Digital Twins (DTs), optimize operations and monitor performance in Smart Critical Systems (SCS) domains like smart grids and manufacturing. DT-based cybersecurity solutions are in their infancy, lacking a unified strategy to overcome challenges spanning next three to five decades. These challenges include reliable data accessibility from Cyber-Physical Systems (CPS), operating in unpredictable environments. Reliable data sources are pivotal for intelligent cybersecurity operations aided with underlying modeling capabilities across the SCS lifecycle, necessitating a DT. To address these challenges, we propose Security Digital Twins (SDTs) collecting realtime data from CPS, requiring the Shift Left and Shift Right (SLSR) design paradigm for SDT to implement both design time and runtime cybersecurity operations. Incorporating virtual CPS components (VC) in Cloud/Edge, data fusion to SDT models is enabled with high reliability, providing threat insights and enhancing cyber resilience. VC-enabled SDT ensures accurate data feeds for security monitoring for both design and runtime. This design paradigm shift propagates innovative SDT modeling and analytics for securing future critical systems. This vision paper outlines intelligent SDT design through innovative techniques, exploring hybrid intelligence with data-driven and rule-based semantic SDT models. Various operational use cases are discussed for securing smart critical systems through underlying modeling and analytics capabilities.
翻译:数字孪生(DT)用于优化智能关键系统(SCS)领域(如智能电网和制造业)的运维并监控性能。基于DT的网络安全解决方案尚处于起步阶段,缺乏统一策略应对未来三五十年的挑战,包括从运行于不可预测环境中的信息物理系统(CPS)获取可靠数据。可靠数据源对基于模型能力的SCS全生命周期智能网络安全运维至关重要,亟需DT支撑。为应对这些挑战,我们提出安全数字孪生(SDT),从CPS采集实时数据,并引入向左向右(SLSR)设计范式,使SDT能够同时实现设计时与运行时网络安全运维。通过云端/边缘端集成虚拟CPS组件(VC),数据融合至SDT模型具备高可靠性,可提供威胁洞察并增强网络韧性。基于VC的SDT能为设计与运行时安全监控提供精准数据馈送。这一设计范式转变推动了面向未来关键系统安全的创新SDT建模与分析。本愿景论文通过创新技术勾勒智能SDT设计,探索融合数据驱动与规则驱动的语义SDT模型的混合智能,并通过底层建模与分析能力讨论多种保障智能关键系统安全的运维用例。