Högskolan i Skövde

his.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Advanced Persistent Threats (APT) in the Energy Sector
University of Skövde, School of Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Advanced Persistent Threats (APTs) pose cybersecurity threats to the energy sector, specifically targeting Industrial Control Systems (ICS). APTs use sophisticated methods for prolonged cyber-attacks that find system vulnerabilities to enable operational takeover, financial damage, and security risks at a national level. The study investigates how APTs persist and how energy infrastructure security withstands them while detailing their effects on security resilience for energy systems.The study adopts a systematic literature review (SLR) methodology to analyse peer-reviewed research published between 2015 and 2025 about APT tactics, techniques, and procedures (TTPS) through the MITRE ATT&CK Matrix for ICS. It also presents findings about ICS attack methods alongside their security implications and identifies flaws in current mitigation strategies. It then suggests adaptive detection methods before presenting a framework to improve resistance against persistent threats. Traditional cybersecurity approaches prove inadequate for dealing with the current evolution of APT tactics, thus demanding immediate implementation of proactive detection mechanisms. This research supports continuous monitoring, proactive security measures, and artificial intelligence systems detecting irregular activities. The study merges threat intelligence while providing functional security upgrades for Industrial Control Systems infrastructure. Future studies should empirically test the proposed mitigation strategies to strengthen APT defence measures within the energy sector.

Place, publisher, year, edition, pages
2025. , p. 40
Keywords [en]
Industrial Control Systems, Energy Sector, Cybersecurity, MITRE ATT&CK
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:his:diva-25261OAI: oai:DiVA.org:his-25261DiVA, id: diva2:1972349
Subject / course
Informationsteknologi
Educational program
Privacy, Information and Cyber Security - Master's Programme 120 ECTS
Examiners
Available from: 2025-06-18 Created: 2025-06-18 Last updated: 2025-09-29Bibliographically approved

Open Access in DiVA

fulltext(495 kB)118 downloads
File information
File name FULLTEXT01.pdfFile size 495 kBChecksum SHA-512
6c954fb213880d31b17acc76aaf47563de8968a6366cbb7dd57aa68ab54d6bb57d51c1c8730ff0caf49764648ced3e3ecb1815d84f9a67e65513fd974d104d1f
Type fulltextMimetype application/pdf

By organisation
School of Informatics
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 119 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 474 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • apa-cv
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf