IDENTIFYING AND MITIGATING ZERO-DAY VULNERABILITIES IN INDUSTRIAL CONTROL SYSTEMS

dc.contributor.advisorShakir, Humood Wasan
dc.contributor.authorAlali, Yahya Abdullah
dc.date.accessioned2025-06-24T11:51:32Z
dc.date.issued2024-12-29
dc.description.abstractThis dissertation addresses the critical issue of zero-day vulnerabilities within Industrial Control Systems (ICS), which govern essential infrastructure sectors such as energy, water, and manufacturing. As ICS environments integrate with Information Technology (IT) systems for enhanced operational efficiency, they become increasingly susceptible to cyber threats, including undetected zero-day exploits that can severely disrupt physical processes. This study focuses on identifying and mitigating zero-day vulnerabilities within ICS by developing a software tool that monitors and detects deviations in Windows services configuration against baseline configurations set by ICS vendors. The research involved designing a tool using PowerShell to gather, preprocess, and compare service data from Windows-based ICS systems, aiming to identify potential misconfigurations or unauthorized modifications that could signal a zero-day exploit. Through an experimental setup in a controlled ICS environment, the tool was evaluated for its efficiency in detecting deviations in service existence and start modes, key indicators of potential vulnerabilities. Results demonstrate the tool’s high accuracy in detecting configuration drifts, enabling proactive vulnerability management and reducing the ICS attack surface. The study underscores the importance of continuous monitoring, baseline configuration checks, and anomaly detection as proactive security measures for ICS environments. This research contributes significantly to ICS security, proposing a scalable solution for safeguarding critical infrastructure against evolving cyber threats.
dc.format.extent64
dc.identifier.citation10.1109/ITIKD63574.2025.11004725
dc.identifier.isbn979-8-3503-5546-8
dc.identifier.urihttps://hdl.handle.net/20.500.14154/75656
dc.language.isoen_US
dc.publisherSaudi Digital Library
dc.subjectIndustrial Control System
dc.subjectCybersecurity
dc.subjectBaseline Configuration
dc.subjectZero-day Vulnerability
dc.titleIDENTIFYING AND MITIGATING ZERO-DAY VULNERABILITIES IN INDUSTRIAL CONTROL SYSTEMS
dc.typeResearch Papers
sdl.degree.departmentInformation Technology
sdl.degree.disciplineInformation Technology Masters
sdl.degree.grantorAhlia University
sdl.degree.nameMaster's Degree In Information Technology And Computer Science

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
SACM-Dissertation.pdf
Size:
6.39 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.61 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections

Copyright owned by the Saudi Digital Library (SDL) © 2025