An Evidence-Driven Analysis of Threat Information Sharing Challenges for Industrial Control Systems and Future Directions

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Hahn, Adam, Krief, Rubin, Rebori-Carretero, Daniel, Puzis, Rami, Elyashar, Aviad, Urlaub, Nik
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910001588600832
author Hahn, Adam
Krief, Rubin
Rebori-Carretero, Daniel
Puzis, Rami
Elyashar, Aviad
Urlaub, Nik
author_facet Hahn, Adam
Krief, Rubin
Rebori-Carretero, Daniel
Puzis, Rami
Elyashar, Aviad
Urlaub, Nik
contents The increasing cyber threats to critical infrastructure highlight the importance of private companies and government agencies in detecting and sharing information about threat activities. Although the need for improved threat information sharing is widely recognized, various technical and organizational challenges persist, hindering effective collaboration. In this study, we review the challenges that disturb the sharing of usable threat information to critical infrastructure operators within the ICS domain. We analyze three major incidents: Stuxnet, Industroyer, and Triton. In addition, we perform a systematic analysis of 196 procedure examples across 79 MITRE ATT&CK techniques from 22 ICS-related malware families, utilizing automated natural language processing techniques to systematically extract and categorize threat observables. Additionally, we investigated nine recent ICS vulnerability advisories from the CISA Known Exploitable Vulnerability catalog. Our analysis identified four important limitations in the ICS threat information sharing ecosystem: (i) the lack of coherent representation of artifacts related to ICS adversarial techniques in information sharing language standards (e.g., STIX); (ii) the dependence on undocumented proprietary technologies; (iii) limited technical details provided in vulnerability and threat incident reports; and (iv) the accessibility of technical details for observed adversarial techniques. This study aims to guide the development of future information-sharing standards, including the enhancement of the cyber-observable objects schema in STIX, to ensure accurate representation of artifacts specific to ICS environments.
format Preprint
id arxiv_https___arxiv_org_abs_2512_18714
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle An Evidence-Driven Analysis of Threat Information Sharing Challenges for Industrial Control Systems and Future Directions
Hahn, Adam
Krief, Rubin
Rebori-Carretero, Daniel
Puzis, Rami
Elyashar, Aviad
Urlaub, Nik
Cryptography and Security
The increasing cyber threats to critical infrastructure highlight the importance of private companies and government agencies in detecting and sharing information about threat activities. Although the need for improved threat information sharing is widely recognized, various technical and organizational challenges persist, hindering effective collaboration. In this study, we review the challenges that disturb the sharing of usable threat information to critical infrastructure operators within the ICS domain. We analyze three major incidents: Stuxnet, Industroyer, and Triton. In addition, we perform a systematic analysis of 196 procedure examples across 79 MITRE ATT&CK techniques from 22 ICS-related malware families, utilizing automated natural language processing techniques to systematically extract and categorize threat observables. Additionally, we investigated nine recent ICS vulnerability advisories from the CISA Known Exploitable Vulnerability catalog. Our analysis identified four important limitations in the ICS threat information sharing ecosystem: (i) the lack of coherent representation of artifacts related to ICS adversarial techniques in information sharing language standards (e.g., STIX); (ii) the dependence on undocumented proprietary technologies; (iii) limited technical details provided in vulnerability and threat incident reports; and (iv) the accessibility of technical details for observed adversarial techniques. This study aims to guide the development of future information-sharing standards, including the enhancement of the cyber-observable objects schema in STIX, to ensure accurate representation of artifacts specific to ICS environments.
title An Evidence-Driven Analysis of Threat Information Sharing Challenges for Industrial Control Systems and Future Directions
topic Cryptography and Security
url https://arxiv.org/abs/2512.18714