Skip to content

Author

Halil Dursunoglu

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

#software testing Dataset Open access Aug 2026

PGR-Guard for IT-to-OT Cyberattack Detection]{PGR-Guard: Cross-Layer Detection and Prevention of IT-to-OT Cyberattacks in Small Power-Generation Facilities

This repository contains the reproducibility package for the study “PGR-Guard: Cross-Layer Detection and Prevention of IT-to-OT Cyberattacks in Small Power-Generation Facilities.” The study introduces PGR-Guard, an applied cybersecurity framework designed to detect and interrupt multi-stage attack progression from information technology environments into operational technology and cyber-physical processes. The framework correlates five security layers: identity activity, network behavior, operational technology protocol activity, controller state, and physical-process context. The repository includes the synthetic/emulated dataset, Python source code, holdout evaluation results, confidence intervals, scenario-level detection results, ablation analysis, statistical significance tests, threshold-selection results, and publication figures used in the manuscript. The evaluation models ten representative attack scenarios, including password spraying, valid-account compromise, internal reconnaissance, IT-to-OT traversal, engineering workstation access, PLC discovery, unauthorized controller reads and writes, controller task modification, and operational disruption. The experiments compare PGR-Guard with signature-based intrusion detection, OT-only anomaly detection, and an independent multi-sensor baseline. On the separated holdout evaluation set, PGR-Guard achieved approximately 0.990 precision, 0.879 recall, 0.931 F1 score, 2.55-second mean time to detection, 97.8% attack interruption rate, and 99.7% Cyber-Physical Prevention Rate (CPPR). The package contains: reproduce_pgr_guard.py — end-to-end reproducibility script PGR_Guard_synthetic_trials.csv — trial-level synthetic/emulated dataset holdout performance and confidence-interval files attack-scenario detection results ablation-study results statistical significance analyses threshold-selection results publication figures data dictionary and software requirements Important data provenance note: the included dataset is generated from a controlled synthetic/emulated OT cybersecurity model. It does not contain telemetry from the 2026 UK power-generation cyber incident, a real utility, a physical power-generation facility, or a physical PLC testbed. The results should therefore be interpreted as controlled emulation results rather than real-world operational measurements. Fixed random seeds are included in the source code to support reproducibility. The repository is intended to support independent verification, extension, and comparison of cross-layer IT-to-OT cyberattack detection methods.

Halil Dursunoglu · 0 citations
#software testing Dataset Open access Aug 2026

PGR-Guard for IT-to-OT Cyberattack Detection]{PGR-Guard: Cross-Layer Detection and Prevention of IT-to-OT Cyberattacks in Small Power-Generation Facilities

This repository contains the reproducibility package for the study “PGR-Guard: Cross-Layer Detection and Prevention of IT-to-OT Cyberattacks in Small Power-Generation Facilities.” The study introduces PGR-Guard, an applied cybersecurity framework designed to detect and interrupt multi-stage attack progression from information technology environments into operational technology and cyber-physical processes. The framework correlates five security layers: identity activity, network behavior, operational technology protocol activity, controller state, and physical-process context. The repository includes the synthetic/emulated dataset, Python source code, holdout evaluation results, confidence intervals, scenario-level detection results, ablation analysis, statistical significance tests, threshold-selection results, and publication figures used in the manuscript. The evaluation models ten representative attack scenarios, including password spraying, valid-account compromise, internal reconnaissance, IT-to-OT traversal, engineering workstation access, PLC discovery, unauthorized controller reads and writes, controller task modification, and operational disruption. The experiments compare PGR-Guard with signature-based intrusion detection, OT-only anomaly detection, and an independent multi-sensor baseline. On the separated holdout evaluation set, PGR-Guard achieved approximately 0.990 precision, 0.879 recall, 0.931 F1 score, 2.55-second mean time to detection, 97.8% attack interruption rate, and 99.7% Cyber-Physical Prevention Rate (CPPR). The package contains: reproduce_pgr_guard.py — end-to-end reproducibility script PGR_Guard_synthetic_trials.csv — trial-level synthetic/emulated dataset holdout performance and confidence-interval files attack-scenario detection results ablation-study results statistical significance analyses threshold-selection results publication figures data dictionary and software requirements Important data provenance note: the included dataset is generated from a controlled synthetic/emulated OT cybersecurity model. It does not contain telemetry from the 2026 UK power-generation cyber incident, a real utility, a physical power-generation facility, or a physical PLC testbed. The results should therefore be interpreted as controlled emulation results rather than real-world operational measurements. Fixed random seeds are included in the source code to support reproducibility. The repository is intended to support independent verification, extension, and comparison of cross-layer IT-to-OT cyberattack detection methods.

Halil Dursunoglu · 0 citations