cyber digital twins

Design and build simulation‑ready, emulated representations of cyber and networked systems by reconstructing real deployments into network topologies, device configurations, traffic/log traces, and attacker‑behavior models. These cyber digital twins reproduce operational dynamics and produce auditable evaluation traces to support controlled experimentation, testing, validation, and analysis at scale.

cyberdigitaltwins

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.37
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

Automatic Generation of Digital Twins for Network Testing

Oct 03, 2025
SD
Shenjia Ding
🏛️ University of Glasgow

Manual pre-deployment testing and validation of communication software in autonomous network evolution is time-consuming and labor-intensive. Method: This paper proposes a digital twin (DT) automated generation method aligned with the ITU-T Autonomous Networks architecture, integrating network modeling, automated orchestration, and parameter-driven simulation to generate executable, high-fidelity DT instances directly from real-world network configurations. Contribution/Results: The approach significantly reduces manual configuration overhead and enables seamless integration of the DT environment into existing verification workflows, supporting efficient execution of experimental subsystems. Experimental evaluation demonstrates that the generated DTs meet practical testing requirements in both accuracy and runtime efficiency. To the best of our knowledge, this work achieves the first end-to-end automated construction and closed-loop validation of digital twins compliant with the ITU-T G.1000 series standards.

Automating digital twin creation for network testingEnabling efficient autonomous network experimentation subsystemsReducing manual configuration effort in validation tools

This work addresses the limitations of existing cybersecurity datasets, which are predominantly static and ill-suited for enabling controllable replay and traceability in heterogeneous, multi-protocol environments. To overcome this, the authors propose a scenario-oriented, container-native testing platform that leverages declarative configuration to parameterize the generation of both adversarial and benign network traffic, log collection, and dataset integration. The platform encapsulates 60 attack scenarios, nine target services, and benign traffic generators within single-purpose containers and integrates them into an automated pipeline for feature extraction and experimental execution. Designed with reproducibility, auditability, and extensibility in mind, the framework significantly reduces operational bias and supports fully traceable, reproducible experiments in complex settings such as IoT and IIoT networks.

cybersecurity experimentationdataset generationmulti-protocol environments

Quantitative Measurement of Cyber Resilience: Modeling and Experimentation

Mar 28, 2023
MJ
Michael J. Weisman
🏛️ DEVCOM Army Research Laboratory | Pennsylvania State University | ICF International | University of California, Irvine

Current cyber-physical systems (CPS) in vehicular environments lack quantitative, experimentally grounded methods for assessing network resilience. Method: This study constructs an experimental testbed replicating real-world truck operational conditions and conducts multiple rounds of malware injection attacks, simultaneously collecting network- and physical-layer data on resistance and recovery behaviors. Contribution/Results: We introduce the novel concept of “bonware” to holistically characterize both cybersecurity defense capability and physical resilience, formalized via an analytically tractable mathematical model. We further define and extract experimentally identifiable, quantitative resilience metrics—termed elastic features—for the first time. Sensitivity analysis confirms these metrics exhibit significant discriminability with respect to attack intensity, defensive strategies, and physical redundancy. This work bridges a critical gap by advancing vehicular CPS resilience from qualitative description to quantifiable, comparable, and optimizable measurement.

Attack RecoveryCyber ResilienceMeasurement Tools

This work addresses the limitations of existing adversarial simulation tools, which rely on agent-based instrumentation of target systems, often leaving anomalous artifacts and failing to faithfully replicate human attacker behavior—particularly in critical phases of the cyber kill chain such as initial access and interactive operations. To overcome these shortcomings, the authors propose and implement an open-source attack scripting language coupled with an agentless execution engine that closely emulates real-world attacker tactics. This approach enables high-fidelity, interactive simulation of complete kill chain stages, including initial access, privilege escalation, and lateral movement. Experimental results demonstrate that system logs generated by this method exhibit significantly greater behavioral similarity to those produced by actual human-driven attacks, thereby enhancing the realism and effectiveness of security testing and intrusion detection research.

adversary emulationattack automationcyber attack scenarios

Latest Papers

What's happening recently
View more

SCyTAG: Scalable Cyber-Twin for Threat-Assessment Based on Attack Graphs

Dec 27, 2025
DT
David Tayouri
🏛️ Ben-Gurion University of the Negev | Fujitsu Research Europe | Fujitsu Technology Solutions

Existing cybersecurity risk assessment methods suffer from a dichotomy: manual analysis relies heavily on expert knowledge and is infeasible for frequent execution, while automated approaches—such as attack graph– or threat simulation–based techniques—are hindered by the high overhead and poor scalability of conventional network twins. To address this, we propose an attack graph–guided paradigm for generating Minimal-Viable Network Twins (MV-NTs), automatically constructing lightweight, scenario-specific twin environments containing only mission-critical components derived from real-world Cyber Threat Intelligence (CTI) reports. Our method integrates attack graph modeling, topology reduction, CTI semantic parsing, and precise scenario mapping to enable accurate, efficient, and non-intrusive threat impact simulation. Evaluation on both real and synthetic enterprise networks demonstrates that MV-NT reduces component count by 85% and resource consumption by 50% compared to full-topology twins, without compromising attack simulation fidelity—achieving, for the first time, a closed-loop assessment pipeline from CTI to executable simulation.

Automates attack graph generation for cyber threat assessmentCreates minimal cyber twins to emulate specific attack scenariosReduces resource needs while maintaining emulation fidelity

Existing cyber ranges struggle to faithfully evaluate the timing behavior of Byzantine Fault Tolerance (BFT) protocols in cyber-physical systems, while real-world testing poses significant security risks. This work proposes ByzTwin-Range, a novel two-layer architecture that uniquely integrates digital twins with BFT protocol testing, enabling controlled experimentation, fault injection, and what-if analysis grounded in real operational data. By overcoming the temporal fidelity limitations of conventional ranges, the system incorporates industrial standards such as OPC UA, TSN, FMI/HLA, and QUIC/mTLS to support continuous validation, adaptive hardening, and differential privacy analysis. Empirical evaluations successfully uncovered critical vulnerabilities—including timeout misconfigurations, timing misjudgments, and adversarial delay attacks—and demonstrated enhanced system resilience through a secure feedback channel.

Byzantine Fault ToleranceCyber RangeCyber-Physical Systems

Reusing Model Validation Methods for the Continuous Validation of Digital Twins of Cyber-Physical Systems

Dec 01, 2025
JM
Joost Mertens
🏛️ University of Antwerp | Ansymo/Cosys-lab | Flanders Make

To address the loss of fidelity in digital twins caused by dynamic physical system evolution—such as maintenance, wear, and human intervention—this paper proposes a model-verification-based continuous validation framework. The framework integrates real-time monitoring with historical data comparison to construct an interpretable validation metric system, incorporates a lightweight anomaly detection mechanism, and introduces a data-driven parameter self-adaptation estimation algorithm for online twin diagnosis and closed-loop model updating. Unlike conventional static calibration methods, our approach enables long-term trustworthiness preservation and autonomous evolution of the digital twin. Evaluated on an industrial quay crane use case, the framework accurately detects system deviations and dynamically refines model parameters, reducing modeling error by 37.2% and improving maintenance response timeliness by 52%. These results demonstrate significant enhancements in the representativeness, robustness, and engineering practicality of digital twins.

Corrects digital twin errors via parameter estimation from data.Detects anomalies in twinned systems using validation metrics.Ensures digital twin validity for evolving cyber-physical systems.

This study addresses the methodological gap in IoT security research between low-fidelity simulations and costly, hard-to-reproduce physical testbeds. To bridge this divide, the authors propose BYOT-CPS, a hybrid cyber-physical testbed that integrates real IoT devices—such as smart bulbs and cameras—with virtual networks emulated in GNS3. Designed to meet core requirements of fidelity, heterogeneity, scalability, reproducibility, and isolation, the platform implements a structured experimental environment comprising enterprise, service, attack, and monitoring zones. The system successfully demonstrates mixed physical-virtual networking, penetration testing, Mirai-style DDoS attack emulation, and fine-grained traffic monitoring. BYOT-CPS effectively narrows the gap between simulation and physical experimentation, offering a robust infrastructure for IoT security research, education, and third-party evaluation.

cyber-physical systemsemulationIoT security

Trace-driven Path Emulation of Satellite Networks using Hypatia

Oct 30, 2025
MO
Martin Ottens
🏛️ Friedrich-Alexander-Universität Erlangen-Nürnberg

Existing discrete-event simulators (e.g., Hypatia) struggle to accurately evaluate real-world protocols and applications in LEO mega-constellation networks, exhibiting a substantial fidelity gap between simulation and empirical measurements. To bridge this gap, we propose a trajectory-driven satellite network path simulation–replay architecture: leveraging Hypatia for offline, high-fidelity path modeling and feature extraction to generate reusable end-to-end trajectory files, which are then replayed in real time on actual hardware and software platforms. This tightly couples simulation with network emulation. The architecture supports multi-constellation scenarios and precisely reproduces dynamic network characteristics—including latency, bandwidth, and topology evolution. Experimental evaluation demonstrates a correlation of 0.96 between simulated and replayed results, significantly enhancing the realism and reproducibility of protocol and application assessments in LEO satellite networks.

Bridging simulation and real-time emulation of satellite networksEvaluating Internet protocols for LEO satellite mega-constellationsReproducing satellite network behavior using trace-driven emulation

Hot Scholars

MM

Michele Magno

ETH Zurich
Wireless sensor networksSmart Sensors and Internet of ThingsWake up RadioPower management
ZL

Zhaoyang Lyu

PhD of Information Engineering, The Chinese University of Hong Kong
machine learning
HY

Heecheol Yoo

MORAI Inc.
Computer VisionAutonomous Driving