{"id":"https://openalex.org/W3126952132","doi":"https://doi.org/10.1109/ecrime51433.2020.9493257","title":"When will my PLC support Mirai? The security economics of large-scale attacks against Internet-connected ICS devices","display_name":"When will my PLC support Mirai? The security economics of large-scale attacks against Internet-connected ICS devices","publication_year":2020,"publication_date":"2020-11-16","ids":{"openalex":"https://openalex.org/W3126952132","doi":"https://doi.org/10.1109/ecrime51433.2020.9493257","mag":"3126952132"},"language":"en","primary_location":{"id":"doi:10.1109/ecrime51433.2020.9493257","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ecrime51433.2020.9493257","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 APWG Symposium on Electronic Crime Research (eCrime)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.17863/cam.59520","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5009313157","display_name":"Michael G. Dodson","orcid":null},"institutions":[{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Michael Dodson","raw_affiliation_strings":["University of Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge","institution_ids":["https://openalex.org/I241749"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025243398","display_name":"Alastair R. Beresford","orcid":"https://orcid.org/0000-0003-0818-6535"},"institutions":[{"id":"https://openalex.org/I241749","display_name":"University of Cambridge","ror":"https://ror.org/013meh722","country_code":"GB","type":"education","lineage":["https://openalex.org/I241749"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Alastair R. Beresford","raw_affiliation_strings":["University of Cambridge"],"affiliations":[{"raw_affiliation_string":"University of Cambridge","institution_ids":["https://openalex.org/I241749"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5018467214","display_name":"Daniel Thomas","orcid":"https://orcid.org/0000-0001-8936-0683"},"institutions":[{"id":"https://openalex.org/I181647926","display_name":"University of Strathclyde","ror":"https://ror.org/00n3w3b69","country_code":"GB","type":"education","lineage":["https://openalex.org/I181647926"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Daniel R. Thomas","raw_affiliation_strings":["University of Strathclyde"],"affiliations":[{"raw_affiliation_string":"University of Strathclyde","institution_ids":["https://openalex.org/I181647926"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5009313157"],"corresponding_institution_ids":["https://openalex.org/I241749"],"apc_list":null,"apc_paid":null,"fwci":1.065,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.78186913,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9983999729156494,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9979000091552734,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.8904139399528503},{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.8077654838562012},{"id":"https://openalex.org/keywords/cybercrime","display_name":"Cybercrime","score":0.7532010078430176},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6909115314483643},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.6769838929176331},{"id":"https://openalex.org/keywords/population","display_name":"Population","score":0.6221759915351868},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.48001307249069214},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.3569898009300232},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.1455521285533905}],"concepts":[{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.8904139399528503},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.8077654838562012},{"id":"https://openalex.org/C2779390178","wikidata":"https://www.wikidata.org/wiki/Q29137","display_name":"Cybercrime","level":3,"score":0.7532010078430176},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6909115314483643},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.6769838929176331},{"id":"https://openalex.org/C2908647359","wikidata":"https://www.wikidata.org/wiki/Q2625603","display_name":"Population","level":2,"score":0.6221759915351868},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.48001307249069214},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3569898009300232},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.1455521285533905},{"id":"https://openalex.org/C149923435","wikidata":"https://www.wikidata.org/wiki/Q37732","display_name":"Demography","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1109/ecrime51433.2020.9493257","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ecrime51433.2020.9493257","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 APWG Symposium on Electronic Crime Research (eCrime)","raw_type":"proceedings-article"},{"id":"pmh:oai:strathprints.strath.ac.uk:75272","is_oa":false,"landing_page_url":"https://strathprints.strath.ac.uk/view/author/1255500.html>;","pdf_url":null,"source":{"id":"https://openalex.org/S4306402226","display_name":"Strathprints: The University of Strathclyde institutional repository (University of Strathclyde)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I181647926","host_organization_name":"University of Strathclyde","host_organization_lineage":["https://openalex.org/I181647926"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"NonPeerReviewed"},{"id":"pmh:oai:www.repository.cam.ac.uk:1810/312428","is_oa":false,"landing_page_url":"https://www.repository.cam.ac.uk/handle/1810/312428","pdf_url":null,"source":{"id":"https://openalex.org/S4306401777","display_name":"Apollo (University of Cambridge)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I241749","host_organization_name":"University of Cambridge","host_organization_lineage":["https://openalex.org/I241749"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference Object"},{"id":"doi:10.17863/cam.59520","is_oa":true,"landing_page_url":"https://doi.org/10.17863/cam.59520","pdf_url":null,"source":{"id":"https://openalex.org/S7407050737","display_name":"Apollo","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.17863/cam.59520","is_oa":true,"landing_page_url":"https://doi.org/10.17863/cam.59520","pdf_url":null,"source":{"id":"https://openalex.org/S7407050737","display_name":"Apollo","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6000000238418579,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G712205639","display_name":null,"funder_award_id":"EP/M020320/1","funder_id":"https://openalex.org/F4320334627","funder_display_name":"Engineering and Physical Sciences Research Council"}],"funders":[{"id":"https://openalex.org/F4320321848","display_name":"Cambridge Trust","ror":"https://ror.org/05sprqy15"},{"id":"https://openalex.org/F4320323264","display_name":"Gates Cambridge Trust","ror":"https://ror.org/033sn5p83"},{"id":"https://openalex.org/F4320334627","display_name":"Engineering and Physical Sciences Research Council","ror":"https://ror.org/0439y7842"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W288692132","https://openalex.org/W312374340","https://openalex.org/W1557652964","https://openalex.org/W2001637908","https://openalex.org/W2002080807","https://openalex.org/W2037202491","https://openalex.org/W2039148409","https://openalex.org/W2040356698","https://openalex.org/W2045591401","https://openalex.org/W2114398364","https://openalex.org/W2203951347","https://openalex.org/W2295108256","https://openalex.org/W2599557761","https://openalex.org/W2608113618","https://openalex.org/W2610896886","https://openalex.org/W2748868501","https://openalex.org/W2766170424","https://openalex.org/W2798110387","https://openalex.org/W2889217075","https://openalex.org/W2941107726","https://openalex.org/W2945492034","https://openalex.org/W2948072163","https://openalex.org/W2955618369","https://openalex.org/W2966195573","https://openalex.org/W2973219882","https://openalex.org/W2980771234","https://openalex.org/W2980839873","https://openalex.org/W2987824313","https://openalex.org/W3039858569","https://openalex.org/W3039975887","https://openalex.org/W3130529786","https://openalex.org/W3168177696","https://openalex.org/W4239628477","https://openalex.org/W4288079454","https://openalex.org/W6610408230","https://openalex.org/W6610899039","https://openalex.org/W6677217071","https://openalex.org/W6743493502","https://openalex.org/W6754140786","https://openalex.org/W6763238779","https://openalex.org/W6766742129","https://openalex.org/W6780328031"],"related_works":["https://openalex.org/W2375896275","https://openalex.org/W2166943775","https://openalex.org/W1903420481","https://openalex.org/W2158007046","https://openalex.org/W2775236000","https://openalex.org/W2071426633","https://openalex.org/W2349754162","https://openalex.org/W119088923","https://openalex.org/W4253323281","https://openalex.org/W2355641539"],"abstract_inverted_index":{"For":[0],"nearly":[1],"a":[2,32,133,140],"decade,":[3],"security":[4,141],"researchers":[5],"have":[6,24],"highlighted":[7],"the":[8,39,67,96,105,113,118,158,166,174],"grave":[9],"risk":[10],"presented":[11],"by":[12,49,112],"Internet-connected":[13,50,148],"Industrial":[14],"Control":[15],"Systems":[16],"(ICS).":[17],"Predictions":[18],"of":[19,31,35,116,135,161,168],"targeted":[20],"and":[21,54,72,86,122,152,165,178],"indiscriminate":[22],"attacks":[23,41,47,146],"yet":[25],"to":[26,64,93,138,155,180],"materialise":[27],"despite":[28],"continued":[29],"growth":[30],"vulnerable":[33],"population":[34,68],"devices.":[36],"We":[37,52,74,131],"investigate":[38],"missing":[40],"against":[42,147],"ICS,":[43],"focusing":[44],"on":[45],"large-scale":[46,145],"enabled":[48],"populations.":[51],"fingerprint":[53],"track":[55,76],"more":[56,176],"than":[57],"10":[58],"000":[59,78],"devices":[60],"over":[61],"four":[62],"years":[63],"confirm":[65],"that":[66,95,171],"is":[69,129],"growing,":[70],"continuously-connected,":[71],"unpatched.":[73],"also":[75],"150":[77],"botnet":[79],"hosts,":[80],"monitor":[81],"120":[82],"global":[83],"ICS":[84,106,120,164],"honeypots,":[85],"sift":[87],"70":[88],"million":[89],"underground":[90],"forum":[91],"posts":[92],"show":[94],"cybercrime":[97],"community":[98],"has":[99],"little":[100],"competence":[101],"or":[102],"interest":[103,162],"in":[104,150,163],"domain.":[107],"Attackers":[108],"may":[109],"be":[110],"dissuaded":[111],"high":[114],"cost":[115],"entry,":[117],"fragmented":[119],"population,":[121],"limited":[123],"onboard":[124],"resources;":[125],"however,":[126],"this":[127],"justification":[128],"incomplete.":[130],"use":[132,153],"series":[134],"case":[136],"studies":[137],"develop":[139],"economics":[142],"model":[143],"for":[144],"populations":[149],"general,":[151],"it":[154],"explain":[156],"both":[157],"current":[159],"lack":[160],"features":[167],"Industry":[169],"4.0":[170],"will":[172],"make":[173],"domain":[175],"accessible":[177],"attractive":[179],"attackers.":[181]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":1}],"updated_date":"2026-04-05T17:49:38.594831","created_date":"2025-10-10T00:00:00"}
