Authors :
Nitin Bodade
Volume/Issue :
Volume 11 - 2026, Issue 7 - July
Google Scholar :
https://tinyurl.com/yphu7bv6
Scribd :
https://tinyurl.com/ycx3amrk
DOI :
https://doi.org/10.38124/ijisrt/26jul085
Note : A published paper may take 4-5 working days from the publication date to appear in PlumX Metrics, Semantic Scholar, and ResearchGate.
Abstract :
The digitalisation of industrial environments and the increasing number of Industrial Internet of Things (IIoT)
devices have completely increased the attack surface of critical manufacturing and operational technology (OT) systems.
Current signature-based, "reactive" cybersecurity models are clearly failing to keep up with the sophistication and speed of
today's Advanced Persistent Threats (APTs), ransomware-as-a-service (RaaS) operations and supply-chain attacks on
industrial digital systems. Cyber Threat Intelligence (CTI) is now a strategic field and discipline for predicting adversarial
actions, but the frameworks in use are largely tactical, siloed, and reactive, and have very limited ability to conduct realtime predictive analytics in industrial environments.
This paper tackles the identified gap by proposing a new conceptual framework called Artificial Intelligence Powered
Cyber Threat Intelligence (AIPCTI) Framework specifically designed to facilitate predictive, adaptive, and automated
methods of threat intelligence for industrial digital infrastructure. This research uses Design Science Research Methodology
(DSRM) that includes Systematic Literature Review (SLR), Knowledge Elicitation from experts and Structured Conceptual
Design in order to create the framework artefact. The AIPCTI Framework comprises six interdependent layers: Threat
Data Acquisition, Threat Intelligence Fusion, AI Analytics Engine, Predictive Risk Assessment, Automated Response, and
Governance and Compliance. These layers support a continuous, intelligence based cyber defence posture that is consistent
with Zero Trust Architecture (ZTA) principles, as well as the MITRE ATT&CK for ICS knowledge base.
The framework has been developed to incorporate feedback from experts in the field of ICS/OT security and validated
using structured scenario-based reasoning using three representative attack patterns: manufacturing ransomware, energysector APT intrusion and IIoT firmware exploitation. The analysis at the architecture level depicts examples of how the
layered design of AIPCTI would be expected to close certain detection and response gaps identified by indicator-based CTI
platforms and IT-focused SOAR solutions, such as providing the ability for AIPCTI to anticipate attack techniques before
they are executed, as well as to limit automated response with safety logic specific to OT. These findings are expressed as a
design stage evaluation and not as an actual performance while in operation: the framework is not yet in place, nor is it
deployed in a live industrial setting, nor is it claimed to be able to improve the detection rate or response time (even though
it can certainly do that). The research provides a theoretically informed conceptual framework for cybersecurity architects,
offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational
claims.
Keywords :
Cyber Threat Intelligence, Predictive Threat Analytics, Industrial IoT Security, Artificial Intelligence, Design Science Research, MITRE ATT&CK for ICS, Zero Trust Architecture, and Operational Technology Security.
References :
- Lee, J.; Davari, H.; Singh, J.; Pandhare, V. Industrial Artificial Intelligence for Industry 4.0-based Manufacturing Systems. Manuf. Lett. 2018, 18, 20–23. https://doi.org/10.1016/j.mfglet.2018.09.002
- Xu, L.D.; Xu, E.L.; Li, L. Industry 4.0: State of the Art and Future Trends. Int. J. Prod. Res. 2018, 56, 2941–2962. https://doi.org/10.1080/00207543.2018.1444806
- IoT Analytics. State of IoT—Spring 2023; IoT Analytics Research: Hamburg, Germany, 2023.
- Stouffer, K.; Lightman, S.; Pillitteri, V.; Abrams, M.; Hahn, A. NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security; NIST: Gaithersburg, MD, USA, 2023. 5. Langner, R. Stuxnet: Dissecting a Cyberwarfare Weapon. IEEE Secur. Priv. 2011, 9, 49–51. https://doi.org/10.1109/MSP.2011.67
- Brubaker, P.; Clarke, R.; Schneier, B. The Oldsmar Water Treatment Facility Cyber Attack: Lessons Learned. Comp. Secur. J. 2022, 38, 102634.
- Lee, R.M.; Assante, M.J.; Conway, T. ICS Defense Use Case No. 6: Industroyer/Crashoverride—Zero Things Cool About a Threat Group Targeting Power Grids; Dragos Inc.: Hanover, MD, USA, 2022.
- IBM Security. IBM X-Force Threat Intelligence Index 2024; IBM Corporation: Armonk, NY, USA, 2024.
- Mandiant. M-Trends 2024 Special Report; Mandiant Inc.: Reston, VA, USA, 2024.
- Zhu, B.; Joseph, A.; Sastry, S. A Taxonomy of Cyber Attacks on SCADA Systems. In Proceedings of the International Conference on Internet of Things and Cyber-Physical Systems, Dalian, China, 19–22 October 2022; pp. 380– 388.
- CISA. Known Exploited Vulnerabilities Catalog 2024; CISA: Arlington, VA, USA, 2024. Available online:
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog (accessed on 15 March 2025).
- Sommer, R.; Paxson, V. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. In Proceedings of the 2010 IEEE Symposium on Security and Privacy, Oakland, CA, USA, 16–19 May 2010; pp. 305–316.
- Gartner. Definition: Threat Intelligence; Gartner Research: Stamford, CT, USA, 2023. 14. Chismon, D.; Ruks, M. Threat Intelligence: Collecting, Analysing, Evaluating; CREST and MWR InfoSecurity: London, UK, 2023.
- Barnum, S. Standardizing Cyber Threat Intelligence Information with the Structured Threat Information Expression (STIX). MITRE Corporation: McLean, VA, USA, 2022.
- Ghosh, N.; Ghosh, S.K.; Das, S.K. Selectively Deceptive Industrial Control System Security Using Cyber Deception. IEEE Trans. Ind. Inform. 2022, 18, 2184–2193. https://doi.org/10.1109/TII.2021.3086398
- Gartner. What is Threat Intelligence; Gartner Research: Stamford, CT, USA, 2022.
- Hutchins, E.M.; Cloppert, M.J.; Amin, R.M. Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains. In Proceedings of the 6th International Conference on Information Warfare and Security, Washington, DC, USA, 17–18 March 2011; pp. 113–125.
- Jordan, J.; Duggan, J. STIX 2.1 and TAXII 2.1 Specifications; OASIS Open: Burlington, MA, USA, 2023.
- Schlette, D.; Caselli, M.; Pernul, G. A Comparative Study on Cyber Threat Intelligence: The Security Incident Response Perspective. IEEE Commun. Surv. Tutor. 2021, 23, 2525–2556. https://doi.org/10.1109/COMST.2021.3117338
- Tounsi, W.; Rais, H. A Survey on Technical Threat Intelligence in the Age of Sophisticated Cyber Attacks. Comput. Secur. 2018, 72, 212–233. https://doi.org/10.1016/j.cose.2017.09.001
- Wagner, T.D.; Mahbub, K.; Palomar, E.; Abdallah, A.E. Cyber Threat Intelligence Sharing: Survey and Research Directions. Comput. Secur. 2022, 87, 101589. https://doi.org/10.1016/j.cose.2019.101589
- Mavroeidis, V.; Bromander, S. Cyber Threat Intelligence Model: An Evaluation of Taxonomies, Sharing Standards, and Ontologies within Cyber Threat Intelligence. In Proceedings of the 2017 European Intelligence and Security Informatics Conference, Athens, Greece, 11–13 September 2022; pp. 91–98.
- Shin, Y.; Kim, K.; Kim, J. Predicting APT Lateral Movement Paths with Graph Neural Networks. IEEE Access 2023, 11, 29341–29358. https://doi.org/10.1109/ACCESS.2023.3261403
- Bao, Y.; Li, X.; Song, F.; Xu, Z. Predicting Attack Sequences Using LSTM and MITRE ATT&CK. Comput. Secur. 2023, 124, 102971. https://doi.org/10.1016/j.cose.2022.102971
- Deliu, I.; Leichter, C.; Franke, K. Extracting Cyber Threat Intelligence from Hacker Forums: Support Vector Machines versus Convolutional Neural Networks. In Proceedings of the 2017 IEEE International Conference on Big Data, Boston, MA, USA, 11–14 December 2022; pp. 3648–3656.
- Sarker, I.H.; Furhad, M.H.; Nowrozy, R. AI-Driven Cybersecurity: An Overview, Security Intelligence Modeling and Research Directions. SN Comput. Sci. 2021, 2, 173. https://doi.org/10.1007/s42979-021-00557-0
- Radoglou-Grammatikis, P.; Sarigiannidis, P.; Efstathopoulos, G.; Skiadopoulos, E. Securing the Smart Grid: A Comprehensive Compilation of Intrusion Detection and Prevention Systems. IEEE Access 2023, 11, 89093– 89132. https://doi.org/10.1109/ACCESS.2023.3304673 29. Conti, M.; Kaliyar, P.; Lal, C. CENSOR: Cloud-Enabled Secure IoT Architecture over SDN Paradigm. Concurr. Comput. Pract. Exp. 2024, 36, e7817. https://doi.org/10.1002/cpe.7817
- Lin, C.T.; Chen, Y.H.; Wu, M.E. Transformer-Based Temporal Anomaly Detection for Industrial Control Systems. IEEE Trans. Ind. Inform. 2024, 20, 2844–2853. https://doi.org/10.1109/TII.2023.3348201
- Khan, I.A.; Pi, D.; Khan, Z.U.; Hussain, Y.; Nawaz, A. HML-IDS: A Hybrid-Multilevel Anomaly Prediction Approach for Intrusion Detection in SCADA Systems. IEEE Access 2023, 7, 89507–89521. https://doi.org/10.1109/ACCESS.2019.2926575
- Testart, C.; Richter, P.; King, A.; Dainotti, A.; Clark, D. Profiling BGP Serial Hijackers: Capturing Persistent Misbehavior in the Global Routing Table. In Proceedings of the ACM Internet Measurement Conference, Amsterdam, The Netherlands, 21–23 October 2023; pp. 420–434.
- Gupta, M.; Akiri, C.; Aryal, K.; Parker, E.; Praharaj, L. From ChatGPT to ThreatGPT: Impact of Generative AI in Cybersecurity and Privacy. IEEE Access 2023, 11, 80218–80245. https://doi.org/10.1109/ACCESS.2023.3300381
- Ferrag, M.A.; Ndhlovu, M.; Tihanyi, N.; Cordeiro, L.C.; Debbah, M.; Lestable, T. Revolutionizing Cyber Threat Detection with Large Language Models. IEEE Access 2024, 12, 15882–15896. https://doi.org/10.1109/ACCESS.2024.3360362
- Fraunholz, D.; Reti, D.; Schneider, J.T.; Duque Anton, S. Employing Digital Twins for Security Testing of Industrial Control Systems. In Proceedings of the 16th International Conference on Availability, Reliability and Security, Vienna, Austria, 17–20 August 2021. https://doi.org/10.1145/3465481.3470029
- International Electrotechnical Commission. IEC 62443-2-1: Industrial Automation and Control Systems Security; IEC: Geneva, Switzerland, 2010 (revised 2023).
- Stouffer, K.A.; Pillitteri, V.; Lightman, S.; Abrams, M.; Hahn, A. NIST Special Publication 800-82 Rev. 3: Guide to Operational Technology (OT) Security; NIST: Gaithersburg, MD, USA, 2023. https://doi.org/10.6028/NIST.SP.800-82r3
- Dragos Inc. OT Cybersecurity Year in Review 2023; Dragos Inc.: Hanover, MD, USA, 2024.
- Antrobus, R.; Green, B.; Frey, S.; Rashid, A. The Forgotten I in IIoT: A Vulnerability Scanner for Industrial Internet of Things. In Proceedings of the 2019 ACM Workshop on Cyber-Physical Systems Security and Privacy, London, UK, 15 November 2022; pp. 59–64.
- Yang, Y.; McLaughlin, K.; Littler, T.; Sezer, S.; Wang, H.F. Rule-Based Intrusion Detection System for SCADA Networks. In Proceedings of the 2nd IET Renewable Power Generation Conference, Edinburgh, UK, 9–11 September 2023; pp. 1–4.
- Casola, V.; De Benedictis, A.; Rak, M.; Villano, U. A Security SLA-Based Methodology to Deploy and Monitor Security Controls in the Cloud. J. Netw. Comput. Appl. 2022, 197, 103264.
- Sisinni, E.; Saifullah, A.; Han, S.; Jennehag, U.; Gidlund, M. Industrial Internet of Things: Challenges, Opportunities, and Directions. IEEE Trans. Ind. Inform. 2018, 14, 4724–4734. https://doi.org/10.1109/TII.2018.2852491
- Frustaci, M.; Pace, P.; Aloi, G.; Fortino, G. Evaluating Critical Security Issues of the IoT World: Present and Future Challenges. IEEE Internet Things J. 2018, 5, 2483–2495. https://doi.org/10.1109/JIOT.2017.2767291
- Zhang, Y.; Kasahara, S.; Shen, Y.; Jiang, X.; Wan, J. Smart Contract-Based Access Control for the Internet of Things. IEEE Internet Things J. 2023, 6, 1594–1605. https://doi.org/10.1109/JIOT.2018.2847705
- Chaabouni, N.; Mosbah, M.; Zemmari, A.; Sauvignac, C.; Faruki, P. Network Intrusion Detection for IoT Security Based on Learning Techniques. IEEE Commun. Surv. Tutor. 2019, 21, 2671–2701. https://doi.org/10.1109/COMST.2019.2896380
- Hassan, W.U.; Bates, A.; Marino, D. Tactical Provenance Analysis for Endpoint Detection and Response Systems. In
- Proceedings of the 2020 IEEE Symposium on Security and Privacy, San Francisco, CA, USA, 18–20 May 2022; pp. 1172–1189.
- Bianco, D. The Pyramid of Pain. Enterprise Detection & Response Blog. 2023. Available online: https://detect- respond.blogspot.com/2013/03/the-pyramid-of-pain.html (accessed on 15 March 2025).
- Pahi, T.; Leitner, M.; Skopik, F. Analysis and Assessment of Situational Awareness Models for National Cyber Security Centers. In Proceedings of the 13th International Conference on Cyber Conflict, Tallinn, Estonia, 25–28 May 2021; pp. 1–24.
- Stojanović, B.; Hofer-Schmitz, K.; Kleb, U. APT Datasets and Attack Modeling Toward the Development of Intrusion Detection Systems in ICS/SCADA. Comput. Secur. 2024, 139, 103678. https://doi.org/10.1016/j.cose.2023.103678
- Rose, S.; Borchert, O.; Mitchell, S.; Connelly, S. NIST Special Publication 800-207: Zero Trust Architecture; NIST: Gaithersburg, MD, USA, 2020. https://doi.org/10.6028/NIST.SP.800-207
- Aldawood, H.; Skinner, G. Reviewing Cyber Security Social Engineering Training and Awareness Programs—Pitfalls and Ongoing Issues. Future Internet 2019, 11, 73. https://doi.org/10.3390/fi11030073
- Kephart, N.; Siber, A.; Bhat, V. Implementing Zero Trust Architecture in Industrial Control Systems: Challenges and Recommendations. Comput. Secur. 2023, 132, 103367. https://doi.org/10.1016/j.cose.2023.103367
- Mehraj, S.; Banday, M.T. Establishing a Zero Trust Strategy in Cloud Computing Environment. In Proceedings of the 2020 International Conference on Computer Communication and Informatics, Coimbatore, India, 22–24 January 2020; pp. 1–6.
- Stafford, V. Zero Trust Architecture; NIST: Gaithersburg, MD, USA, 2023. Available online: https://www.nist.gov/publications/zero-trust-architecture (accessed on 20 March 2025).
- Haque, M.A.; Shetty, S.; Krishnappa, B. ICS-CRAT: A Cyber Resilience Assessment Tool for Industrial Control
- Systems. In Proceedings of the 2019 IEEE 9th Annual Computing and Communication Workshop and Conference, Las Vegas, NV, USA, 7–9 January 2022; pp. 0137–0143.
- MITRE ATT&CK for ICS. ATT&CK for Industrial Control Systems Knowledge Base; MITRE Corporation: McLean, VA, USA, 2024. Available online: https://attack.mitre.org/matrices/ics/ (accessed on 1 March 2025).
- Mohan, M.; Lam, K.Y.; Pan, L. Internet of Things-Based Cyber Risk Assessment System for Critical Infrastructure Protection in Smart Cities. IEEE Trans. Ind. Inform. 2023, 19, 1037–1046. https://doi.org/10.1109/TII.2022.3177316
- Skopik, F.; Pahi, T. Under False Flag: Using Technical Artifacts for Cyber Attack Attribution. Cybersecurity 2020, 3,
- 8. https://doi.org/10.1186/s42400-020-00048-4 59. Varga, S.; Brynielsson, J.; Franke, U. Cyber-Threat Perception and Risk Management in the Swedish Financial Sector. Comput. Secur. 2021, 105, 102239. https://doi.org/10.1016/j.cose.2021.102239
- Husák, M.; Komárková, J.; Bou-Harb, E.; Čeleda, P. Survey of Attack Projection, Prediction, and Forecasting in Cyber
- Security. IEEE Commun. Surv. Tutor. 2019, 21, 640–660. https://doi.org/10.1109/COMST.2018.2871866
- Creswell, J.W.; Creswell, J.D. Research Design: Qualitative, Quantitative, and Mixed Methods Approaches, 5th ed.; SAGE Publications: Thousand Oaks, CA, USA, 2022.
- Peffers, K.; Tuunanen, T.; Rothenberger, M.A.; Chatterjee, S. A Design Science Research Methodology for Information Systems Research. J. Manag. Inf. Syst. 2007, 24, 45–77. https://doi.org/10.2753/MIS0742- 1222240302
- Gregor, S.; Hevner, A.R. Positioning and Presenting Design Science Research for Maximum Impact. MIS Q. 2013, 37, 337–355. https://doi.org/10.25300/MISQ/2013/37.2.01
- Hevner, A.R.; March, S.T.; Park, J.; Ram, S. Design Science in Information Systems Research. MIS Q. 2004, 28, 75– 105. https://doi.org/10.2307/25148625
- Phahlamohlaka, J.; Jansen van Vuuren, J.; Coetzee, A. Cyber Security Awareness Toolkit for National Security: An Approach to South Africa's Cyber Security Policy Implementation. In Proceedings of the 2011 Information Security South Africa Conference, Johannesburg, South Africa, 15–17 August 2022; pp. 1–8.
- European Commission. Industry 5.0: Towards a Sustainable, Human-Centric and Resilient European Industry; European Commission: Brussels, Belgium, 2022. 67. National Institute of Standards and Technology. Cybersecurity Framework 2.0; NIST: Gaithersburg, MD, USA, 2024.https://doi.org/10.6028/NIST.CSWP.29
- European Union Agency for Cybersecurity. ENISA Threat Landscape 2024; ENISA: Heraklion, Greece, 2024.
- Maehara, T.; Yamamoto, A.; Kikuchi, H. Practical Evaluation of Cyber Threat Intelligence Sharing in Financial Institutions. J. Cybersecur. 2023, 9, tyad013. https://doi.org/10.1093/cybsec/tyad013
- Williams, J.; Howard, A.; Kavanagh-Psaila, K. Evaluating Cyber Threat Intelligence Platforms: A Taxonomy-Based Approach. Comput. Secur. 2024, 145, 103974. https://doi.org/10.1016/j.cose.2024.103974.
The digitalisation of industrial environments and the increasing number of Industrial Internet of Things (IIoT)
devices have completely increased the attack surface of critical manufacturing and operational technology (OT) systems.
Current signature-based, "reactive" cybersecurity models are clearly failing to keep up with the sophistication and speed of
today's Advanced Persistent Threats (APTs), ransomware-as-a-service (RaaS) operations and supply-chain attacks on
industrial digital systems. Cyber Threat Intelligence (CTI) is now a strategic field and discipline for predicting adversarial
actions, but the frameworks in use are largely tactical, siloed, and reactive, and have very limited ability to conduct realtime predictive analytics in industrial environments.
This paper tackles the identified gap by proposing a new conceptual framework called Artificial Intelligence Powered
Cyber Threat Intelligence (AIPCTI) Framework specifically designed to facilitate predictive, adaptive, and automated
methods of threat intelligence for industrial digital infrastructure. This research uses Design Science Research Methodology
(DSRM) that includes Systematic Literature Review (SLR), Knowledge Elicitation from experts and Structured Conceptual
Design in order to create the framework artefact. The AIPCTI Framework comprises six interdependent layers: Threat
Data Acquisition, Threat Intelligence Fusion, AI Analytics Engine, Predictive Risk Assessment, Automated Response, and
Governance and Compliance. These layers support a continuous, intelligence based cyber defence posture that is consistent
with Zero Trust Architecture (ZTA) principles, as well as the MITRE ATT&CK for ICS knowledge base.
The framework has been developed to incorporate feedback from experts in the field of ICS/OT security and validated
using structured scenario-based reasoning using three representative attack patterns: manufacturing ransomware, energysector APT intrusion and IIoT firmware exploitation. The analysis at the architecture level depicts examples of how the
layered design of AIPCTI would be expected to close certain detection and response gaps identified by indicator-based CTI
platforms and IT-focused SOAR solutions, such as providing the ability for AIPCTI to anticipate attack techniques before
they are executed, as well as to limit automated response with safety logic specific to OT. These findings are expressed as a
design stage evaluation and not as an actual performance while in operation: the framework is not yet in place, nor is it
deployed in a live industrial setting, nor is it claimed to be able to improve the detection rate or response time (even though
it can certainly do that). The research provides a theoretically informed conceptual framework for cybersecurity architects,
offices of industrial CISO's, and policy makers, as well as a well- defined research agenda for empirical testing of operational
claims.
Keywords :
Cyber Threat Intelligence, Predictive Threat Analytics, Industrial IoT Security, Artificial Intelligence, Design Science Research, MITRE ATT&CK for ICS, Zero Trust Architecture, and Operational Technology Security.