Adaptive Machine Learning Based Cyber Threat Intelligence in Industrial Control Systems: A Systematic Literature Review
| aut.relation.articlenumber | 100874 | |
| aut.relation.endpage | 100874 | |
| aut.relation.journal | International Journal of Critical Infrastructure Protection | |
| aut.relation.startpage | 100874 | |
| dc.contributor.author | Nasir, Nabeel | |
| dc.contributor.author | Lutui, Raymond | |
| dc.contributor.author | Sarkar, Nurul I | |
| dc.contributor.author | Vaipulu, Taniela | |
| dc.date.accessioned | 2026-07-08T21:59:45Z | |
| dc.date.issued | 2026-07-13 | |
| dc.description.abstract | The convergence of information and operational technology has rendered Industrial Control Systems (ICS) prime targets for sophisticated, multi-stage cyber attacks that exploit vulnerabilities across different layers of the industrial enterprise. Defending these critical systems necessitates a paradigm shift from static, isolated security controls to intelligent, adaptive, and holistic approaches. This Systematic Literature Review (SLR) synthesizes and critically analyzes 34 recent academic papers published between 2020–2025 to establish the foundational knowledge required to develop novel, adaptive Cyber Threat Intelligence (CTI) mechanisms that leverage Machine Learning (ML) for cross-layer defense. The review is guided by a central research goal: to understand how to build a unified, cross-layer CTI system capable of correlating threat data, managing performance impact, automating data translation, and overcoming significant adoption barriers. Our extensive analysis reveals that while numerous studies have proposed ML-based CTI and cross-layer defense mechanisms, no single existing approach fully integrates these concepts into a cohesive, adaptive system. Key findings highlight the promise of Deep Reinforcement Learning for adaptive defense orchestration, the critical performance efficiencies of lightweight models for edge deployment, the recognized importance of standardization (e.g., STIX/TAXII) for interoperability, and the persistent barriers of data scarcity, trust deficits, and the simulation-to-reality gap. Based on this comprehensive synthesis, we propose a detailed conceptual multi-tier architectural approach that addresses identified gaps and provides a blueprint for future research. This review concludes by outlining an extensive and actionable research agenda for realizing a truly adaptive, resilient, and intelligent cross-layer CTI system for next-generation ICS security. The findings contribute to both academic research and industrial practice by providing a roadmap for developing next-generation security solutions that can adapt to the evolving threat landscape while maintaining operational integrity in critical infrastructure systems. | |
| dc.identifier.citation | International Journal of Critical Infrastructure Protection, ISSN: 1874-5482 (Print), Elsevier BV, 100874-100874. doi: 10.1016/j.ijcip.2026.100874 | |
| dc.identifier.doi | 10.1016/j.ijcip.2026.100874 | |
| dc.identifier.issn | 1874-5482 | |
| dc.identifier.uri | http://hdl.handle.net/10292/21568 | |
| dc.language | en | |
| dc.publisher | Elsevier BV | |
| dc.relation.uri | https://www.sciencedirect.com/science/article/pii/S1874548226000466 | |
| dc.rights | CC-BY Creative Commons - Attribution | |
| dc.rights | © 2026 The Authors. | |
| dc.rights.accessrights | OpenAccess | |
| dc.rights.uri | http://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | 0802 Computation Theory and Mathematics | |
| dc.subject | 0905 Civil Engineering | |
| dc.subject | Cyber threat intelligence (CTI) | |
| dc.subject | Industrial control systems (ICS) | |
| dc.subject | Machine learning | |
| dc.subject | Cross-layer defense | |
| dc.subject | Interoperability | |
| dc.subject | Purdue model | |
| dc.subject | Zero trust | |
| dc.subject | Adaptive security | |
| dc.subject | Threat correlation | |
| dc.title | Adaptive Machine Learning Based Cyber Threat Intelligence in Industrial Control Systems: A Systematic Literature Review | |
| dc.type | Journal Article | |
| pubs.elements-id | 767089 |
