Pith. sign in

REVIEW 3 cited by

CICAPT-IIOT: A provenance-based APT attack dataset for IIoT environment

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.11278 v1 pith:CGPSPKVI submitted 2024-07-15 cs.CR

classification cs.CR
keywords detectioniiotdatasetattackcicapt-iiotcybersecurityadvanceddata
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The Industrial Internet of Things (IIoT) is a transformative paradigm that integrates smart sensors, advanced analytics, and robust connectivity within industrial processes, enabling real-time data-driven decision-making and enhancing operational efficiency across diverse sectors, including manufacturing, energy, and logistics. IIoT is susceptible to various attack vectors, with Advanced Persistent Threats (APTs) posing a particularly grave concern due to their stealthy, prolonged, and targeted nature. The effectiveness of machine learning-based intrusion detection systems in APT detection has been documented in the literature. However, existing cybersecurity datasets often lack crucial attributes for APT detection in IIoT environments. Incorporating insights from prior research on APT detection using provenance data and intrusion detection within IoT systems, we present the CICAPT-IIoT dataset. The main goal of this paper is to propose a novel APT dataset in the IIoT setting that includes essential information for the APT detection task. In order to achieve this, a testbed for IIoT is developed, and over 20 attack techniques frequently used in APT campaigns are included. The performed attacks create some of the invariant phases of the APT cycle, including Data Collection and Exfiltration, Discovery and Lateral Movement, Defense Evasion, and Persistence. By integrating network logs and provenance logs with detailed attack information, the CICAPT-IIoT dataset presents foundation for developing holistic cybersecurity measures. Additionally, a comprehensive dataset analysis is provided, presenting cybersecurity experts with a strong basis on which to build innovative and efficient security solutions.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. CLIProv: A Contrastive Log-to-Intelligence Multimodal Approach for Threat Detection and Provenance Analysis

    cs.CR 2025-07 conditional novelty 6.0 of 10

    CLIProv detects APT behaviors by embedding provenance log sequences and MITRE ATT&CK text into one semantic space via contrastive learning, then retrieving the closest technique description.

  2. A Novel Short-Term Anomaly Prediction for IIoT with Software Defined Twin Network

    cs.NI 2025-09 reject novelty 4.0 of 10

    A T+15 second anomaly prediction framework for IIoT, built on SDN telemetry and a digital twin, with reported LightGBM-GPU F2 score 0.822 on CICAPT-IIoT2024.

  3. Enhancing IoT Network Security through Adaptive Curriculum Learning and XAI

    cs.CR 2025-01 conditional novelty 4.0 of 10

    A curriculum-learning neural network with LIME feature un-learning and ensemble stacking reports 97 to 98 percent accuracy on Edge-IIoT, CIC-APT-IIoT-2024, and CIC-IoV-2024 intrusion detection benchmarks.

Pith tools