The transformation of previously isolated Critical Infrastructures (CIs) into intricate Systems-of-Systems has rendered them vulnerable to various threats. CIs are characterized by long life cycles and high availability requirements, which pose significant challenges in maintaining cybersecurity throughout their operational life cycle. Existing testing methodologies prove inadequate and may compromise the CI’s operational continuity. This paper proposes to shift testing activities to a Digital Twin (DT) connected to the CI. The DT provides a digital counterpart of the real system, enabling cost-effective testing without compromising operational integrity. For this approach, we present an enterprise architecture called the cybersecurity DT reference architecture. Through a camera surveillance system use case, we demonstrate the feasibility of this reference architecture, focusing on what-if testing using DT-enabled attack simulations. We show how to enhance decision-making when evaluating system configurations and how to deploy optimized configurations to the real system.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Reference Architecture of Cybersecurity Digital Twin

  • Taru Itäpelto,
  • Mohammed Elhajj,
  • Marten van Sinderen,
  • Maria Iacob

摘要

The transformation of previously isolated Critical Infrastructures (CIs) into intricate Systems-of-Systems has rendered them vulnerable to various threats. CIs are characterized by long life cycles and high availability requirements, which pose significant challenges in maintaining cybersecurity throughout their operational life cycle. Existing testing methodologies prove inadequate and may compromise the CI’s operational continuity. This paper proposes to shift testing activities to a Digital Twin (DT) connected to the CI. The DT provides a digital counterpart of the real system, enabling cost-effective testing without compromising operational integrity. For this approach, we present an enterprise architecture called the cybersecurity DT reference architecture. Through a camera surveillance system use case, we demonstrate the feasibility of this reference architecture, focusing on what-if testing using DT-enabled attack simulations. We show how to enhance decision-making when evaluating system configurations and how to deploy optimized configurations to the real system.