Pith. sign in

REVIEW 2 cited by

Cyber security of OT networks: A tutorial, survey of attacks and overview of current state of defense tools, protocols, & challenges

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2502.14017 v4 pith:JLJZ7RHV submitted 2025-02-19 cs.CR

classification cs.CR
keywords emphcybersecurityresilienceaccessconvergencecyberdetectionhealthcare
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The convergence of Operational Technology (OT) and Information Technology (IT) under Industry~4.0 has widened the cyber-attack surface of critical infrastructure across manufacturing, energy, transportation, water, and healthcare. This survey synthesizes OT/IT cybersecurity along four axes. First, we taxonomize \emph{attack vectors} that traverse the IT--OT boundary, separating IT-side initial access (phishing, exploits, supply-chain compromise, exposed remote access) from OT-side propagation and impact (insecure protocols, weak authentication, firmware tampering, control-logic manipulation). Second, we review \emph{defensive technologies} -- signature-based intrusion detection, AI/ML anomaly detection, Zero Trust Architecture, blockchain-based event logging, digital twins, and OT-aware Security Operations Centers -- and identify remaining \emph{gaps}: OT-specific patch management, dataset scarcity for ML, IoMT segmentation, and the absence of consistent resilience metrics. Third, we compile a cross-validated \emph{historical record} of 69 high-impact incidents spanning 2010--2025, from Stuxnet to Jaguar Land Rover, and quantify their \emph{commercial effects} sector by sector using figures sourced from SEC filings, government post-incident reviews, and primary regulatory disclosures. Fourth, we map the \emph{regulatory landscape}: NIST Cybersecurity Framework2.0 and SP~800-82~Rev.~3, IEC~62443, the EU NIS2 Directive, DORA, the Cyber Resilience Act, NERC~CIP, and healthcare-specific regimes (IEC-80001-1, FDA, NIST-SP-1800-8). A sectoral deep-dive on healthcare illustrates the IT--OT convergence threat model under high-consequence conditions. The result is a single, source-traceable reference on where OT/IT cybersecurity stands, what the historical record costs defenders who lag, and where investment yields the highest marginal return on resilience.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. An Experimental Study of Machine Learning-Based Intrusion Detection for OPC UA over Industrial Private 5G Networks

    cs.CR 2026-03 conditional novelty 5.0 of 10

    Supervised machine-learning classifiers can distinguish benign from malicious OPC UA traffic on a private 5G testbed, with F1 scores above 0.9 for most attacks, though reproducibility is limited.

  2. Generative AI for CAD Automation: Leveraging Large Language Models for 3D Modelling

    cs.HC 2025-07 conditional novelty 3.0 of 10

    An LLM-powered FreeCAD pipeline with error-driven re-prompting succeeds on simple and moderate 3D shapes but fails on highly constrained parameterized models.

Pith tools