of Measures to Design Secure Software for Automated Process Control Systems</article-title>
          .
          <source>In Proceedings of the 12th International Siberian Conference on Control and Communications</source>
          (Moscow, Russia, May
          <volume>12</volume>
          - 14,
          <year>2016</year>
          ).
          <article-title>SIBCON 2016</article-title>
          . IEEE,
          <volume>7491660</volume>
          ,
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SIBCON.
          <year>2016</year>
          .
          <volume>7491660</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A. S.</given-names>
            <surname>Sani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Yuan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. L.</given-names>
            <surname>Yeoh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Qiu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Bao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Vucetic</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z. Y.</given-names>
            <surname>Dong</surname>
          </string-name>
          ,
          <article-title>CyRA: A real-time risk-based security assessment framework for cyber attacks prevention in industrial control systems</article-title>
          ,
          <source>IEEE Power and Energy Society General Meeting 2019-August</source>
          (
          <year>2019</year>
          )
          <article-title>8973948</article-title>
          . doi:
          <volume>10</volume>
          .1109/PESGM40551.
          <year>2019</year>
          .
          <volume>8973948</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>G.</given-names>
            <surname>Assenza</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Faramondi</surname>
          </string-name>
          , G. Oliva,
          <string-name>
            <given-names>R.</given-names>
            <surname>Setola</surname>
          </string-name>
          ,
          <article-title>Cyber threats for operational technologies</article-title>
          ,
          <source>International Journal of System of Systems Engineering</source>
          <volume>10</volume>
          (
          <issue>2</issue>
          ) (
          <year>2020</year>
          )
          <fpage>128</fpage>
          -
          <lpage>142</lpage>
          . doi:
          <volume>10</volume>
          .1504/IJSSE.
          <year>2020</year>
          .
          <volume>109127</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Yichao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Tianyang</surname>
          </string-name>
          , G. Xiaoyue,
          <string-name>
            <given-names>W.</given-names>
            <surname>Qingxian</surname>
          </string-name>
          ,
          <article-title>An improved attack path discovery algorithm through compact graph planning</article-title>
          ,
          <source>IEEE Access 7</source>
          (
          <year>2019</year>
          )
          <fpage>59346</fpage>
          -
          <lpage>59356</lpage>
          . doi:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2019</year>
          .
          <volume>2915091</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>N. V.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <article-title>Intelligent complex security management system FEC for the industry 5.0</article-title>
          , IOP Conference Series: Materials
          <source>Science and Engineering</source>
          <volume>950</volume>
          (
          <issue>1</issue>
          ) (
          <year>2020</year>
          )
          <article-title>012016</article-title>
          . doi:
          <volume>10</volume>
          .1088/
          <fpage>1757</fpage>
          - 899X/950/1/012016.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>N.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Merkulov</surname>
          </string-name>
          .
          <article-title>Intellectual analysis and basic modeling of complex threats</article-title>
          .
          <source>CEUR Workshop Proceedings</source>
          .
          <year>2019</year>
          . Vol-
          <volume>2603</volume>
          . P.
          <volume>23</volume>
          -
          <fpage>28</fpage>
          . URL: http://ceur-ws.org/Vol2603/paper6.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>N. V.</given-names>
            <surname>Korneev</surname>
          </string-name>
          ,
          <article-title>A Neurograph as a Model to Support Control over the Comprehensive Objects Safety for BIM Technologies</article-title>
          ,
          <source>IOP Conference Series: Earth and Environmental Science</source>
          <volume>224</volume>
          (
          <year>2019</year>
          )
          <article-title>012021</article-title>
          . doi:
          <volume>10</volume>
          .1088/
          <fpage>1755</fpage>
          -1315/224/1/012021.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>A. H.</given-names>
            <surname>Dakheel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. H.</given-names>
            <surname>Dakheel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H. H.</given-names>
            <surname>Abbas</surname>
          </string-name>
          ,
          <article-title>Intrusion detection system in gas-pipeline industry using machine learning</article-title>
          ,
          <source>Periodicals of Engineering and Natural Sciences</source>
          <volume>7</volume>
          (
          <issue>3</issue>
          ) (
          <year>2019</year>
          )
          <fpage>1030</fpage>
          -
          <lpage>1040</lpage>
          . doi:
          <volume>10</volume>
          .21533/pen.v7i3.
          <fpage>512</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>L.</given-names>
            <surname>Wei</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Chuipin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Qiang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Jingguo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Xionghui</surname>
          </string-name>
          ,
          <article-title>A method of NC machine tools intelligent monitoring system in smart factories</article-title>
          ,
          <source>Robotics and Computer-Integrated Manufacturing</source>
          <volume>61</volume>
          (
          <year>2020</year>
          )
          <article-title>101842</article-title>
          . doi:
          <volume>10</volume>
          .1016/j.rcim.
          <year>2019</year>
          .
          <volume>101842</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>V. N. Nanisura</given-names>
            <surname>Damanik</surname>
          </string-name>
          , S. U. Sunaringtyas,
          <article-title>Secure code recommendation based on code review result using owasp code review guide</article-title>
          ,
          <source>International Workshop on Big Data and Information Security (IWBIS)</source>
          , Depok, Indonesia, IEEE,
          <year>2020</year>
          , pp.
          <fpage>153</fpage>
          -
          <lpage>157</lpage>
          . doi:
          <volume>10</volume>
          .1109/IWBIS50925.
          <year>2020</year>
          .
          <volume>9255559</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>K.</given-names>
            <surname>Nagendran</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Adithyan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Chethana</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Camillus</surname>
          </string-name>
          , K. B. Bala Sri Varshini, Web application penetration testing,
          <source>International Journal of Innovative Technology and Exploring Engineering</source>
          <volume>8</volume>
          (
          <issue>10</issue>
          ) (
          <year>2019</year>
          )
          <fpage>1029</fpage>
          -
          <lpage>1035</lpage>
          . doi:
          <volume>10</volume>
          .35940/ijitee.J9173.0881019.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>N. D.</given-names>
            <surname>Thai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N. H.</given-names>
            <surname>Hieu</surname>
          </string-name>
          ,
          <article-title>A framework for website security assessment</article-title>
          ,
          <source>ACM International Conference Proceeding Series (ICCCM)</source>
          , Bangkok, АСМ, New York, NY,
          <year>2019</year>
          , pp.
          <fpage>153</fpage>
          -
          <lpage>157</lpage>
          . doi:
          <volume>10</volume>
          .1145/3348445.3348456.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>A. V.</given-names>
            <surname>Barabanov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. S.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V. L.</given-names>
            <surname>Tsirlov. Information Security Controls Against</surname>
          </string-name>
          Cross-Site
          <source>Request Forgery Attacks On Software Application of Automated Systems. Journal of Physics: Conference Series</source>
          .
          <year>2018</year>
          . V. 1015. P. 042034. DOI :
          <volume>10</volume>
          .1088/
          <fpage>1742</fpage>
          -6596/1015/4/042034
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>M.</given-names>
            <surname>Bada</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Pete</surname>
          </string-name>
          ,
          <article-title>An exploration of the cybercrime ecosystem around Shodan</article-title>
          ,
          <source>International Conference on Internet of Things: Systems, Management and Security (IOTSMS)</source>
          , Paris, France, IEEE,
          <year>2020</year>
          ,
          <volume>9340224</volume>
          . doi:
          <volume>10</volume>
          .1109/IOTSMS52051.
          <year>2020</year>
          .
          <volume>9340224</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>A. K. Phulre</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Kamble</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Phulre</surname>
          </string-name>
          ,
          <article-title>Content management systems hacking probabilities for admin access with google dorking and database code injection for web content security</article-title>
          ,
          <source>International Conference on Data, Engineering and Applications</source>
          (IDEA), Bhopal, India, IEEE,
          <year>2020</year>
          ,
          <volume>9170655</volume>
          . doi:
          <volume>10</volume>
          .1109/IDEA49133.
          <year>2020</year>
          .
          <volume>9170655</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>L.</given-names>
            <surname>Hartmann</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wendzel</surname>
          </string-name>
          ,
          <article-title>Anomaly detection in ICS based on data-history analysis</article-title>
          ,
          <source>ACM International Conference Proceeding Series (EICC)</source>
          , Rennes,
          <string-name>
            <surname>АСМ</surname>
          </string-name>
          , New York, NY,
          <year>2020</year>
          , рр. 1-
          <fpage>2</fpage>
          . doi:
          <volume>10</volume>
          .1145/3424954.3424963.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>P.</given-names>
            <surname>Manzanares-Lopez</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. P.</given-names>
            <surname>Muñoz-Gea</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Malgosa-Sanahuja</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Flores-de la Cruz</surname>
          </string-name>
          ,
          <article-title>A virtualized infrastructure to offer network mapping functionality in SDN networks</article-title>
          ,
          <source>International Journal of Communication Systems</source>
          <volume>32</volume>
          (
          <issue>10</issue>
          ) (
          <year>2019</year>
          )
          <article-title>e3961</article-title>
          . doi:
          <volume>10</volume>
          .1002/dac.3961.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>S.</given-names>
            <surname>Lau</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Klick</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Arndt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Roth</surname>
          </string-name>
          , POSTER:
          <article-title>Towards highly interactive honeypots for industrial control systems</article-title>
          ,
          <source>ACM Conference on Computer and Communications Security (CCS'16)</source>
          , Vienna, АСМ, New York, NY,
          <year>2016</year>
          , pp.
          <fpage>1823</fpage>
          -
          <lpage>1825</lpage>
          . doi:
          <volume>10</volume>
          .1145/2976749.2989063.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Ammar</surname>
          </string-name>
          ,
          <string-name>
            <surname>A.</surname>
          </string-name>
          <article-title>AlSharif, Deployment of IoT-based honeynet model</article-title>
          ,
          <source>ACM International Conference Proceeding Series (ICIT</source>
          <year>2018</year>
          :
          <article-title>IoT</article-title>
          and Smart City),
          <source>Hong Kong</source>
          ,
          <string-name>
            <surname>АСМ</surname>
          </string-name>
          , New York, NY,
          <year>2018</year>
          , pp.
          <fpage>134</fpage>
          -
          <lpage>139</lpage>
          . doi:
          <volume>10</volume>
          .1145/3301551.3301586.
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>L.</given-names>
            <surname>Rosa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Freitas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Mazo</surname>
          </string-name>
          , E. Monteiro,
          <string-name>
            <given-names>T.</given-names>
            <surname>Cruz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Simoes</surname>
          </string-name>
          ,
          <article-title>A comprehensive security analysis of a SCADA protocol: From OSINT to mitigation</article-title>
          ,
          <source>IEEE Access 7</source>
          (
          <year>2019</year>
          )
          <fpage>42156</fpage>
          -
          <lpage>42168</lpage>
          . doi:
          <volume>10</volume>
          .1109/ACCESS.
          <year>2019</year>
          .
          <volume>2906926</volume>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>