MULTI-VECTOR ATTACKS ON CYBER-PHYSICAL SYSTEMS: MECHANISMS, DETECTION, AND PROTECTION EXAMPLES
https://doi.org/10.53360/2788-7995-2026-1(21)-12
Abstract
The article presents a comprehensive and in-depth review of multi-vector cyberattacks implemented in cyber-physical systems (CPS). The study provides a detailed analysis of the key architectural prerequisites of CPS, threat models at the intersection of information technology and operational technology (IT/OT), as well as the mechanisms for coordinating cyber and physical impacts. The main types of attacks are systematized, including false data injection (FDI/FDIA), malware targeting industrial control systems and PLCs, supply-chain attacks, ransomware, denial-of-service (DoS) attacks, insider threats, and direct physical interference. Their interconnection and amplification effects within a unified compromise scenario are demonstrated.
Based on open scientific studies and industry reports, the paper analyzes notable cases such as Stuxnet, cyberattacks on Ukraine’s energy infrastructure, CrashOverride/Industroyer, TRITON/Trisis, and ransomware incidents in industrial environments. In addition, a risk-oriented matrix based on the principle «Attack Type – CPS Layer» is proposed. A practical anomaly-detection pipeline using IT/OT event correlation and machine-learning methods is described.
The work includes tables, diagrams, and graphs illustrating CPS architecture, the lifecycle of multivector operations, and engineering security measures aligned with the standards ST RK ISO/IEC 27001, NIST, ISA/IEC 62443, and MITRE ATT&CK for ICS.
Keywords
About the Authors
K. M. SagindykovRussian Federation
Kakim Moldabekovich Sagindykov – Candidate of Technical Sciences (Ph.D.), Associate Professor of the Department of Information Security
0100008, 2 Satpayev Street, Astana
F. B. Tebueva
Russian Federation
Fariza Bilyalovna Tebuyeva – Doctor of Physical and Mathematical Sciences, Professor of the Department of Computational Mathematics and Cybernetics
355017, 1 Pushkina Street, Stavropol
N. Zh. Mukusheva
Kazakhstan
Nazym Zhumageldyevna Mukusheva – PhD student (Doctoral student) of the Department of Information Security
0100008, 2 Satpayev Street, Astana
References
1. Cyber-Physical Systems Security – A Survey / A. Humayed et al // IEEE Internet of Things Journal. – 2017. – Vol. 4, № 6. – P. 1802-1831. https://arxiv.org/abs/1701.04525.
2. Liu Y. False Data Injection Attacks against State Estimation in Electric Power Grids / Y. Liu, P. Ning, M.K. Reiter // Proceedings of the 16th ACM Conference on Computer and Communications Security (CCS 2009). – New York: ACM, 2009. – P. 21-32.
3. СТ РК ISO/IEC 27001-2023. Информационные технологии. Методы обеспечения безопасности. Системы менеджмента информационной безопасности. Требования. – Астана: Комитет технического регулирования и метрологии, 2023.
4. NIST SP 800-82 Rev. 3. Guide to Operational Technology (OT) Security. – Gaithersburg: National Institute of Standards and Technology, 2023. https://doi.org/10.6028/NIST.SP.800-82r3.
5. ISA/IEC 62443. Industrial Automation and Control Systems Security: Series of Standards. – Research Triangle Park: International Society of Automation, 2023. https://www.iec.ch/dyn/www/f?p=103:85:0::::FSP_LANG_ID:25 (дата обращения: 25.01.2026).
6. MITRE ATT&CK® Framework. Knowledge Base for Adversary Tactics and Techniques (ICS Domain). – Версия 18. – MITRE Corporation, 2025. https://attack.mitre.org (дата обращения: 25.01.2026).
7. Karnouskos S. Stuxnet Worm Impact on Industrial Cyber-Physical System Security / S. Karnouskos // Proceedings of the 37th Annual Conference of the IEEE Industrial Electronics Society. – Melbourne, 2011. – P. 4490-4494.
8. Langner R. To Kill a Centrifuge: A Technical Analysis of What Stuxnet’s Creators Tried to Achieve. – Hamburg: The Langner Group, 2011. – 32 p.
9. TRITON: How It Disrupted Safety Systems and Changed the Threat Landscape of Industrial Control Systems / А. Carcano еt al // Black Hat USA 2018 Proceedings. – Las Vegas, 2018.
10. CISA. MAR-17-352-01 HatMan (TRITON/TRISIS) – Safety System Targeted Malware (Update A). – Washington, DC: Cybersecurity and Infrastructure Security Agency, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).
11. Google Cloud Threat Intelligence. TRITON Threat Actor Profile and Detection Methods. – Google, 2023. https://cloud.google.com/security (дата обращения: 25.01.2026).
12. Dragos Inc. CRASHOVERRIDE: Analysis of the Threat to Electric Grid Operations. – Hanover: Dragos, 2017.
13. CISA. CrashOverride Malware Alert and Mitigations. – Washington, DC, 2017. https://www.cisa.gov (дата обращения: 25.01.2026).
14. ESET Research. Industroyer2: Industroyer Reloaded. – Bratislava: ESET, 2022. https://www.welivesecurity.com (дата обращения: 25.01.2026).
15. CISA. IR-ALERT-H-16-056-01: Cyber-Attack Against Ukrainian Critical Infrastructure. – Updated 20.07.2021. – Washington, DC. https://www.cisa.gov (дата обращения: 25.01.2026).
16. SANS Institute, E-ISAC. Analysis of the Cyber Attack on the Ukrainian Power Grid. – Bethesda, 2016.
17. Tuptuk N. Security of Smart Manufacturing Systems / N. uptuk, S. Hailes // Journal of Manufacturing Systems. – 2018. – Vol. 47. – P. 93-106. https://doi.org/10.1016/j.jmsy.2018.04.007.
18. Ransomware on Cyber-Physical Systems: Taxonomies, Case Studies, Security Gaps and Open Challenges / M. Benmalek et al // Computers & Security. – 2023. – Vol. 124.
19. Securing the Industrial Internet of Things against Ransomware Attacks // Journal of Network and Computer Applications. – 2023. – Vol. 212.
20. False Data Injection Attack in Smart Grid CPS: Issues and Detection Algorithms // Computers & Security. – 2023. – Vol. 122.
21. False Data Injection Attack in Smart Grid: Model and Detection Based on Deep Reinforcement Learning // Frontiers in Energy Research. – 2022. – Vol. 10.
22. ENIGMA: An Explainable Digital Twin Security Solution for Cyber-Physical Systems // Computers & Security. – 2023. – Vol. 123.
23. A Survey on Security-Enhancing Digital Twins: Models, Applications and Challenges // Computer Communications. – 2025. – Vol. 214.
Review
For citations:
Sagindykov K.M., Tebueva F.B., Mukusheva N.Zh. MULTI-VECTOR ATTACKS ON CYBER-PHYSICAL SYSTEMS: MECHANISMS, DETECTION, AND PROTECTION EXAMPLES. Bulletin of Shakarim University. Technical Sciences. 2026;1(1(21)):110-118. (In Kazakh) https://doi.org/10.53360/2788-7995-2026-1(21)-12
JATS XML















