<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Feature extraction for anomaly detection in industrial control systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Silvio Russo</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Claudio Zanasi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Isabella Marasco</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Department of Computer Science and Engineering, University of Bologna</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The threat landscape for industrial systems is in rapid evolution, with cyber-attacks becoming increasingly sophisticated, targeted, and motivated. This situation should raise many concerns because of the growing interconnection of industrial control systems with the Internet, as well as the proliferation of cyberphysical systems and the Industrial Internet of Things. In these scenarios, an accurate detection of attacks is of utmost importance. The swiftness with which the environment of security risks in IoT and industrial systems is a cause for concern, given the rising complexity, specificity, and determination of cyber-attacks. This issue becomes particularly problematic due to the expanding integration of industrial control systems with the Internet and the widespread adoption of cyber-physical systems. In this work, we introduce a novel methodology for improving the Feature Extraction process. The solution shows versatility, operating not only as a standalone tool for identifying network attacks but, more significantly, as a valuable tool for pre-processing raw packet data tailored for integration with artificial intelligence models. The proposed solution was developed with an emphasis on addressing the specific cybersecurity needs of the industrial sector. This approach is driven by the imperative requirements of the industrial landscape, where safeguarding critical systems against cyber threats is of paramount importance. Furthermore, our system was tested on an industrial dataset that demonstrates the applicability and eficacy of our solution within the peculiar context of industrial environments. The outcomes of these tests contribute to the validation of our approach.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Anomaly Detection</kwd>
        <kwd>Control Systems</kwd>
        <kwd>Feature Extraction</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The analysis of network trafic through machine learning models is becoming necessary for the
early detection of suspicious activities. Cyber-physical systems (CPS) constitute a network of
interconnected devices facilitating seamless information exchange among tangible IoT devices.
These types of devices are used in diferent contexts like medical devices, autonomous vehicles,
industrial automatons, wearable, and urban smart infrastructures, and can be remotely
conifgured and managed. With their progressive adoption, these devices can monitor and access
huge amounts of critical and even sensitive data. Moreover, the proliferation of these devices
in the industries expands the surface area for cyber-attacks with consequent higher risks of
data leak, ransomware and sabotage operations. In certain industrial contexts and critical
infrastructures, the severity of cyber threats increases due to the potential consequences of an
attack on Industrial Control Systems (ICS) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] and the challenges associated with implementing
modern security measures for these systems.
      </p>
      <p>Current cybersecurity research and products primarily focus on methods and techniques for
the information technology (IT) environment. However, the increasing integration of industrial
control systems with IT systems, the proliferation of CPS, Industrial Internet of Things (IIoT)
solutions, and the rising frequency of attacks on industrial systems necessitate a shift in research
objectives towards addressing the unique challenges emerging from industrial settings.</p>
      <p>
        Common datasets used for evaluating network intrusion systems (NIDS), such as KDDCUPP99
[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and NSL-KDD [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], are old and not applicable for industrial systems. For this reason, we
consider the recent CIC Modbus 2023 dataset [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] and use it for the extraction of various features,
including Flow Features, Basic Features, Content Features, Time Features, and Labelled Features.
This comprehensive set allows a solid foundation for network trafic analysis specifically tailored
for industrial environment. The feature extraction rules, implemented in the Bro-code scripting
language, represent the core of this paper and a necessary step for the efective implementation
of a classification neural network that takes a pcap file as its input and provides immediate
evaluation of malicious or legitimate industrial trafic. Network Intrusion Detection Systems
(NIDS) based on AI models assume a pivotal role in safeguarding network infrastructure [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
In this context, the Feature Extractor (FE) components stand out as fundamental elements
that contribute to the overall eficacy of the detection phase. The Feature Extractor serves as a
critical component that is responsible for extracting relevant features and patterns from network
trafic data. Its role is to analyze the incoming data streams, identify anomalies, and extract
key information that can be indicative of potential security threats or malicious activities. This
process involves scrutinizing various aspects of the network trafic, including packet headers,
payload contents, communication patterns, and other pertinent attributes.
      </p>
      <p>The motivation behind this research stems from a critical issue observed in real-world
scenarios: NIDS frequently generate an excessive number of false positives. This persistent
problem significantly undermines the efectiveness of these systems in practical settings outside
of controlled research environments. One of the primary causes we have identified is the poor
quality of data that classification models receive as input, due to inefective Feature Extraction
processes. Therefore, with this research, we aim to take a first step towards a reliable and
efective feature extraction process that can extract truly relevant information for detection
purposes, thereby maximizing the eficacy of attack classification models without sacrificing
system performance.</p>
      <p>
        Diferently from other solutions that can be found in literature mostly based on artificial
intelligence (AI) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] techniques, our solution is based on a deterministic feature extraction
process able to guarantee the quality of the extracted data to improve the training process. The
paper aims to provide a macroscopic view of the functioning of NIDS, with a particular focus
on the Feature Extraction process, demonstrating how they can be customized and integrated
by implementing a neural network to enhance their accuracy.
      </p>
      <p>The rest of the paper is organized as follows. Section 2 discusses related works. Section 3
describes the methodology and the proposed solution. Section 4 discusses the used dataset and
the identified attacks. Section 5 presents details about the prototype and the experimental tests.
Section 6 summarizes the main conclusions and outlines future work.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>
        The problem of IoT[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] and industrial security [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] has become more relevant because these
components are crucial for the security and safety of cyber-physical environments. Several
works[
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ] analyze the critical situation in which the cybersecurity of IoT/OT word, proposing
new solutions. These works examine the challenges and vulnerabilities present in the evolving
interplay between the IoT and OT. In response to the identified risks, researchers have put
forth innovative solutions[
        <xref ref-type="bibr" rid="ref11 ref12">11, 12</xref>
        ] aimed at enhancing the overall security posture of this
interconnected ecosystem.
      </p>
      <p>
        The work [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] introduces a dynamic and adaptable security paradigm, aiming to redefine
traditional security models by embracing the evolving nature of contemporary digital
environments.
      </p>
      <p>
        Several works have analyzed the problem of feature extraction from Network trafic, the
main goal of these works is to determine the best solution to extract relevant information from
trafic data to improve the capacity to identify attacks or anomalies. The adopted solutions
are very diferent, leveraging a wide type of diferent techniques, from old-style script-based
solutions to AI-based ones. In [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] the author presents and examines the UNSW-NB15 data
set creation, comparing it with other datasets like e KDDCUP 99[
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] and NSL-KDD[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. To
benchmark and compare the diferent datasets the authors propose a solution based on a FE
composed of two diferent software, Zeek [ 14] and Argus[15]. The extracted features identify
relevant information to have a comprehensive knowledge of the network behaviour, starting
from this work we improve the feature extraction process by extracting a diferent set of features,
as described in section3, and developing a set of scripts to automatic labelling process, also
identifying specific types of attacks.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] the authors evaluate and compare the eficacy of diferent Deep Learning (DL) models
in identifying attack vectors against three Shallow Learning models: Deep Feed Forward,
Convolution Neural Network, Recurrent Neural Network, Decision Trees, Logistic Regression,
and Naive Bayes. This work analyzes three FE techniques that have been evaluated on diferent
datasets, in particular, Principal Component Analysis (PCA), Linear Discriminant Analysis
(LDA), and Auto-encoder (AE) are investigated for their impact on three benchmark datasets:
UNSW-NB15, ToN-IoT, and CSE-CIC-IDS2018.
      </p>
      <p>As we have done in this work the authors leverage the output of the FE as input for the
Machine Learning models trying to improve the performances of the NIDS, in particular for
PCA and AE, several dimensions (1,2,3,4,5,10,20 and 30) are selected trying to find the optimal
number. The problem is that the FE process based on these algorithms makes it dificult to
determine the quality of the extracted data, and this has an impact on the performance of the
classifier.</p>
      <p>In our work, we emphasize the importance of a deterministic FE process to ensure the quality
and reliability of extracted data. While PCA and AE in the cited paper attempt to optimize
performance by varying the number of dimensions, our solution focuses on maximizing the
eficacy of the FE process without compromising classifier performance. This approach addresses
the challenge of determining the quality of extracted data, which directly impacts classifier
performance.</p>
      <p>Furthermore, our research takes into account the practical constraints of real-world
environments, particularly the crucial aspect of execution time</p>
      <p>Moreover, in a real environment, the execution time is crucial to have an efective solution to
detect and prevent cyber-attacks. In this sense, the suggested FE algorithm requires significantly
more resources than the solution presented in our work.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Feature extraction</title>
      <p>An important part of this work is the FE designed to work with industrial data to build quality
datasets that can be used to train machine learning model to detect anomalous activities. Today
most papers use artificial networks of diferent types (AE, PCA, RNN ecc...) to extract relevant
features to improve the eficiency and the efectiveness of other machine learning models that
play the role of NIDS. This approach introduces a significant computational complexity that is
acceptable in research but is useless in real contexts where NIDS must analyze huge numbers
of packets per second.</p>
      <p>The proposed solution leverages Zeek [14] to implement an efective and fast FE. It is an
open-source network security monitoring tool developed by researchers at Lawrence Berkeley
National Laboratory. It is able of actively capturing, indexing, and analyzing real-time network
trafic. Its capabilities include the passive monitoring of network trafic to extract information
about protocols, connections, and data transfer. It can identify various protocols like HTTP,
DNS, FTP, and others, showcasing a focus on behavioural analysis for anomaly detection.
The tool supports signature-based detection for known threats, generating detailed logs that
facilitate forensic analysis and incident investigation. More importantly, being an open-source
project its extensibility, allows users to create custom scripts and plugins tailored to their
specific security requirements. The scripting language associated with Zeek allows us to create
customized scripts for efective network data analysis and processing. This tool is widely used
in cybersecurity to augment network security by providing visibility into network trafic and
identifying potential threats in real time.</p>
      <p>
        The proposed solution will be tested on the "CIC Modbus 2023" [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The extracted features
are diverse, in this way, we can identify all the relevant information that allows us to analyze
the connection. They are categorized into diferent groups, each focusing on specific aspects of
communication:
• Flow Feature: These features are designed to identify a connection uniquely.
• Basic Feature: Ofering general information about the connection, these features
contribute to building a basic understanding.
• Content Feature: Analyzing packet content, typically of TCP type, these features help
identify specific communication characteristics.
      </p>
      <p>• Time Features: Focusing on packet timing within a connection.</p>
      <p>
        Building upon the foundation laid out in the referenced work [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], we have expanded the set
of features to enhance the quality of the extracted information. Our goal is to acquire relevant
data that can significantly enhance the subsequent training of the machine learning model.
      </p>
      <p>In particular, we extract new features to closely monitor the retransmitted packets that
occur during communication sessions, we delve into the analysis of the time intervals between
Feature Name Description</p>
      <p>Label 0 for normal and 1 for attack records
s_retrans Source segments retransmitted (TCP)
d_retrans Destination segments retransmitted (TCP)
m_int_s For each connection, the mean interval between two packets (Source - in mSec)
m_int_d For each connection, the mean interval between two packets (Destination - in mSec)
http_post No. of flows that have the method Post in HTTP service
user_ftp User FTP if requested
pwd_ftp Password FTP if captured</p>
      <p>uid A unique identifier of the connection
local_orig If the connection is originated locally, this value will be T. If it was originated
remotely, it will be F
local_resp If the connection is responded to locally, this value will be T. If it was responded to
remotely, it will be F
history Records the state history of connections as a string of letters
tunnel_parents If this connection was over a tunnel, indicate the uid values for any encapsulating
parent connections used over the lifetime of this inner connection
orig_bytes The number of payload bytes the originator sent
resp_bytes The number of payload bytes the responder sent
successive packets for each connection, providing valuable insights into the dynamics of data
transfer. Additionally, we employ a quantitative approach to evaluate flows by scrutinizing the
usage of the POST method in the HTTP service, integrating also data related to FTP usernames
and passwords.</p>
      <p>Furthermore, a unique identifier has been introduced for each connection, two boolean
ifelds have been added to diferentiate whether a connection originated locally or remotely,
information particularly relevant in industrial networks to identify attacks. In industrial settings,
it is crucial to isolate the networks from the external world. This involves minimizing remote
communications as much as possible, as they can serve as potential access points for attackers,
putting at risk the security of the entire infrastructure and posing risks to the safety of workers.</p>
      <p>Also, specific information for tunnelling and the connection state history has been included
and documented as a string.</p>
      <p>The new extracted features are described in Table 1</p>
      <p>The solution is based on diferent scripts for extracting the features, BASH automation was
used to automatize the feature extraction.</p>
      <p>Several data structures have been employed to facilitate the management of blocks of
information in the logs. These structures include:
• Info: stores information to be logged for each identified connection in the analyzed pcap
ifles;
• FlowFeatures: preserves details of the addresses involved in a connection and the protocol
used;
• eachPackets: collects information described in the reference document for each packet;
• each TCP Conn: specific to TCP connections, stores relevant information;
• infoAllC: summarizes the total number of HTTP flows using the Get and Post methods.</p>
      <p>Regarding log management, crucial for the usability of the extracted feature, it was decided
to group similar functionalities to minimize the number of generated log files and enhance their
management.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Threat and anomaly detection</title>
      <p>The dataset used is diverse and includes various types of network trafic. It is generated by
capturing pcap files that simulate both legitimate and malicious network trafic within a fictional
network. The dataset is divided into two parts: the ’Dataset Attack’ and the ’Dataset Benign’.</p>
      <p>Within the simulated network architecture (Figure 1), the SecureIEDs identified as IED1A
(185.175.0.4) and IED4C (185.175.0.8) are considered secure. Similarly, the Secure SCADA HMI
(185.175.0.3) is included among the devices considered secure. However, there is also an insecure
IED (185.175.0.5) and an insecure SCADA HMI (185.175.0.3), making them potentially vulnerable.</p>
      <p>A crucial element of the architecture is the Central Agent (185.175.0.6), which receives the
so-called detection score from agents present in each secure device. Simultaneously, there is an
Attacker (185.175.0.7), responsible for the attacks visible in the "Dataset Attack".</p>
      <p>The provided dataset necessitates a preprocessing phase before being suitable for input into
machine learning models. The FE, discussed in Section 3, facilitates the preparation of the
data for the subsequent training phase. Given that the resulting data is unlabeled, the most
immediate application is an unsupervised algorithm to discern the intrinsic characteristics of the
trafic and perform an anomaly detection task. First, we used a K-Means clustering algorithm to
perform an initial analysis of the data. Then we used the Isolation Forest algorithm to perform
anomaly detection.</p>
      <p>Unsupervised algorithms excel at detecting anomalies in comparison to normal trafic.
However, for the accurate detection of malicious attacks, particularly those employing hiding
techniques, a supervised learning approach may prove more suitable. Labelling the dataset
becomes crucial for efectively training the models to distinguish real attacks from normal
trafic. Therefore, we implemented an automatic labelling process based on various heuristics.
Using these scripts, we comprehensively labelled all samples from the initial dataset to create a
new dataset suitable for training a machine learning model. Following this, we trained a neural
network on the refined dataset to build an automatic threat detection system.</p>
      <p>The neural network adopts at its core is a Long Short-Term Memory (LSTM) layer with 128
units, making it particularly efective for analyzing sequential data, such as the available trafic
logs. Following the LSTM is a dense layer with a ReLU activation function, succeeded by a
dropout layer for regularization to reduce the risk of overfitting. Lastly, there is a dense layer
with a sigmoid activation function to produce the final binary classification output.</p>
      <p>The network can only distinguish between benign and malicious samples, as we did not
include the specific type of attack in the labels. This decision was made to enhance the
generalization capabilities of the network, allowing the model to attempt recognition of attacks not
explicitly present in the training data.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Results</title>
      <p>The use of Zeek to perform feature extraction from the pcap files of the “CIC Modbus 2023”
dataset, exploiting its scripting capability, proved to be a good solution due to the reduced
computational time required compared to machine learning models and the possibility of
obtaining a deterministic solution, while also allowing a detailed analysis of the diferent
connection types.</p>
      <p>To evaluate the capability of the proposed method, we applied machine learning techniques
(K-means and Isolation Forest) on features extracted with Zeek to identify unusual patterns
and behaviours in network trafic. Figure 2 shows the results obtained applying K-means to
the analyzer.log file containing the information related to network protocols extracted by Zeek.
We can observe the presence of five clusters, where cluster 0 (green) is the densest, indicating
a prevalent trafic type. Clusters 1 (blue) and 4 (purple), which contain fewer instances and
are more compact, represent less frequent categories of network trafic. Clusters 2 (red) and 3
(yellow), the former consisting of a single instance and the latter of only two, could indicate the
presence of outliers or the presence of a new type of trafic or anomalies.</p>
      <p>The results from the conn.log file, containing trafic data and the subsequent analysis, is
depicted in Figure 3, unveil the existence of three distinct clusters. Cluster 2 (green) stands out
as the most cohesive, characterized by lower internal variance, representing standard trafic. In
contrast, both cluster 0 (red) and cluster 1 (blue) exhibit greater dispersion and lower density,
suggesting increased variability and heterogeneity in the type of trafic.</p>
      <p>The results of applying Isolation Forest to detect anomalies in the data, is reported in the
Figure 4. It shows inliers, which represent observations that fit the general pattern of the data
and are classified as normal activity and outlier observations, highlighted in black, that deviate
significantly from the norm and may indicate anomalies or suspicious activity.</p>
      <p>Finally, by training the Artificial Neural Network model on the labelled dataset generated
with Zeek, we evaluated its capability to detect the presence of attacks in network trafic. Table
2 presents the sample distribution in the training dataset, categorized into normal trafic and
attacks.</p>
      <p>We partitioned the data into a standard 70% - 30% split for training and testing purposes.
Using the neural network described in section 4 we achieved an accuracy of 84.21% in correctly
detecting malicious samples from the normal trafic.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Conclusions</title>
      <p>The use of machine learning approach for feature extraction is common, although its high
computational requirements make it impractical for real-world applications. In this paper, we
propose the use of Zeek for feature extraction to improve the speed and efectiveness, and
machine learning techniques for the analysis of the extracted features. The dataset used is "CIC
Modbus 2023", which contains trafic data from an industrial network.</p>
      <p>The efectiveness of the proposal was confirmed by the results of the detailed analysis
performed on the diferent types of connections. The K-means and Isolation Forest algorithms
were able to identify patterns within the network trafic and detect possible anomalies when
additional features were used. Furthermore, the neural network achieved an accuracy of 84.21%,
demonstrating its capability to distinguish between malicious and benign network trafic using
the dataset generated by Zeek. This research emphasizes the potential of combining traditional
tools with machine learning methods to enhance the detection of potential malicious activity.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgments</title>
      <p>This work was partially supported by project SERICS (PE00000014) under the MUR National
Recovery and Resilience Plan funded by the European Union - NextGenerationEU.
systems (unsw-nb15 network data set), in: 2015 Military Communications and Information
Systems Conference (MilCIS), 2015, pp. 1–6. doi:10.1109/MilCIS.2015.7348942.
[14] I. C. S. I. (ICSI), Zeek, 2024. URL: https://zeek.org/.
[15] Argus, 2024. URL: https://openargus.org/.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M.</given-names>
            <surname>Benmalek</surname>
          </string-name>
          ,
          <article-title>Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges, Internet of Things and Cyber-Physical Systems (</article-title>
          <year>2024</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2] I. University of California, Kdd cup
          <year>1999</year>
          data,
          <year>1999</year>
          . URL: https://kdd.ics.uci.edu/databases/ kddcup99/kddcup99.html.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>T.</surname>
          </string-name>
          et al.,
          <source>Nsl-kdd dataset</source>
          ,
          <year>2009</year>
          . URL: https://www.unb.ca/cic/datasets/nsl.html.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>K.</given-names>
            <surname>Boakye-Boateng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Ghorbani</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Lashkari</surname>
          </string-name>
          ,
          <article-title>Securing substations with trust, risk posture, and multi-agent systems: A comprehensive approach</article-title>
          ,
          <source>in: 2023 20th Annual International Conference on Privacy, Security and Trust (PST)</source>
          ,
          <source>IEEE Computer Society</source>
          , Los Alamitos, CA, USA,
          <year>2023</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>12</lpage>
          . URL: https://doi.ieeecomputersociety.
          <source>org/10.1109/ PST58708</source>
          .
          <year>2023</year>
          .
          <volume>10320154</volume>
          . doi:
          <volume>10</volume>
          .1109/PST58708.
          <year>2023</year>
          .
          <volume>10320154</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Ahmad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. Shahid</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Wai Shiang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Abdullah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Ahmad</surname>
          </string-name>
          ,
          <article-title>Network intrusion detection system: A systematic study of machine learning and deep learning approaches</article-title>
          ,
          <source>Transactions on Emerging Telecommunications Technologies</source>
          <volume>32</volume>
          (
          <year>2021</year>
          )
          <article-title>e4150</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Sarhan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Layeghy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Moustafa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Gallagher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Portmann</surname>
          </string-name>
          ,
          <article-title>Feature extraction for machine learning-based intrusion detection in iot networks</article-title>
          ,
          <source>Digital Communications and Networks</source>
          (
          <year>2022</year>
          ). URL: https://www.sciencedirect.com/science/article/pii/S2352864822001754. doi:https://doi.org/10.1016/j.dcan.
          <year>2022</year>
          .
          <volume>08</volume>
          .012.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <article-title>[7] nozominetworks, What it needs to know about ot/iot security</article-title>
          threats in
          <year>2020</year>
          ,
          <year>2020</year>
          . URL: https://www.nozominetworks.com/blog/ what-it
          <article-title>-needs-to-know-about-ot-io-security-threats-in-2020.</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>T.</given-names>
            <surname>Micro</surname>
          </string-name>
          ,
          <article-title>State of ot security in 2022: Big survey key insights</article-title>
          ,
          <year>2022</year>
          . URL: https://www. trendmicro.com/en_nl/research/22/f/state
          <article-title>-of-ot-security-2022</article-title>
          .html.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>I.</given-names>
            <surname>Stellios</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kotzanikolaou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Psarakis</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Alcaraz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lopez</surname>
          </string-name>
          ,
          <article-title>A survey of iot-enabled cyberattacks: Assessing attack paths to critical infrastructures and services</article-title>
          ,
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          <volume>20</volume>
          (
          <year>2018</year>
          )
          <fpage>3453</fpage>
          -
          <lpage>3495</lpage>
          . doi:
          <volume>10</volume>
          .1109/COMST.
          <year>2018</year>
          .
          <volume>2855563</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>M. A.</given-names>
            <surname>Khan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Salah</surname>
          </string-name>
          , Iot security: Review, blockchain solutions, and open challenges,
          <source>Future Generation Computer Systems</source>
          <volume>82</volume>
          (
          <year>2018</year>
          )
          <fpage>395</fpage>
          -
          <lpage>411</lpage>
          . URL: https:// www.sciencedirect.com/science/article/pii/S0167739X17315765. doi:https://doi.org/ 10.1016/j.future.
          <year>2017</year>
          .
          <volume>11</volume>
          .022.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Iqbal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Saxena</surname>
          </string-name>
          ,
          <article-title>Future industry internet of things with zero-trust security</article-title>
          ,
          <source>Information Systems Frontiers</source>
          (
          <year>2022</year>
          )
          <fpage>1</fpage>
          -
          <lpage>14</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>C.</given-names>
            <surname>Zanasi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Russo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Colajanni</surname>
          </string-name>
          ,
          <article-title>Flexible zero trust architecture for the cybersecurity of industrial iot infrastructures</article-title>
          ,
          <source>Ad Hoc Networks</source>
          <volume>156</volume>
          (
          <year>2024</year>
          )
          <article-title>103414</article-title>
          . URL: https://www.sciencedirect.com/science/article/pii/S1570870524000258. doi:https://doi. org/10.1016/j.adhoc.
          <year>2024</year>
          .
          <volume>103414</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>N.</given-names>
            <surname>Moustafa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Slay</surname>
          </string-name>
          , Unsw-nb15:
          <article-title>a comprehensive data set for network intrusion detection</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>