Pith. sign in

REVIEW 5 major objections 4 minor 172 references

Cyber-Physical Security Vulnerabilities Identification and Classification in Smart Manufacturing -- A Defense-in-Depth Driven Framework and Taxonomy

T0 review · 5 major / 4 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read This paper reframes manufacturing vulnerabilities as exploitable gaps in five defense layers and builds what it calls the first taxonomy of cyber-physical vulnerabilities for smart manufacturing.

desk verdict Useful synthesis of manufacturing cyber-physical vulnerabilities, but the 'first taxonomy' claim outruns the evidence and the five-layer completeness is asserted rather than demonstrated. read the letter →

arxiv 2501.09023 v2 pith:4H2AVTV6 submitted 2024-12-29 cs.CR

classification cs.CR
keywords smartmanufacturingcyber-physicalvulnerabilitiesdefense-in-depthvulnerabilitytaxonomycybersecurityqualitycontrolattackstagesIndustry4.0
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Smart manufacturing systems are attacked not just through software flaws but through the physical world: altered part geometry, sabotaged inspection, manipulated sensors. This paper argues that the usual definition of a vulnerability—a weakness in an information system—misses those attack paths, so it redefines a vulnerability as an exploitable gap in a defense layer. It then proposes a five-layer defense-in-depth model for manufacturing—organizational policies and procedures, cyber defenses, personnel, post-production inspection, and production process monitoring—and assembles a taxonomy of vulnerabilities under each layer. The authors claim this is the first taxonomy of cyber-physical vulnerabilities for smart manufacturing, and they demonstrate it on an illustrative manufacturing-as-a-service system, mapping each vulnerability to stages of a seven-stage attack-progression model.

What carries the argument

The load-bearing mechanism is the cyber-physical defense-in-depth model together with the vulnerability–defense duality. The model says a complete manufacturing defense has five overlapping layers: organizational policies and procedures; traditional cyber defenses covering networks, cloud services, IIoT devices, and software; security-aware personnel; security-aware post-production inspection; and security-aware process monitoring. The duality rule says every vulnerability is the absence, poor design, or misimplementation of a defense in one of these layers. The taxonomy is generated by auditing each layer for missing or deficient defenses and grouping the results.

What would settle it

A documented attack that succeeds through a vector outside the five layers—for example, sabotage delivered through contaminated raw material or a compromised design file passing between business partners with no corresponding policy, cyber, personnel, inspection, or process gap—would refute the taxonomy's claim to comprehensiveness.

Watch

Extended reading notes

Core claim

The central discovery is that the vulnerability–defense duality supplies a workable classification principle: a vulnerability is not a property of a component but the gap left by an absent, poorly designed, or misimplemented defense. By benchmarking a manufacturing system against the five-layer cyber-physical defense-in-depth model, the paper systematically identifies vulnerabilities in the manufacturing cyberspace, human element, post-production inspection, and production process monitoring, plus organizational policies. The resulting taxonomy organizes these vulnerabilities into a hierarchy—five primary layers, each with categories and individual vulnerabilities—and the illustrative example shows how the same taxonomy can be used to locate missing defense layers, map vulnerabilities to attack stages, and analyze real attacks such as tampered CAD files that evade inspection because only a subset of features is measured.

Load-bearing premise

The taxonomy assumes every exploitable manufacturing vulnerability can be characterized as a gap in one of five non-overlapping defense layers—policies, cyber, personnel, inspection, and process monitoring—so a vulnerability that falls outside these layers would break the classification's completeness.

Editorial extensions

If this is right

  • Manufacturers can run a five-layer audit to find missing defense layers, such as an inspection regime that checks only key quality characteristics and therefore cannot detect attack-induced changes elsewhere on a part.
  • Security teams can map each identified vulnerability to a stage of the attack-progression model, clarifying which attack activities are enabled and where detection is most likely.
  • The taxonomy gives small and medium manufacturers a structured starting point for audit questionnaires, so vulnerability assessment does not require deep security expertise.
  • Mitigation can be targeted per layer: zero-trust and network segmentation for cyber gaps, training for personnel gaps, adaptive quality-control tools for inspection gaps, and physics-aware monitoring of power, vibration, or acoustics for process gaps.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper, the five-layer model implies that a manufacturer can tolerate imperfect cyber defenses provided personnel, inspection, and process monitoring are calibrated to catch the physical manifestations of an attack; that shifts investment priorities toward quality-control-based detection.
  • The taxonomy could be stress-tested on supply-chain attack vectors—tainted raw materials, compromised logistics, or design handoff between firms—which the five layers do not explicitly name; such cases would reveal whether the claimed comprehensiveness holds.
  • A testable extension is to convert the taxonomy into an inter-rater reliability study: two auditors applying the framework to the same system should assign the same vulnerabilities to the same layers and attack stages if the taxonomy is unambiguous.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 4 minor

Summary. The paper proposes a defense-in-depth-driven framework for identifying and classifying cyber-physical vulnerabilities in smart manufacturing systems. It redefines manufacturing-specific vulnerabilities as exploitable gaps in defense layers, introduces a five-layer cyber-physical defense-in-depth model (organizational policies and procedures, cyber defenses, personnel, post-production inspection, and production process monitoring), and then surveys literature and vulnerability repositories to populate a taxonomy of vulnerabilities within each layer. The paper also presents an illustrative smart manufacturing system, maps identified vulnerabilities to the cyber kill chain, and discusses empirical cyber-physical attacks that exploit selected vulnerabilities. The central claim is that this constitutes the first comprehensive taxonomy of cyber-physical vulnerabilities in smart manufacturing systems.

Significance. If the central claim were fully supported, the framework would give manufacturers and auditors a practical, structured way to audit security posture across both cyber and physical domains, and the kill-chain mapping would help prioritize defenses. The paper's strengths are its clear defense-layer framing, its extensive use of domain-specific literature (e.g., manufacturing quality control and process monitoring), and its demonstration of how non-cyber defenses such as inspection and personnel training can detect attack-induced physical changes. The illustrative CNC example in Section 5.5.3 is particularly instructive because it shows how an attack that evades conventional power-monitoring features can be detected by local temporal features. The taxonomy, however, is only as good as the completeness and disjointness of its five layers, and the paper does not currently provide the systematic evidence needed to support the 'comprehensive' and 'first' claims.

major comments (5)
  1. [Section 3.1 and Section 4] The abstract and Section 6 call the taxonomy 'comprehensive' and 'the first,' but Section 3.1 defines a vulnerability as 'any deficiency across the product's life cycle,' whereas Section 4 classifies vulnerabilities only into the five defense layers of Section 3.3.2. Section 2.3 itself cites Sturm et al. (2017) as listing raw material as an attack location; raw material provenance, supply chain logistics, and product design handoff have no category in Figures 4-9. The paper needs either to expand the taxonomy to cover these areas, to add an explicit coverage argument showing that all life-cycle deficiencies correspond to at least one of the five layers, or to revise the claim to something like 'first defense-layer-driven taxonomy.' Without this, the comprehensiveness claim is unsupported.
  2. [Section 3.4] Section 3.4 states that relevant literature from Web of Science, Scopus, IEEE, ScienceDirect, and ASME Digital Collection, along with vulnerability repositories such as NVD and CWE, was surveyed, but no search strings, inclusion/exclusion criteria, date ranges, or coverage checks are reported. This makes the vulnerability list non-reproducible and prevents a reader from judging whether the taxonomy is complete. A systematic review protocol (or a clear acknowledgment that the survey is a narrative review with the corresponding limitations) is needed.
  3. [Sections 4.3.1, 4.4.4, and 4.5.2] The taxonomy does not specify how the five layers are disjoint. For example, 'Lack of cybersecurity awareness, knowledge, and skills' (Section 4.3.1) is placed under Personnel, but inadequate training could equally be attributed to a policy/procedure gap; 'Data analysis deficiencies' appears both under Inspection (Section 4.4.4) and under Process data processing and analytics (Section 4.5.2); and 'Weak authentication practices' (Section 4.3.2) overlaps with 'Insufficient authentication and authorization' under Network (Section 4.2.1). The authors should provide operational definitions or assignment rules for placing a vulnerability in exactly one layer, or explicitly acknowledge and discuss overlaps.
  4. [Section 5.4, Table 2] Table 2 lists only eight vulnerability instances for the illustrative system, covering a small subset of the categories in the full taxonomy. The abstract and Section 6 describe the example as demonstrating 'effectiveness,' but the example does not exercise most categories and cannot validate completeness or the discriminative power of the taxonomy. The claim should be scaled back to 'illustrates the application' or the authors should add a more systematic validation, such as applying the framework to several diverse systems and checking coverage.
  5. [Section 6] The claim of being the 'first taxonomy of cyber-physical vulnerabilities in smart manufacturing' requires a precise comparison with existing classifications, including the attack-location taxonomy of Sturm et al. (2017), the QC-vulnerability list of Elhabashy et al. (2020), and the attack taxonomy of Yampolskiy et al. (2018), all cited in Section 2. Since the paper's contribution is a defense-layer-based vulnerability taxonomy, the novelty claim should be scoped to that framing, with a clear statement of how it differs from prior attack and vulnerability taxonomies.
minor comments (4)
  1. [Figure 4] Figure 4 contains a typo: 'Cloud servics' should be 'Cloud services.'
  2. [Section 5.5.1] The citation of Sturm et al. (2017) is inconsistently spelled as 'Strum' in the sentence beginning 'Strum et al. (2017) demonstrated the introduction of internal voids.'
  3. [Section 4.1] The phrase 'cybersecurity teams are short-stuffed' should be 'short-staffed.'
  4. [Reference list] Several references lack complete bibliographic details; for example, references [11], [12], and [54] do not include full publication venues or page ranges, which reduces the reproducibility of the literature survey.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the defense-in-depth framing is an acknowledged organizing definition, and the taxonomy is assembled from independent literature rather than derived from a fitted parameter or self-citation chain.

full rationale

The paper's central move is to redefine manufacturing vulnerabilities as exploitable gaps in defense layers (abstract: 'Vulnerabilities are conceptualized as exploitable gaps within various defense layers'; Section 3.2: 'This work characterizes system vulnerabilities as the absence of proper defense strategies and/or measures'), and then to classify vulnerabilities within the five layers of the proposed cyber-physical defense-in-depth model. This is an explicit definitional frame, not a hidden derivation: the paper does not claim to predict or mathematically deduce the existence or severity of vulnerabilities from independent first principles. The taxonomy's content is a literature- and repository-based enumeration of concrete weaknesses under each heading, so the individual vulnerability categories are not equivalent by construction to the five-layer skeleton. The authors cite their own prior work (e.g., Shafae et al. 2019, Rahman et al. 2023, Rahman et al. 2024) as part of the background, but Table 1 also maps the same five layers onto NIST CSF 2.0 and other independent sources, so the defense model does not rest solely on a self-citation chain. The illustrative example in Section 5.4 is an application of the framework, not an empirical validation, and the paper's 'first comprehensive taxonomy' claim is a novelty assertion that is not backed by a completeness proof; the lack of coverage for raw-material/supply-chain gaps and the unverified non-overlap of layers are legitimate correctness and scope concerns, but they are not circularity. No prediction is fitted and renamed, no uniqueness theorem is imported from the authors, and no ansatz is smuggled in via citation. Therefore the derivation chain is self-contained in the limited sense that the framework's definitions and categories are openly declared rather than disguised outputs of the same definitions.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

No free parameters are fitted. The paper's contributions are conceptual: a defense-in-depth model and a taxonomy. The main burden is carried by domain assumptions about the completeness and appropriateness of the five-layer model and the survey-based identification method. No new physical entities, particles, or mediators are introduced.

assumptions (5)
  • domain assumption Defense-in-depth is an appropriate normative benchmark against which vulnerabilities can be measured.
    Section 3.3 introduces the defense-in-depth model as the basis for identifying missing defenses. The paper provides no external justification that defense-in-depth is the correct or complete framing for manufacturing security.
  • domain assumption Vulnerabilities can be characterized as gaps in defense layers (vulnerability-defense duality).
    Section 3.2 defines vulnerability as absence of proper defense, which is a definitional premise that shapes the entire taxonomy. It is not derived from empirical evidence.
  • domain assumption The five defense layers (policy, cyber, personnel, inspection, process) are comprehensive and non-overlapping for manufacturing systems.
    Section 3.3.2 and Figure 3(right) propose the five-layer model. The paper does not demonstrate completeness or mutual exclusivity of the layers.
  • domain assumption The surveyed literature and vulnerability repositories are representative of all manufacturing-specific vulnerabilities.
    Section 3.4 states that relevant literature was surveyed, but no systematic search or selection protocol is given, so representativeness is assumed.
  • domain assumption The Lockheed Martin cyber kill chain is applicable to cyber-physical manufacturing attacks.
    Section 3.1 maps vulnerabilities to the seven-stage kill chain without discussing whether the framework is appropriate for physical and cyber-physical attacks.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Cyber-Physical Security Vulnerabilities Identification and Classification in Smart Manufacturing -- A Defense-in-Depth Driven Framework and Taxonomy." pith.science (2026). https://pith.science/paper/4H2AVTV6

@misc{pith2026250109023,
  author       = {Pith},
  title        = {Pith review of: Cyber-Physical Security Vulnerabilities Identification and Classification in Smart Manufacturing -- A Defense-in-Depth Driven Framework and Taxonomy},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/4H2AVTV6}},
  note         = {Machine review of arXiv:2501.09023}
}
read the original abstract

The increasing cybersecurity threats to critical manufacturing infrastructure necessitate proactive strategies for vulnerability identification, classification, and assessment. Traditional approaches, which define vulnerabilities as weaknesses in computational logic or information systems, often overlook the physical and cyber-physical dimensions critical to manufacturing systems, comprising intertwined cyber, physical, and human elements. As a result, existing solutions fall short in addressing the complex, domain-specific vulnerabilities of manufacturing environments. To bridge this gap, this work redefines vulnerabilities in the manufacturing context by introducing a novel characterization based on the duality between vulnerabilities and defenses. Vulnerabilities are conceptualized as exploitable gaps within various defense layers, enabling a structured investigation of manufacturing systems. This paper presents a manufacturing-specific cyber-physical defense-in-depth model, highlighting how security-aware personnel, post-production inspection systems, and process monitoring approaches can complement traditional cyber defenses to enhance system resilience. Leveraging this model, we systematically identify and classify vulnerabilities across the manufacturing cyberspace, human element, post-production inspection systems, production process monitoring, and organizational policies and procedures. This comprehensive classification introduces the first taxonomy of cyber-physical vulnerabilities in smart manufacturing systems, providing practitioners with a structured framework for addressing vulnerabilities at both the system and process levels. Finally, the effectiveness of the proposed model and framework is demonstrated through an illustrative smart manufacturing system and its corresponding threat model.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

172 extracted references · 72 canonical work pages

  1. [1]

    An Approach to Cyber -Physical Vulnerability Assessment for Intelligent Manufacturing Systems,

    DeSmit, Z., Elhabashy, A. E., Wells, L. J., and Camelio, J. A., 2017, “An Approach to Cyber -Physical Vulnerability Assessment for Intelligent Manufacturing Systems,” J. Manuf. Syst., 43, pp. 339– 351. https://doi.org/https://doi.org/10.1016/j.jmsy.2017.03.004

  2. [2]

    Rahman, M. H., 2024, “Secure Cyber -Physical Manufacturing Systems (Secure- CyPhyMan): Advanced Methods for Manufacturing Cybersecurity Threat Characterization, Risk Modeling and Assessment, and a Resilient Attack Detection and Prevention,” The University of Arizona

  3. [3]

    Introduction to Hardware Security,

    Bhunia, S., and Tehranipoor, M., 2019, “Introduction to Hardware Security,” Hardware Security , Elsevier, pp. 1–20. https://doi.org/10.1016/b978-0-12-812477-2.00006-x

  4. [4]

    Security of Smart Manufacturing Systems,

    Tuptuk, N., and Hailes, S., 2018, “Security of Smart Manufacturing Systems,” J. Manuf. Syst., 47, pp. 93 –

  5. [5]

    IBM Security X -Force Threat Intelligence Index

    2022, “IBM Security X -Force Threat Intelligence Index.” [Online]. Available: https://www.ibm.com/security/data-breach/threat-intelligence/. [Accessed: 17-May-2024]

  6. [6]

    Physics-Based Detection of Cyber-Attacks in Manufacturing Systems: A Machining Case Study,

    Rahman, M. H., and Shafae, M., 2022, “Physics-Based Detection of Cyber-Attacks in Manufacturing Systems: A Machining Case Study,” J. Manuf. Syst., 64, pp. 676–683. https://doi.org/10.1016/j.jmsy.2022.04.012

  7. [7]

    IBM Security X -Force Threat Intelligence Index

    2024, “IBM Security X -Force Threat Intelligence Index.” [Online]. Available: https://www.ibm.com/reports/threat-intelligence

  8. [8]

    Taxonomy -Driven Graph-Theoretic Framework for Manufacturing Cybersecurity Risk Modeling and Assessment,

    Rahman, M. H., Hamedani, E. Y., Son, Y.- J., and Shafae, M., 2024, “Taxonomy -Driven Graph-Theoretic Framework for Manufacturing Cybersecurity Risk Modeling and Assessment,” J. Comput. Inf. Sci. Eng., 24(7), p. 071003. https://doi.org/10.1115/1.4063729

Show all 172 references
  1. [9]

    Systematic Analysis of Cyber-Attacks on CPS-Evaluating Applicability of DFD -Based Approach,

    Yampolskiy, M., Horvath, P., Koutsoukos, X. D., Xue, Y., and Sztipanovits, J., 2012, “Systematic Analysis of Cyber-Attacks on CPS-Evaluating Applicability of DFD -Based Approach,” 5th International Symposium on Resilient Control Systems, ISRCS, IEEE, pp. 55–62. https://doi.org...

  2. [10]

    Taxonomy for Description of Cross -Domain Attacks on CPS,

    Yampolskiy, M., Horvath, P., Koutsoukos, X. D., Xue, Y., and Sztipanovits, J., 2013, “Taxonomy for Description of Cross -Domain Attacks on CPS,” Proceedings of the 2nd ACM International Conference on High Confidence Networked Systems - HiCoNS ’13, pp. 135–142. https://doi.org/...

  3. [11]

    Sabotaging Metal Additive Manufacturing: Powder Delivery System Manipulation and Material -Dependent Effects,

    Graves, L. M. G., King, W., Carrion, P., Shao, S., Shamsaei, N., and Yampolskiy, M., 2021, “Sabotaging Metal Additive Manufacturing: Powder Delivery System Manipulation and Material -Dependent Effects,” Addit. Manuf., p. 102029

  4. [12]

    Hackers Could Destroy 3D Printers by Setting Them on Fire | TechRadar

    2020, “Hackers Could Destroy 3D Printers by Setting Them on Fire | TechRadar.” [Online]. Available: https://www.techradar.com/news/hackers-could-destroy-3d-printers-by-setting-them-on-fire. [Accessed: 14 - Jun-2024]

  5. [14]

    Cyber-Physical Vulnerabilities in Additive Manufacturing Systems: A Case Study Attack on the. STL File with Human Subjects,

    Sturm, L. D., Williams, C. B., Camelio, J. A., White, J., and Parker, R., 2017, “Cyber-Physical Vulnerabilities in Additive Manufacturing Systems: A Case Study Attack on the. STL File with Human Subjects,” J. Manuf. Syst., 44, pp. 154–164. https://doi.org/https://doi.org/10.10...

  6. [15]

    Defending against Product -Oriented Cyber -Physical Attacks on Machining Systems,

    Shafae, M. S., Wells, L. J., and Purdy, G. T., 2019, “Defending against Product -Oriented Cyber -Physical Attacks on Machining Systems,” Int. J. Adv. Manuf. Technol., pp. 1–21. https://doi.org/10.1007/s00170-019- 03805-z

  7. [16]

    Dr0wned – Cyber-Physical Attack with Additive Manufacturing,

    Belikovetsky, S., Yampolskiy, M., Toh, J., Gatlin, J., and Elovici, Y., 2017, “Dr0wned – Cyber-Physical Attack with Additive Manufacturing,” 11th USENIX Workshop on Offensive Technologies, WOOT 2017, Co- Located with USENIX Security 2017

  8. [17]

    Renault -Nissan Resumes Nearly All Production after Cyber Attack | Reuters

    2017, “Renault -Nissan Resumes Nearly All Production after Cyber Attack | Reuters.” [Online]. Available: https://www.reuters.com/article/us-cyber-attack-renault/renault-nissan-resumes-nearly-all-production-after- cyber-attack-idUSKCN18B0S5. [Accessed: 23-Feb-2024]

  9. [18]

    Toyota Cyberattack: Production to Restart in Japan after Attack on Kojima Industries | CNN Business

    2022, “Toyota Cyberattack: Production to Restart in Japan after Attack on Kojima Industries | CNN Business.” [Online]. Available: https://www.cnn.com/2022/03/01/business/toyota -japan-cyberattack-production- restarts-intl-hnk/index.html. [Accessed: 19-Jan-2024]

  10. [19]

    Honda’s Global Operations Hit by Cyber -Attack - BBC News

    2020, “Honda’s Global Operations Hit by Cyber -Attack - BBC News.” [Online]. Available: https://www.bbc.com/news/technology-52982427. [Accessed: 11-Feb-2023]

  11. [20]

    Cyber -Physical Security Challenges in Manufacturing Systems,

    Wells, L. J., Camelio, J. A., Williams, C. B., and White, J., 2014, “Cyber -Physical Security Challenges in Manufacturing Systems,” Manuf. Lett., 2(2), pp. 74–77. https://doi.org/10.1016/j.mfglet.2014.01.005

  12. [21]

    Cyber -Physical Attack Vulnerabilities in Manufacturing Quality Control Tools,

    Elhabashy, A. E., Wells, L. J., and Camelio, J. A., 2020, “Cyber -Physical Attack Vulnerabilities in Manufacturing Quality Control Tools,” Qual. Eng., 32(4), pp. 676 –692. https://doi.org/https://doi.org/10.1080/08982112.2020.1737115

  13. [22]

    Security of Additive Manufacturing: Attack Taxonomy and Survey,

    Yampolskiy, M., King, W. E., Gatlin, J., Belikovetsky, S., Brown, A., Skjellum, A., and Elovici, Y., 2018, “Security of Additive Manufacturing: Attack Taxonomy and Survey,” Addit. Manuf., 21 (November 2017), pp. 431–457. https://doi.org/10.1016/j.addma.2018.03.015

  14. [23]

    IBM Security X -Force Threat Intelligence Index

    2023, “IBM Security X -Force Threat Intelligence Index.” [Online]. Available: https://www.ibm.com/reports/threat-intelligence. [Accessed: 29-Mar-2024]

  15. [24]

    Manufacturing Cybersecurity Threat Attributes and Countermeasures: Review, Meta- Taxonomy, and Use Cases of Cyberattack Taxonomies,

    Rahman, M. H., Wuest, T., and Shafae, M., 2023, “Manufacturing Cybersecurity Threat Attributes and Countermeasures: Review, Meta- Taxonomy, and Use Cases of Cyberattack Taxonomies,” J. Manuf. Syst., 68, pp. 196–208. https://doi.org/https://doi.org/10.1016/j.jmsy.2023.03.009

  16. [25]

    https://doi.org/10.1109/JPROC.2011.2165269

    NIST, 2014, Framework for Improving Critical Infrastructure Cybersecurity . https://doi.org/10.1109/JPROC.2011.2165269

  17. [26]

    https://doi.org/10.6028/NIST.IR.8183

    Stouffer, K., Zimmerman, T., Tang, C., Lubell, J., Cichonski, J., and Mccarthy, J., 2020, NISTIR 8183 Revision 1, Cybersecurity Framework: Manufacturing Profile. https://doi.org/10.6028/NIST.IR.8183

  18. [28]

    National Vulnerability Database

    2023, “National Vulnerability Database.” [Online]. Available: https://nvd.nist.gov/. [Accessed: 29-Apr-2024]

  19. [29]

    CVE - Home

    2023, “CVE - Home.” [Online]. Available: https://cve.mitre.org/cve/. [Accessed: 11-Feb-2024]

  20. [30]

    CWE - Common Weakness Enumeration

    2023, “CWE - Common Weakness Enumeration.” [Online]. Available: https://cwe.mitre.org/. [Accessed: 12- Jun-2024]

  21. [31]

    IBM X-Force Exchange - Overview

    IBM, “IBM X-Force Exchange - Overview.” [Online]. Available: https://www.ibm.com/products/ibm-xforce- exchange

  22. [32]

    https://doi.org/10.6028/NIST.SP.800-82r1

    Stouffer, K., Falco, J., and Scarfone, K., 2013, Guide to Industrial Control Systems (ICS) Security . https://doi.org/10.6028/NIST.SP.800-82r1

  23. [33]

    Industrial Control Systems Cyber Emergency Response Team, 2016, Recommended Practice: Improving Industrial Control System Cybersecurity with Defense-in-Depth Strategies

  24. [34]

    https://doi.org/10.1002/9781119644538

    Flaus, J., 2019, Cybersecurity of Industrial Systems. https://doi.org/10.1002/9781119644538

  25. [35]

    Available: https://www.shodan.io/

    2023, “Shodan.” [Online]. Available: https://www.shodan.io/

  26. [36]

    Nmap: The Network Mapper - Free Security Scanner

    2023, “Nmap: The Network Mapper - Free Security Scanner.” [Online]. Available: https://nmap.org/

  27. [37]

    Metasploit Penetration Testing Software

    2023, “Metasploit Penetration Testing Software.” [Online]. Available: https://www.metasploit.com/

  28. [38]

    Peeking under the Skirts of a Nation: Finding Ics Vulnerabilities in the Critical Digital Infrastructure,

    Kiravuo, T., Tiilikainen, S., Särelä, M., and Manner, J., 2015, “Peeking under the Skirts of a Nation: Finding Ics Vulnerabilities in the Critical Digital Infrastructure,” European Conference on Cyber Warfare and Security, Academic Conferences International Limited, p. 137

  29. [40]

    [Online]

    NCCIC, 2017, NCCIC ICS CYBER SECURITY EVALUATION TOOL. [Online]. Available: https://ics-cert.us- cert.gov/sites/default/files/FactSheets/NCCIC ICS_FactSheet_CSET_S508C.pdf

  30. [41]

    Intelligent Manufacturing in the Context of Industry 4.0: A Review,

    Zhong, R. Y., Xu, X., Klotz, E., and Newman, S. T., 2017, “Intelligent Manufacturing in the Context of Industry 4.0: A Review,” Engineering, 3(5), pp. 616–630. https://doi.org/10.1016/J.ENG.2017.05.015

  31. [42]

    Table 3.9ESI. Current -Cost Average Age at Yearend of Private Fixed Assets by Industry

    U.S. Bureau of Economic Analysis, 2018, “Table 3.9ESI. Current -Cost Average Age at Yearend of Private Fixed Assets by Industry.”

  32. [43]

    Cyber Kill Chain® | Lockheed Martin

    2025, “Cyber Kill Chain® | Lockheed Martin.” [Online]. Available: https://www.lockheedmartin.com/en- us/capabilities/cyber/cyber-kill-chain.html. [Accessed: 10-Mar-2025]

  33. [44]

    [Online]

    Federal Emergency Management Agency (FEMA), 2014, Unit IV - Vulnerability Assessment . [Online]. Available: https://www.fema.gov/pdf/plan/prevent/rms/155/e155_ig.pdf

  34. [45]

    [Online]

    Risk Management for DoD Security Programs Student Guide . [Online]. Available: https://www.cdse.edu/documents/student-guides/risk-management.pdf

  35. [46]

    Information Security Strategies: Towards an Organizational Multi-Strategy Perspective,

    Ahmad, A., Maynard, S. B., and Park, S., 2014, “Information Security Strategies: Towards an Organizational Multi-Strategy Perspective,” J. Intell. Manuf., 25(2), pp. 357–370

  36. [47]

    Weaver, R., Weaver, D., and Farwood, D., 2013, Guide to Network Defense and Countermeasures , Cengage Learning

  37. [48]

    CheatSheetSeries/Session_Management_Cheat_Sheet.Md at Master · OWASP/CheatSheetSeries · GitHub

    “CheatSheetSeries/Session_Management_Cheat_Sheet.Md at Master · OWASP/CheatSheetSeries · GitHub.” [Online]. Available: https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Session_Management_Cheat_Sheet. md. [Accessed: 08-Jun-2024]

  38. [49]

    Biometrics: A Tool for Information Security,

    Jain, A. K., Ross, A., and Pankanti, S., 2006, “Biometrics: A Tool for Information Security,” IEEE Trans. Inf. forensics Secur., 1(2), pp. 125–143

  39. [50]

    https://doi.org/10.6028/NIST.CSWP.29

    2024, The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29

  40. [51]

    Advanced Monitoring of Machining Operations,

    Teti, R., Jemielniak, K., O’Donnell, G., and Dornfeld, D., 2010, “Advanced Monitoring of Machining Operations,” CIRP Ann., 59(2), pp. 717–739

  41. [52]

    Tang, C., and Tang, C., 2017, Key Performance Indicators for Process Control System Cybersecurity Performance Analysis, US Department of Commerce, National Institute of Standards and Technology

  42. [53]

    VISTA: An Inclusive Insider Threat Taxonomy, with Mitigation Strategies,

    Renaud, K., Warkentin, M., Pogrebna, G., and van der Schyff, K., 2024, “VISTA: An Inclusive Insider Threat Taxonomy, with Mitigation Strategies,” Inf. Manag., 61(1), p. 103877

  43. [54]

    Taxonomy for Cybersecurity Threat Attributes and Countermeasures in Smart Manufacturing Systems,

    Rahman, M. H., Cassandro, R., Wuest, T., and Shafae, M., 2024, “Taxonomy for Cybersecurity Threat Attributes and Countermeasures in Smart Manufacturing Systems,” arXiv, pp. 1– 25. https://doi.org/https://doi.org/10.48550/arXiv.2401.01374

  44. [55]

    Cybersecurity of Industrial Cyber-Physical Systems: A Review,

    Kayan, H., Nunes, M., Rana, O., Burnap, P., and Perera, C., 2022, “Cybersecurity of Industrial Cyber-Physical Systems: A Review,” ACM Comput. Surv., 54(11s), pp. 1–35

  45. [56]

    A Review of Cybersecurity Guidelines for Manufacturing Factories in Industry 4.0,

    Mullet, V., Sondi, P., and Ramat, E., 2021, “A Review of Cybersecurity Guidelines for Manufacturing Factories in Industry 4.0,” IEEE Access, 9, pp. 23235–23263

  46. [57]

    A Survey of Cybersecurity of Digital Manufacturing,

    Mahesh, P., Tiwari, A., Jin, C., Kumar, P. R., Reddy, A. L. N., Bukkapatanam, S. T. S., Gupta, N., and Karri, R., 2021, “A Survey of Cybersecurity of Digital Manufacturing,” Proc. IEEE, 109(4), pp. 495– 516. https://doi.org/10.1109/JPROC.2020.3032074

  47. [58]

    Physical Unclonable Functions for Device Authentication and Secret Key Generation,

    Suh, G. E., and Devadas, S., 2007, “Physical Unclonable Functions for Device Authentication and Secret Key Generation,” 2007 44th ACM/IEEE Design Automation Conference, IEEE, pp. 9–14

  48. [59]

    Obfuscation of Embedded Codes in Additive Manufactured Components for Product Authentication,

    Chen, F., Yu, J. H., and Gupta, N., 2019, “Obfuscation of Embedded Codes in Additive Manufactured Components for Product Authentication,” Adv. Eng. Mater., 21(8), p. 1900146

  49. [60]

    A Survey of Cybersecurity and Resilience of Digital Manufacturing,

    Mahesh, P., Tiwari, A., Jin, C., Kumar, P. R., Reddy, A. L. N., Bukkapatanam, S. T. S., Gupta, N., and Karri, R., 2020, “A Survey of Cybersecurity and Resilience of Digital Manufacturing,” arXiv Prepr. arXiv2006.05042, 14(8), pp. 1–18. [Online]. Available: http://arxiv.org/abs...

  50. [61]

    NVD - Search and Statistics

    “NVD - Search and Statistics.” [Online]. Available: https://nvd.nist.gov/vuln/search. [Accessed: 20 -Dec- 2018]

  51. [62]

    Stouffer, K., Stouffer, K., Zimmerman, T., Tang, C., Lubell, J., Cichonski, J., and McCarthy, J., 2017, Cybersecurity Framework Manufacturing Profile , US Department of Commerce, National Institute of Standards and Technology

  52. [63]

    https://doi.org/10.1109/SIMS.2016.7802895

    Heikkila, M., Rattya, A., Pieska, S., and Jamsa, J., 2016, Security Challenges in Small -and Medium-Sized Manufacturing Enterprises. https://doi.org/10.1109/SIMS.2016.7802895

  53. [65]

    [Online]

    The Ponemon Institute, 2018, Separating the Truths from the Myths in Cybersecurity Sponsored by BMC . [Online]. Available: https://www.ponemon.org/local/upload/file/BMC Consolidated Report Final.pdf

  54. [66]

    Cybersecurity for Smart Factories in the Manufacturing Industry | Deloitte US

    2020, “Cybersecurity for Smart Factories in the Manufacturing Industry | Deloitte US.” [Online]. Available: https://www2.deloitte.com/us/en/pages/energy-and-resources/articles/smart-factory-cybersecurity- manufacturing-industry.html. [Accessed: 15-Feb-2022]

  55. [67]

    DIGFuPAS: Deceive IDS with GAN and Function- Preserving on Adversarial Samples in SDN -Enabled Networks,

    Duy, P. T., Khoa, N. H., Nguyen, A. G.- T., and Pham, V.- H., 2021, “DIGFuPAS: Deceive IDS with GAN and Function- Preserving on Adversarial Samples in SDN -Enabled Networks,” Comput. Secur., 109 , p. 102367

  56. [68]

    Hackers Could Target Fax Machines as Backdoor into an Organization’s Network

    “Hackers Could Target Fax Machines as Backdoor into an Organization’s Network.” [Online]. Available: https://www.insurancejournal.com/news/international/2018/08/14/497921.htm. [Accessed: 04- Jun-2024]

  57. [69]

    A Data Exfiltration and Remote Exploitation Attack on Consumer 3D Printers,

    Do, Q., Martini, B., and Choo, K.- K. R., 2016, “A Data Exfiltration and Remote Exploitation Attack on Consumer 3D Printers,” IEEE Trans. Inf. Forensics Secur., 11 (10), pp. 2174 –2186. https://doi.org/10.1109/TIFS.2016.2578285

  58. [70]

    Kuipers, D., and Fabro, M., 2006, Control Systems Cyber Security: Defense in Depth Strategies

  59. [71]

    Cyber-Physical Vulnerabilities in Additive Manufacturing Systems,

    Sturm, L. D., Williams, C. B., Camelio, J. A., White, J., and Parker, R., 2014, “Cyber-Physical Vulnerabilities in Additive Manufacturing Systems,” Context, 7 (8). [Online]. Available: http://sffsymposium.engr.utexas.edu/sites/default/files/2014-075-Sturm.pdf. [Accessed: 01-Feb-2019]

  60. [72]

    Assessing and Augmenting SCADA Cyber Security: A Survey of Techniques,

    Nazir, S., Patel, S., and Patel, D., 2017, “Assessing and Augmenting SCADA Cyber Security: A Survey of Techniques,” Comput. Secur., 70, pp. 436–454. https://doi.org/10.1016/j.cose.2017.06.010

  61. [73]

    Bad Parts: Are Our Manufacturing Systems at Risk of Silent Cyberattacks?,

    Turner, H., White, J., Camelio, J. A., Williams, C., Amos, B., and Parker, R., 2015, “Bad Parts: Are Our Manufacturing Systems at Risk of Silent Cyberattacks?,” IEEE Secur. Priv., 13(3), pp. 40 –47. https://doi.org/10.1109/MSP.2015.60

  62. [74]

    Using 3D Printers as Weapons,

    Yampolskiy, M., Skjellum, A., Kretzschmar, M., Overfelt, R. A., Sloan, K. R., and Yasinsac, A., 2016, “Using 3D Printers as Weapons,” Int. J. Crit. Infrastruct. Prot., 14 , pp. 58 –71. https://doi.org/10.1016/j.ijcip.2015.12.004

  63. [75]

    Analysis and Mitigation of Vulnerabilities in Short -Range Wireless Communications for Industrial Control Systems,

    Reaves, B., and Morris, T., 2012, “Analysis and Mitigation of Vulnerabilities in Short -Range Wireless Communications for Industrial Control Systems,” Int. J. Crit. Infrastruct. Prot., 5 (3–4), pp. 154 –174. https://doi.org/10.1016/j.ijcip.2012.10.001

  64. [76]

    Detecting Cyber -Physical Attacks in CyberManufacturing Systems with Machine Learning Methods,

    Wu, M., Song, Z., and Moon, Y. B., 2019, “Detecting Cyber -Physical Attacks in CyberManufacturing Systems with Machine Learning Methods,” J. Intell. Manuf., 30(3), pp. 1111– 1123. https://doi.org/10.1007/s10845-017-1315-5

  65. [77]

    Cybersecurity for Digital Manufacturing,

    Wu, D., Ren, A., Zhang, W., Fan, F., Liu, P., Fu, X., and Terpenny, J., 2018, “Cybersecurity for Digital Manufacturing,” J. Manuf. Syst., 48, pp. 3–12. https://doi.org/10.1016/j.jmsy.2018.03.006

  66. [78]

    Vulnerability Analysis of Desktop 3D Printer Software,

    Moore, S., Armstrong, P., McDonald, T., and Yampolskiy, M., 2016, “Vulnerability Analysis of Desktop 3D Printer Software,” Proc. - 2016 Resil. Week, RWS 2016, pp. 46– 51. https://doi.org/10.1109/RWEEK.2016.7573305

  67. [79]

    USB-Based Attacks,

    Nissim, N., Yahalom, R., and Elovici, Y., 2017, “USB-Based Attacks,” 70, pp. 675–688

  68. [80]

    Risks Associated with USB Hardware Trojan Devices Used by Insiders,

    Clark, J., Leblanc, S., and Knight, S., 2011, “Risks Associated with USB Hardware Trojan Devices Used by Insiders,” 2011 IEEE International Systems Conference , IEEE, pp. 201 –208. https://doi.org/10.1109/SYSCON.2011.5929130

  69. [81]

    The Industrial Internet of Things ( IIoT ): An Analysis Framework,

    Boyes, H., Hallaq, B., Cunningham, J., and Watson, T., 2018, “The Industrial Internet of Things ( IIoT ): An Analysis Framework,” 101(March), pp. 1–12

  70. [82]

    As Voice Assistants Go Mainstream, Researchers Warn of Vulnerabilities - CNET

    Ry Crist, “As Voice Assistants Go Mainstream, Researchers Warn of Vulnerabilities - CNET.” [Online]. Available: https://www.cnet.com/news/security -researchers-warn-of-voice-vulnerabilities/. [Accessed: 11 - Jun-2024]

  71. [83]

    [Online]

    Zhang, N., Mi, X., Feng, X., Wang, X., Tian, Y., and Qian, F., Understanding and Mitigating the Security Risks of Voice -Controlled Third -Party Skills on Amazon Alexa and Google Home * . [Online]. Available: https://arxiv.org/pdf/1805.01525.pdf. [Accessed: 11-Apr-2019]

  72. [84]

    Researchers Discover Vulnerabilities in Smart Assistants’ Voice Commands - Malwarebytes Labs | Malwarebytes Labs

    “Researchers Discover Vulnerabilities in Smart Assistants’ Voice Commands - Malwarebytes Labs | Malwarebytes Labs.” [Online]. Available: https://blog.malwarebytes.com/cybercrime/2018/05/security- vulnerabilities-smart-assistants/. [Accessed: 11-Apr-2019]

  73. [85]

    [Online]

    DolphinAttack: Inaudible Voice Command - YouTube. [Online]. Available: https://www.youtube.com/watch?v=21HjF4A3WE4. [Accessed: 11-Apr-2019]

  74. [86]

    Alexa, Can i Trust You?,

    Chung, H., Iorga, M., Voas, J., and Lee, S., 2017, “Alexa, Can i Trust You?,” Computer (Long. Beach. Calif)., 50(9), pp. 100–104. https://doi.org/10.1109/MC.2017.3571053

  75. [88]

    A Large -Scale Analysis of the Security of Embedded Firmwares,

    Costin, A., Zaddach, J., Francillon, A., Balzarotti, D., Sophia, E., and France, A., 2014, “A Large -Scale Analysis of the Security of Embedded Firmwares,” 23rd {USENIX} Security Symposium ({USENIX} Security 14), pp. 95–110. [Online]. Available: http://firmware.re. [Accessed: ...

  76. [89]

    Secure Cloud Computing for Critical Infrastructure: A Survey,

    Younis, Y. A., and Kifayat, K., 2013, “Secure Cloud Computing for Critical Infrastructure: A Survey,” Liverpool John Moores Univ. United Kingdom, Tech. Rep, pp. 599–610

  77. [90]

    The Biggest Cybersecurity Crises of 2019 So Far,

    Newman, L., 2019, “The Biggest Cybersecurity Crises of 2019 So Far,” WIRED. [Online]. Available: https://www.wired.com/story/biggest-cybersecurity-crises-2019-so-far/. [Accessed: 18-Jul-2019]

  78. [91]

    Internet of Things (IoT) Cybersecurity Colloquium: A NIST Workshop Proceedings

    Megas, K., Piccarreta, B., and O’Rourke, D. G., 2017, “Internet of Things (IoT) Cybersecurity Colloquium: A NIST Workshop Proceedings.” https://doi.org/10.6028/NIST.IR.8201

  79. [92]

    Data Security in the World of Cloud Computing,

    Kaufman, L. M., 2009, “Data Security in the World of Cloud Computing,” IEEE Secur. Priv., 7 (4), pp. 61– 64

  80. [93]

    A Survey on Security Issues in Service Delivery Models of Cloud Computing,

    Subashini, S., and Kavitha, V., 2011, “A Survey on Security Issues in Service Delivery Models of Cloud Computing,” J. Netw. Comput. Appl., 34(1), pp. 1–11

  81. [94]

    Security and Privacy Challenges in Cloud Computing Environments,

    Takabi, H., Joshi, J. B. D., and Ahn, G.- J., 2010, “Security and Privacy Challenges in Cloud Computing Environments,” IEEE Secur. Priv., 8(6), pp. 24–31

  82. [95]

    Data Security and Privacy Protection Issues in Cloud Computing,

    Chen, D., and Zhao, H., 2012, “Data Security and Privacy Protection Issues in Cloud Computing,” 2012 International Conference on Computer Science and Electronics Engineering, IEEE, pp. 647 –651

  83. [96]

    An Analysis of Security Issues for Cloud Computing,

    Hashizume, K., Rosado, D. G., Fernández-Medina, E., and Fernandez, E. B., 2013, “An Analysis of Security Issues for Cloud Computing,” J. internet Serv. Appl., 4(1), p. 5

  84. [97]

    Internet of Things: Applications and Challenges in Technology and Standardization,

    Bandyopadhyay, D., and Sen, J., 2011, “Internet of Things: Applications and Challenges in Technology and Standardization,” Wirel. Pers. Commun., 58(1), pp. 49–69. https://doi.org/10.1007/s11277-011-0288-5

  85. [98]

    Cyber Security Threats to IoT Applications and Service Domains,

    Tweneboah-Koduah, S., Skouby, K. E., and Tadayoni, R., 2017, “Cyber Security Threats to IoT Applications and Service Domains,” Wirel. Pers. Commun., 95(1), pp. 169–185. https://doi.org/10.1007/s11277-017-4434- 6

  86. [99]

    Internet of Things in Industries: A Survey,

    Da Xu, L., He, W., and Li, S., 2014, “Internet of Things in Industries: A Survey,” IEEE Trans. Ind. informatics, 10(4), pp. 2233–2243

  87. [100]

    Taxonomies for Reasoning About Cyber -Physical Attacks in IoT -Based Manufacturing Systems.,

    Pan, Y., White, J., Schmidt, D. C., Elhabashy, A., Sturm, L., Camelio, J., and Williams, C., 2017, “Taxonomies for Reasoning About Cyber -Physical Attacks in IoT -Based Manufacturing Systems.,” Int. J. Interact. Multimed. Artif. Intell., 4(3), pp. 45–54. https://doi.org/10.978...

  88. [101]

    Self -Secured Control with Anomaly Detection and Recovery in Automotive Cyber -Physical Systems,

    Vatanparvar, K., Abdullah, M., and Faruque, A., 2019, “Self -Secured Control with Anomaly Detection and Recovery in Automotive Cyber -Physical Systems,” 2019 Design, Automation & Test in Europe Conference & Exhibition (DATE) , IEEE, pp. 788 –793. [Online]. Available: http://ai...

  89. [102]

    Intelligent Agents Defending for an IoT World: A Review,

    Coulter, R., and Pan, L., 2018, “Intelligent Agents Defending for an IoT World: A Review,” Comput. Secur., 73, pp. 439–458. https://doi.org/10.1016/j.cose.2017.11.014

  90. [103]

    Securing the Internet of Things,

    Roman, R., Najera, P., and Lopez, J., 2011, “Securing the Internet of Things,” Computer (Long. Beach. Calif)., (9), pp. 51–58

  91. [104]

    Internet of Things (IoT) – A Growing Number of Backdoors into Your Network

    2024, “Internet of Things (IoT) – A Growing Number of Backdoors into Your Network.” [Online]. Available: https://www.happierit.com/knowledge-centre/internet-of-things-iot-a-growing-number-of-backdoors-into- your-network?rq=Internet of Things (IoT). [Accessed: 10-Jun-2024]

  92. [105]

    [Online]

    2011, The Internet of Things How the Next Evolution of the Internet Is Changing Everything. [Online]. Available: https://www.cisco.com/c/dam/en_us/about/ac79/docs/innov/IoT_IBSG_0411FINAL.pdf. [Accessed: 20-Dec-2018]

  93. [106]

    https://doi.org/10.1016/j.jmsy.2018.04.007

  94. [107]

    CATIA Vulnerabilities: National Vulnerability Database

    2023, “CATIA Vulnerabilities: National Vulnerability Database.” [Online]. Available: https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=catia&search_typ e=all. [Accessed: 22-Apr-2023]

  95. [108]

    Mysterious New Ransomware Targets Industrial Control Systems | WIRED

    “Mysterious New Ransomware Targets Industrial Control Systems | WIRED.” [Online]. Available: https://www.wired.com/story/ekans-ransomware-industrial-control-systems/. [Accessed: 24-Feb-2020]

  96. [109]

    The Dangers of Backdoor Software Vulnerabilities and How to Mitigate Them,

    Flores, B., 2019, “The Dangers of Backdoor Software Vulnerabilities and How to Mitigate Them,” Cyber Def. Mag. [Online]. Available: https://www.cyberdefensemagazine.com/the -dangers-of-backdoor-software- vulnerabilities-and-how-to-mitigate-them/. [Accessed: 10-Jul-2019]

  97. [110]

    Hacker Lexicon: What Is a Backdoor?,

    Zetter, K., 2014, “Hacker Lexicon: What Is a Backdoor?,” WIRED. [Online]. Available: https://www.wired.com/2014/12/hacker-lexicon-backdoor/. [Accessed: 10-Jul-2019]

  98. [112]

    Windows XP Support Has Ended - Windows Help

    “Windows XP Support Has Ended - Windows Help.” [Online]. Available: https://support.microsoft.com/en - us/help/14223/windows-xp-end-of-support. [Accessed: 17-Jul-2019]

  99. [113]

    Cybersecurity- the Human Factor Prioritizing People Solutions to Improve the Cyber Resiliency of the Federal Workforce,

    FISSEA, 2017, “Cybersecurity- the Human Factor Prioritizing People Solutions to Improve the Cyber Resiliency of the Federal Workforce,” FISSEA 30th Annu. Conf. [Online]. Available: https://csrc.nist.gov/CSRC/media/Events/FISSEA-30th-Annual- Conference/documents/FISSEA2017_Witk...

  100. [114]

    IIROC, and OCRCVM, 2015, Cybersecurity Best Practices Guide For IIROC Dealer Members

  101. [115]

    AI -Driven Phishing And Deep Fakes: The Future Of Digital Fraud,

    2025, “AI -Driven Phishing And Deep Fakes: The Future Of Digital Fraud,” Forbes. [Online]. Available: https://www.forbes.com/councils/forbestechcouncil/2025/03/10/ai-driven-phishing-and-deep-fakes-the- future-of-digital-fraud/. [Accessed: 10-Mar-2025]

  102. [116]

    Phishing with AI Is Cybersecurity’s New Hook

    Company, M. &, 2025, “Phishing with AI Is Cybersecurity’s New Hook.” [Online]. Available: https://www.mckinsey.com/featured-insights/sustainable-inclusive-growth/charts/phishing-with-ai-is- cybersecuritys-new-hook. [Accessed: 10-Mar-2025]

  103. [117]

    The Human Factor in IT Security: How Employees Are Making Businesses Vulnerable from Within

    Kaspersky, 2022, “The Human Factor in IT Security: How Employees Are Making Businesses Vulnerable from Within.” [Online]. Available: https://www.kaspersky.com/blog/the -human-factor-in-it-security/. [Accessed: 03-Feb-2023]

  104. [118]

    Lab, K., Ready or Not? A Global Survey into Attitudes and Opinions on IT Security

  105. [119]

    Prevalence and Impact of Password Exposure Vulnerabilities in ICS/OT - SecurityWeek

    “Prevalence and Impact of Password Exposure Vulnerabilities in ICS/OT - SecurityWeek.” [Online]. Available: https://www.securityweek.com/prevalence -and-impact-of-password-exposure-vulnerabilities-in- ics-ot/. [Accessed: 09-Dec-2024]

  106. [120]

    Unitronics Vision Legacy Series (Update A) | CISA

    “Unitronics Vision Legacy Series (Update A) | CISA.” [Online]. Available: https://www.cisa.gov/news - events/ics-advisories/icsa-24-109-01. [Accessed: 09-Dec-2024]

  107. [121]

    Authentication Security Best Practices in the Manufacturing Industry

    2022, “Authentication Security Best Practices in the Manufacturing Industry.” [Online]. Available: https://blog.hypr.com/best-practices-for-authentication-security-in-manufacturing. [Accessed: 09-Dec-2024]

  108. [122]

    Vulnerability Management Best Practices

    2023, “Vulnerability Management Best Practices .” [Online]. Available: https://www.wiz.io/academy/vulnerability-management-best-practices. [Accessed: 09-Dec-2024]

  109. [123]

    Kaspersky Lab Survey: One -in-Four Hide Cybersecurity Incidents From Their Employers

    Kaspersky, 2017, “Kaspersky Lab Survey: One -in-Four Hide Cybersecurity Incidents From Their Employers.” [Online]. Available: https://usa.kaspersky.com/about/press -releases/2017_kaseprsky-lab- survey-one-in-four-hide-cybersecurity-incidents-from-their-employers. [Accessed: 14...

  110. [124]

    The Psychology of Cybersecurity Burnout

    2024, “The Psychology of Cybersecurity Burnout.” [Online]. Available: https://www.informationweek.com/cyber-resilience/the-psychology-of-cybersecurity-burnout. [Accessed: 09-Dec-2024]

  111. [125]

    IBM Security X -Force Threat Intelligence Index

    2018, “IBM Security X -Force Threat Intelligence Index.” [Online]. Available: https://securityintelligence.com/2018-ibm-x-force-report-shellshock-fades-gozi-rises-and-insider-threats- soar/?mhsrc=ibmsearch_a&mhq=x-force threat intelligence index 2018. [Accessed: 08-Mar-2022]

  112. [126]

    [Online]

    IBM, 2019, Cost of a Data Breach Report . [Online]. Available: https://www.ibm.com/security/data -breach. [Accessed: 23-Aug-2021]

  113. [127]

    Cost of Insider Threats | ObserveIT

    2022, “Cost of Insider Threats | ObserveIT.” [Online]. Available: https://www.observeit.com/cost-of-insider- threats/. [Accessed: 13-Jun-2024]

  114. [128]

    SP 800 -53 Rev.4 - Security and Privacy Controls for Federal Information Systems and Organizations,

    National Institute of Standards and Technology (NIST), 2014, “SP 800 -53 Rev.4 - Security and Privacy Controls for Federal Information Systems and Organizations,” Natl. Inst. Stand. Technol. - Spec. Publ., 800– 53, pp. 1–460. https://doi.org/10.6028/NIST.SP.800-53r4

  115. [129]

    J., Franz, M., and Miller, D., The Use of Attack Trees in Assessing Vulnerabilities in SCADA Systems

    Byres, E. J., Franz, M., and Miller, D., The Use of Attack Trees in Assessing Vulnerabilities in SCADA Systems. [Online]. Available: https://www.researchgate.net/profile/Eric_Byres/publication/228952316_The_use_of_attack_trees_in_asses sing_vulnerabilities_in_SCADA_systems/lin...

  116. [130]

    Insider Threats as the Main Security Threat in 2017

    2017, “Insider Threats as the Main Security Threat in 2017.” [Online]. Available: https://www.tripwire.com/state-of-security/security-data-protection/insider-threats-main-security-threat- 2017/. [Accessed: 08-Jun-2024]

  117. [131]

    Ex- Employee Fingered in Texas Power Company Hack | WIRED

    2009, “Ex- Employee Fingered in Texas Power Company Hack | WIRED.” [Online]. Available: https://www.wired.com/2009/05/efh/. [Accessed: 30-May-2024]

  118. [132]

    Feds: Hacker Disabled Offshore Oil Platforms’ Leak -Detection System | WIRED

    2009, “Feds: Hacker Disabled Offshore Oil Platforms’ Leak -Detection System | WIRED.” [Online]. Available: https://www.wired.com/2009/03/feds-hacker-dis/. [Accessed: 20-May-2024]

  119. [134]

    P., 2007, Automation, Production Systems, and Computer -Integrated Manufacturing, Prentice Hall Press

    Groover, M. P., 2007, Automation, Production Systems, and Computer -Integrated Manufacturing, Prentice Hall Press

  120. [135]

    A Cyber -Physical Attack Taxonomy for Production Systems: A Quality Control Perspective,

    Elhabashy, A. E., Wells, L. J., Camelio, J. A., and Woodall, W. H., 2019, “A Cyber -Physical Attack Taxonomy for Production Systems: A Quality Control Perspective,” J. Intell. Manuf., 30(6), pp. 2489–2504. https://doi.org/10.1007/s10845-018-1408-9

  121. [136]

    DT4I4 -Secure: Digital Twin Framework for Industry 4.0 Systems Security,

    Lin, Y. -Z., Shao, S., Rahman, M. H., Shafae, M., and Satam, P., 2023, “DT4I4 -Secure: Digital Twin Framework for Industry 4.0 Systems Security,” 2023 IEEE 14th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), IEEE, pp. 200–209

  122. [137]

    Attributing Meanings to Representations of Data: The Case of Statistical Process Control,

    Hoyles, C., Bakker, A., Kent, P., and Noss, R., 2007, “Attributing Meanings to Representations of Data: The Case of Statistical Process Control,” Math. Think. Learn., 9 (4), pp. 331 –360. https://doi.org/10.1080/10986060701533326

  123. [138]

    Cumulative Sum Control Charts for Monitoring Weibull‐distributed Time between Events,

    Shafae, M. S., Dickinson, R. M., Woodall, W. H., and Camelio, J. A., 2015, “Cumulative Sum Control Charts for Monitoring Weibull‐distributed Time between Events,” Qual. Reliab. Eng. Int., 31(5), pp. 839–849

  124. [139]

    C., 2019, Introduction to Statistical Quality Control, John wiley & sons

    Montgomery, D. C., 2019, Introduction to Statistical Quality Control, John wiley & sons

  125. [140]

    The Misuse and Abuse of SPC: A Case Study Examination,

    Bird, D., and Dale, B. G., 1994, “The Misuse and Abuse of SPC: A Case Study Examination,” Int. J. Veh. Des., 15(1–2), pp. 99–107

  126. [141]

    Using Quality Measurements: Practice, Problems and Possibilities,

    Wood, M., and Preece, D., 1992, “Using Quality Measurements: Practice, Problems and Possibilities,” Int. J. Qual. Reliab. Manag

  127. [142]

    Assessing the Performance of Control Charts for Detecting Previously Unexplored Shift Types in High Density Spatial Data,

    Dastoorian, R., Wells, L., and Shafae, M., 2022, “Assessing the Performance of Control Charts for Detecting Previously Unexplored Shift Types in High Density Spatial Data,” Qual. Eng., 34 (1), pp. 125–141

  128. [143]

    The Misuse of Statistics: Concepts, Tools, and a Research Agenda,

    Gardenier, J. S., and Resnik, D. B., 2002, “The Misuse of Statistics: Concepts, Tools, and a Research Agenda,” Account. Res., 9(2), pp. 65–74. https://doi.org/10.1080/08989620212968

  129. [144]

    Quality Control Tools for Cyber-Physical Security of Production Systems,

    Elhabashy, A. E., 2018, “Quality Control Tools for Cyber-Physical Security of Production Systems,” Virginia Polytechnic Institute and State University

  130. [145]

    Trojan Detection and Side-Channel Analyses for Cyber-Security in Cyber -Physical Manufacturing Systems,

    Vincent, H., Wells, L., Tarazaga, P., and Camelio, J., 2015, “Trojan Detection and Side-Channel Analyses for Cyber-Security in Cyber -Physical Manufacturing Systems,” Procedia Manuf., 1 , pp. 77 –85. https://doi.org/https://doi.org/10.1016/j.promfg.2015.09.065

  131. [146]

    Automated Surface Defect Detection Using High - Density Data,

    Wells, L. J., Shafae, M. S., and Camelio, J. A., 2016, “Automated Surface Defect Detection Using High - Density Data,” J. Manuf. Sci. Eng., 138(7)

  132. [147]

    Automated Part Inspection Using 3d Point Clouds,

    Wells, L. J., Shafae, M. S., and Camelio, J. A., 2013, “Automated Part Inspection Using 3d Point Clouds,” International Manufacturing Science and Engineering Conference , American Society of Mechanical Engineers, p. V002T02A034

  133. [148]

    A Survey of Physics -Based Attack Detection in Cyber - Physical Systems,

    Giraldo, J., Urbina, D., Cardenas, A., Valente, J., Faisal, M., Ruths, J., Tippenhauer, N. O., Candell, R., Tippen-Hauer, N. O., and Sandberg, H., 2018, “A Survey of Physics -Based Attack Detection in Cyber - Physical Systems,” ACM Comput. Surv., 51(4), pp. 1–32. https://doi.o...

  134. [149]

    I., Urbina, D

    Urbina, D. I., Urbina, D. I., Giraldo, J., Cardenas, A. A., Valente, J., Faisal, M., Tippenhauer, N. O., Ruths, J., Candell, R., and Sandberg, H., 2016, Survey and New Directions for Physics -Based Attack Detection in Control Systems, US Department of Commerce, National Instit...

  135. [150]

    Acoustic Side-Channel Attacks on Additive Manufacturing Systems,

    Al Faruque, M. A., Chhetri, S. R., Canedo, A., and Wan, J., 2016, “Acoustic Side-Channel Attacks on Additive Manufacturing Systems,” 2016 ACM/IEEE 7th International Conference on Cyber -Physical Systems, ICCPS 2016 - Proceedings, IEEE, pp. 1–10. https://doi.org/10.1109/ICCPS.2...

  136. [151]

    Side Channels of Cyber -Physical Systems: Case Study in Additive Manufacturing,

    Rokka Chhetri, S., and Al Faruque, M. A., 2017, “Side Channels of Cyber -Physical Systems: Case Study in Additive Manufacturing,” IEEE Des. Test, 34(4), pp. 18–25. https://doi.org/10.1109/MDAT.2017.2682225

  137. [152]

    My Smartphone Knows What You Print: Exploring Smartphone -Based Side -Channel Attacks against 3d Printers,

    Song, C., Lin, F., Ba, Z., Ren, K., Zhou, C., and Xu, W., 2016, “My Smartphone Knows What You Print: Exploring Smartphone -Based Side -Channel Attacks against 3d Printers,” Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, ACM, pp. 895–907

  138. [153]

    GPS Jamming and the Impact on Maritime Navigation,

    Grant, A., Williams, P., Ward, N., and Basker, S., 2009, “GPS Jamming and the Impact on Maritime Navigation,” J. Navig., 62(2), pp. 173–187

  139. [154]

    WALNUT: Waging Doubt on the Integrity of MEMS Accelerometers with Acoustic Injection Attacks,

    Trippel, T., Weisse, O., Xu, W., Honeyman, P., and Fu, K., 2017, “WALNUT: Waging Doubt on the Integrity of MEMS Accelerometers with Acoustic Injection Attacks,” 2017 IEEE European Symposium on Security and Privacy (EuroS&P), IEEE, pp. 3–18

  140. [155]

    Machine Learning-Based Layer-Wise Detection of Overheating Anomaly in LPBF Using Photodiode Data,

    Hasan, N., Saha, A. K., Wessman, A., and Shafae, M., 2024, “Machine Learning-Based Layer-Wise Detection of Overheating Anomaly in LPBF Using Photodiode Data,” Manuf. Lett., 41, pp. 1423 –1431. https://doi.org/https://doi.org/10.1016/j.mfglet.2024.09.169. This article has been ...

  141. [156]

    Adversarial Attacks and Mitigation for Anomaly Detectors of Cyber-Physical Systems,

    Jia, Y., Wang, J., Poskitt, C. M., Chattopadhyay, S., Sun, J., and Chen, Y., 2021, “Adversarial Attacks and Mitigation for Anomaly Detectors of Cyber-Physical Systems,” Int. J. Crit. Infrastruct. Prot., 34, p. 100452

  142. [157]

    Siemens SPPA -T3000 | CISA

    2020, “Siemens SPPA -T3000 | CISA.” [Online]. Available: https://www.us -cert.gov/ics/advisories/icsa-19- 351-02. [Accessed: 08-Jun-2024]

  143. [158]

    [Online]

    Anderson, R., Security in Open versus Closed Systems-The Dance of Boltzmann, Coase and Moore. [Online]. Available: https://www.cl.cam.ac.uk/~rja14/Papers/toulouse.pdf. [Accessed: 02 -Jan-2019]

  144. [159]

    Research Challenges for the Security of Control Systems,

    Alvaro A. Cárdenas, Saurabh Amin, S. S., Cárdenas, A. A., Amin, S., Sastry, S., and Alvaro A. Cárdenas, Saurabh Amin, S. S., 2008, “Research Challenges for the Security of Control Systems,” Third Conference on Hot Topics in Security (HOTSEC), Berkeley, CA , pp. 1 –6. [Online]....

  145. [160]

    Cyber -Physical Systems: The next Computing Revolution,

    Rajkumar, R., Lee, I., Sha, L., and Stankovic, J., 2010, “Cyber -Physical Systems: The next Computing Revolution,” Design Automation Conference, IEEE, pp. 731–736

  146. [161]

    Keeping the Bad Guys out: Protecting and Vaccinating Deep Learning with Jpeg Compression,

    Das, N., Shanbhogue, M., Chen, S. -T., Hohman, F., Chen, L., Kounavis, M. E., and Chau, D. H., 2017, “Keeping the Bad Guys out: Protecting and Vaccinating Deep Learning with Jpeg Compression,” arXiv Prepr. arXiv1705.02900

  147. [162]

    Practical Black -Box Attacks against Machine Learning,

    Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A., 2016, “Practical Black -Box Attacks against Machine Learning,” ASIA CCS ’17 Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506–519. https://doi.org/10...

  148. [163]

    How to Ensure Bad Quality in Metal Additive Manufacturing: In-Situ Infrared Thermography from the Security Perspective,

    Slaughter, A., Yampolskiy, M., Matthews, M., King, W. E., Guss, G., and Elovici, Y., 2017, “How to Ensure Bad Quality in Metal Additive Manufacturing: In-Situ Infrared Thermography from the Security Perspective,” Proceedings of the 12th International Conference on Availability...

  149. [164]

    China’s Huawei and ZTE Pose National Security Threat, Says US Committee | Technology | The Guardian

    “China’s Huawei and ZTE Pose National Security Threat, Says US Committee | Technology | The Guardian.” [Online]. Available: https://www.theguardian.com/technology/2012/oct/08/china -huawei-zte-security-threat. [Accessed: 19-Jan-2023]

  150. [165]

    Stress and Failure Analysis of the Connecting Rod of Diesel Engine,

    Witek, L., and Zelek, P., 2019, “Stress and Failure Analysis of the Connecting Rod of Diesel Engine,” Eng. Fail. Anal., 97, pp. 374–382

  151. [166]

    Incremental Machine Learning-Integrated Blockchain for Real -Time Security Protection in Cyber -Enabled Manufacturing Systems,

    Oskolkov, B., Kan, C., Tian, W., Law, A. C. C., and Liu, C., 2025, “Incremental Machine Learning-Integrated Blockchain for Real -Time Security Protection in Cyber -Enabled Manufacturing Systems,” J. Comput. Inf. Sci. Eng., pp. 1–27

  152. [167]

    Proof of Delivery of Digital Assets Using Blockchain and Smart Contracts,

    Hasan, H. R., and Salah, K., 2018, “Proof of Delivery of Digital Assets Using Blockchain and Smart Contracts,” IEEE Access, 6, pp. 65439–65448

  153. [168]

    Distributed Intrusion Detection System in a Multi- Layer Network Architecture of Smart Grids,

    Zhang, Y., Wang, L., Sun, W., Green, R. C., and Alam, M., 2011, “Distributed Intrusion Detection System in a Multi- Layer Network Architecture of Smart Grids,” IEEE Trans. Smart Grid, 2 (4), pp. 796– 808. https://doi.org/10.1109/TSG.2011.2159818

  154. [169]

    2024 Data Breach Investigations Report | Verizon

    2024, “2024 Data Breach Investigations Report | Verizon.” [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/. [Accessed: 10-Mar-2025]

  155. [170]

    Ai - Driven Solutions for Social Engineering Attacks: Detection, Prevention, and Response,

    Fakhouri, H. N., Alhadidi, B., Omar, K., Makhadmeh, S. N., Hamad, F., and Halalsheh, N. Z., 2024, “Ai - Driven Solutions for Social Engineering Attacks: Detection, Prevention, and Response,” 2024 2nd International Conference on Cyber Resilience (ICCR), IEEE, pp. 1–8

  156. [171]

    Digital Audio Signature for 3D Printing Integrity,

    Belikovetsky, S., Solewicz, Y. A., Yampolskiy, M., Toh, J., and Elovici, Y., 2019, “Digital Audio Signature for 3D Printing Integrity,” IEEE Trans. Inf. Forensics Secur., 14(5), pp. 1127 –1141. https://doi.org/10.1109/TIFS.2018.2851584

  157. [172]

    Sabotage Attack Detection for Additive Manufacturing Systems,

    Yu, S. Y., Malawade, A. V., Chhetri, S. R., and Al Faruque, M. A., 2020, “Sabotage Attack Detection for Additive Manufacturing Systems,” IEEE Access, 8 , pp. 27218– 27231. https://doi.org/10.1109/ACCESS.2020.2971947

  158. [173]

    Physically Unclonable Functions: A Study on the State of the Art and Future Research Directions,

    Maes, R., and Verbauwhede, I., 2010, “Physically Unclonable Functions: A Study on the State of the Art and Future Research Directions,” Towards Hardware-Intrinsic Security, Springer, pp. 3–37

  159. [174]

    Assessment & Auditing Resources | NIST

    2025, “Assessment & Auditing Resources | NIST.” [Online]. Available: https://www.nist.gov/cyberframework/assessment-auditing-resources. [Accessed: 10-Mar-2025]

  160. [175]

    Understanding Control Charts - Minitab

    2025, “Understanding Control Charts - Minitab.” [Online]. Available: https://support.minitab.com/en - us/minitab/help-and-how-to/quality-and-process-improvement/control-charts/supporting- topics/basics/understanding-control-charts/. [Accessed: 10-Mar-2025]

  161. [176]

    What Are Statistical Tests?,

    2025, “What Are Statistical Tests?,” NIST. [Online]. Available: https://www.itl.nist.gov/div898/handbook/prc/section1/prc13.htm. [Accessed: 10 -Mar-2025]

  162. [177]

    Example of Xbar Chart - Minitab

    2025, “Example of Xbar Chart - Minitab.” [Online]. Available: https://support.minitab.com/en - This article has been published in the ASME Journal of Computing and Information Science in Engineering (JCISE) https://doi.org/10.1115/1.4068844 Page 39 of 39 us/minitab/help-and-ho...

  163. [178]

    Overview for Xbar -R Chart - Minitab

    2025, “Overview for Xbar -R Chart - Minitab.” [Online]. Available: https://support.minitab.com/en - us/minitab/help-and-how-to/quality-and-process-improvement/control-charts/how-to/variables-charts-for- subgroups/xbar-r-chart/before-you-start/overview/. [Accessed: 10-Mar-2025]

  164. [179]

    Interpret the Key Results for an S Chart - Minitab

    2025, “Interpret the Key Results for an S Chart - Minitab.” [Online]. Available: https://support.minitab.com/en-us/minitab/help-and-how-to/quality-and-process-improvement/control- charts/how-to/variables-charts-for-subgroups/s-chart/interpret-the-results/key-results/. [Accesse...

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.