Repository logo

Adaptive Machine Learning Based Cyber Threat Intelligence in Industrial Control Systems: A Systematic Literature Review

Loading...
Thumbnail Image

Files

Size: 1.75 MB, File format: Adobe PDF

Authors

Nasir, Nabeel

Lutui, Raymond

Sarkar, Nurul I

Vaipulu, Taniela

Supervisor

Degree name

Journal Title

Journal ISSN

Volume Title

Publisher

Elsevier BV

Abstract

The convergence of information and operational technology has rendered Industrial Control Systems (ICS) prime targets for sophisticated, multi-stage cyber attacks that exploit vulnerabilities across different layers of the industrial enterprise. Defending these critical systems necessitates a paradigm shift from static, isolated security controls to intelligent, adaptive, and holistic approaches. This Systematic Literature Review (SLR) synthesizes and critically analyzes 34 recent academic papers published between 2020–2025 to establish the foundational knowledge required to develop novel, adaptive Cyber Threat Intelligence (CTI) mechanisms that leverage Machine Learning (ML) for cross-layer defense. The review is guided by a central research goal: to understand how to build a unified, cross-layer CTI system capable of correlating threat data, managing performance impact, automating data translation, and overcoming significant adoption barriers. Our extensive analysis reveals that while numerous studies have proposed ML-based CTI and cross-layer defense mechanisms, no single existing approach fully integrates these concepts into a cohesive, adaptive system. Key findings highlight the promise of Deep Reinforcement Learning for adaptive defense orchestration, the critical performance efficiencies of lightweight models for edge deployment, the recognized importance of standardization (e.g., STIX/TAXII) for interoperability, and the persistent barriers of data scarcity, trust deficits, and the simulation-to-reality gap. Based on this comprehensive synthesis, we propose a detailed conceptual multi-tier architectural approach that addresses identified gaps and provides a blueprint for future research. This review concludes by outlining an extensive and actionable research agenda for realizing a truly adaptive, resilient, and intelligent cross-layer CTI system for next-generation ICS security. The findings contribute to both academic research and industrial practice by providing a roadmap for developing next-generation security solutions that can adapt to the evolving threat landscape while maintaining operational integrity in critical infrastructure systems.

Description

Keywords

0802 Computation Theory and Mathematics, 0905 Civil Engineering, Cyber threat intelligence (CTI), Industrial control systems (ICS), Machine learning, Cross-layer defense, Interoperability, Purdue model, Zero trust, Adaptive security, Threat correlation

Source

International Journal of Critical Infrastructure Protection, ISSN: 1874-5482 (Print), Elsevier BV, 100874-100874. doi: 10.1016/j.ijcip.2026.100874

Rights statement

CC-BY Creative Commons - Attribution
© 2026 The Authors.

Endorsement

Review

Supplemented By

Referenced By

Creative Commons license

Except where otherwise noted, this item's license is described as CC-BY Creative Commons - Attribution