Adaptive Machine Learning Based Cyber Threat Intelligence in Industrial Control Systems: A Systematic Literature Review
Loading...
Files
Size: 1.75 MB, File format: Adobe PDF
Date
Authors
Nasir, Nabeel
Lutui, Raymond
Sarkar, Nurul I
Vaipulu, Taniela
Supervisor
Item type
Degree name
Journal Title
Journal ISSN
Volume Title
Publisher
Elsevier BV
Abstract
The convergence of information and operational technology has rendered Industrial Control Systems (ICS) prime targets for sophisticated, multi-stage cyber attacks that exploit vulnerabilities across different layers of the industrial enterprise. Defending these critical systems necessitates a paradigm shift from static, isolated security controls to intelligent, adaptive, and holistic approaches. This Systematic Literature Review (SLR) synthesizes and critically analyzes 34 recent academic papers published between 2020–2025 to establish the foundational knowledge required to develop novel, adaptive Cyber Threat Intelligence (CTI) mechanisms that leverage Machine Learning (ML) for cross-layer defense. The review is guided by a central research goal: to understand how to build a unified, cross-layer CTI system capable of correlating threat data, managing performance impact, automating data translation, and overcoming significant adoption barriers. Our extensive analysis reveals that while numerous studies have proposed ML-based CTI and cross-layer defense mechanisms, no single existing approach fully integrates these concepts into a cohesive, adaptive system. Key findings highlight the promise of Deep Reinforcement Learning for adaptive defense orchestration, the critical performance efficiencies of lightweight models for edge deployment, the recognized importance of standardization (e.g., STIX/TAXII) for interoperability, and the persistent barriers of data scarcity, trust deficits, and the simulation-to-reality gap. Based on this comprehensive synthesis, we propose a detailed conceptual multi-tier architectural approach that addresses identified gaps and provides a blueprint for future research. This review concludes by outlining an extensive and actionable research agenda for realizing a truly adaptive, resilient, and intelligent cross-layer CTI system for next-generation ICS security. The findings contribute to both academic research and industrial practice by providing a roadmap for developing next-generation security solutions that can adapt to the evolving threat landscape while maintaining operational integrity in critical infrastructure systems.
Description
Keywords
0802 Computation Theory and Mathematics, 0905 Civil Engineering, Cyber threat intelligence (CTI), Industrial control systems (ICS), Machine learning, Cross-layer defense, Interoperability, Purdue model, Zero trust, Adaptive security, Threat correlation
Source
International Journal of Critical Infrastructure Protection, ISSN: 1874-5482 (Print), Elsevier BV, 100874-100874. doi: 10.1016/j.ijcip.2026.100874
Publisher's version
Rights statement
CC-BY Creative Commons - Attribution
© 2026 The Authors.
© 2026 The Authors.
Permanent link
Endorsement
Review
Supplemented By
Referenced By
Creative Commons license
Except where otherwise noted, this item's license is described as CC-BY Creative Commons - Attribution

