@article{10.1145/3510410, author = {Kayan, Hakan and Nunes, Matthew and Rana, Omer and Burnap, Pete and Perera, Charith}, title = {Cybersecurity of Industrial Cyber-Physical Systems: A Review}, year = {2022}, issue_date = {January 2022}, publisher = {Association for Computing Machinery}, address = {New York, NY, USA}, volume = {54}, number = {11s}, issn = {0360-0300}, url = {https://doi.org/10.1145/3510410}, doi = {10.1145/3510410}, abstract = {Industrial cyber-physical systems (ICPSs) manage critical infrastructures by controlling the processes based on the “physics” data gathered by edge sensor networks. Recent innovations in ubiquitous computing and communication technologies have prompted the rapid integration of highly interconnected systems to ICPSs. Hence, the “security by obscurity” principle provided by air-gapping is no longer followed. As the interconnectivity in ICPSs increases, so does the attack surface. Industrial vulnerability assessment reports have shown that a variety of new vulnerabilities have occurred due to this transition. Although there are existing surveys in this context, very little is mentioned regarding the outputs of these reports. While these reports show that the most exploited vulnerabilities occur due to weak boundary protection, these vulnerabilities also occur due to limited or ill-defined security policies. However, current literature focuses on intrusion detection systems (IDSs), network traffic analysis (NTA) methods, or anomaly detection techniques. Hence, finding a solution for the problems mentioned in these reports is relatively hard. We bridge this gap by defining and reviewing ICPSs from a cybersecurity perspective. In particular, multi-dimensional adaptive attack taxonomy is presented and utilized for evaluating real-life ICPS cyber incidents. Finally, we identify the general shortcomings and highlight the points that cause a gap in existing literature while defining future research directions.}, journal = {ACM Comput. Surv.}, month = {sep}, articleno = {229}, numpages = {35}, keywords = {cybersecurity, Cyber-physical systems, industrial control systems} }