Digital twins for incident response in critical infrastructure
Abstract
Critical infrastructure underpins day-to-day life and is crucial to maintaining living standards and public health. Much of critical infrastructure is built upon Industrial Control Systems (ICS) that have been undergoing a digital transformation fuelled by the promotion of Industry 4.0 concepts, such as edge-computing, integrated machine learning (ML) and artificial intelligence (AI), and cloud integration. While these technologies are advertised as net benefits for ICSs, they put critical process control systems at risk by increasing the number of open services, ports, and protocols, which an adversary can exploit to cause real-world impacts. Incident Response (IR) in critical infrastructure brings with it some unique challenges, including high system availability requirements and a safety culture that has largely been reluctant to embrace technological change. As a result, IR practitioners are left with a high volume of data to analyse, few bespoke ICS-specific cyber security tools, and less autonomy when interacting with digital components. Digital Twins (DTs) – virtual representations of real-world systems – have been proposed for many applications in the manufacturing domain, but have not been adequately explored for assisting IR practitioners in responding to cyber-attacks that target ICSs. To that end, this thesis investigates the application of DTs in critical infrastructure domains. Firstly, the thesis examines how DTs can be integrated into existing IR procedures to provide new information and assurances for an organisation, thus increasing response efficiency and the likelihood of successful threat eradication. Secondly, the thesis demonstrates a novel method for utilising DTs for producing data for a range of conditions that may not be safe to produce in the real- world system. This data is used in the training, validation, and testing of an ML-based cyber security model. Finally, the thesis presents a critical-infrastructure-appropriate architecture for implementing DTs, utilising varying levels of automation for IR activities. Crucially, the stakeholders within critical infrastructure are considered throughout this thesis, to ensure that the contributions are able to be appropriately applied in the real world. The impact of DTs on IR activities is demonstrated both on a procedural level – through the integration of DTs in existing IR processes – and at a technical level – through the improvement of cyber security models and the development of a novel DT architecture. Thesis is embargoed until 31 December 2026.