Publication Date
8-31-2026
Abstract
Recent attacks on America's critical infrastructure have drawn increased attention on securing industrial control systems and operational technology in power plants, utility companies, and other sectors providing public services. Attack detection and mitigation strategies on these systems have shown promising results using machine learning and other statistical baselining techniques, mostly using supervised learning and classification. Unsupervised learning using cluster analysis and other techniques remain mostly unexplored. In this paper, we propose multi-layered feature extraction and hybrid clustering framework to detect fine-grained nested attack patterns in Modbus-over-TCP traffic. Operating under the assumption of known number of distinct network categories, our approach achieves traffic segregation without label training. The results are validated using MITRE ATT&CK framework and serve as threat interpretation for industrial control systems environments. We provide a comprehensive analysis by calculating silhouette scores for each clustering stage, achieving a global macro-cluster separation score of 0.411 and localized sub-cluster semantic consistency. The results demonstrate that pipeline successfully distills pure, unidirectional attack vectors from operational baselines and show promising results for further research in this area.