<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Computational nanotechnology</journal-id><journal-title-group><journal-title xml:lang="en">Computational nanotechnology</journal-title><trans-title-group xml:lang="ru"><trans-title>Computational nanotechnology</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2313-223X</issn><issn publication-format="electronic">2587-9693</issn><publisher><publisher-name xml:lang="en">YUR-VAK</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">350191</article-id><article-id pub-id-type="doi">10.33693/2313-223X-2025-12-3-115-122</article-id><article-id pub-id-type="edn">BGUXHV</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>METHODS AND SYSTEMS OF INFORMATION PROTECTION, INFORMATION SECURITY</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>МЕТОДЫ И СИСТЕМЫ ЗАЩИТЫ ИНФОРМАЦИИ, ИНФОРМАЦИОННАЯ БЕЗОПАСНОСТЬ</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">Digital twin-based method for detecting information security threats in critical information infrastructure objects</article-title><trans-title-group xml:lang="ru"><trans-title>Метод обнаружения признаков угроз информационной безопасности объектов критической информационной инфраструктуры на основе цифровых двойников</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-6579-0988</contrib-id><contrib-id contrib-id-type="spin">5691-8947</contrib-id><name-alternatives><name xml:lang="en"><surname>Mityakov</surname><given-names>Evgenii S.</given-names></name><name xml:lang="ru"><surname>Митяков</surname><given-names>Евгений Сергеевич</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Dr. Sci. (Econ.), Professor, head, KB-9 Department</p></bio><bio xml:lang="ru"><p>доктор экономических наук, профессор, заведующий, кафедра КБ-9</p></bio><email>mityakov@mirea.ru</email><xref ref-type="aff" rid="aff1"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">MIREA – Russian Technological University</institution></aff><aff><institution xml:lang="ru">МИРЭА – Российский технологический университет</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2025-11-02" publication-format="electronic"><day>02</day><month>11</month><year>2025</year></pub-date><volume>12</volume><issue>3</issue><fpage>115</fpage><lpage>122</lpage><history><date date-type="received" iso-8601-date="2025-11-07"><day>07</day><month>11</month><year>2025</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2025, Yur-VAK</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2025, Юр-ВАК</copyright-statement><copyright-year>2025</copyright-year><copyright-holder xml:lang="en">Yur-VAK</copyright-holder><copyright-holder xml:lang="ru">Юр-ВАК</copyright-holder><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://www.urvak.ru/contacts/</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.rcsi.science/2313-223X/article/view/350191">https://journals.rcsi.science/2313-223X/article/view/350191</self-uri><abstract xml:lang="en"><p>The article presents a method for detecting information security (IS) threat indicators in critical information infrastructure (CII) facilities using a digital twin (DT) with an adaptive mechanism. It addresses the limitations of traditional IS approaches under conditions of scarce real attack data, challenges in testing on operational CII facilities, and difficulties in identifying targeted, evasive threats. A dual-loop method (DT loop and CII facility loop) integrated with a three-level adaptation mechanism (operational, tactical, strategic modes) is proposed. The method encompasses stages of synthetic data generation, model training/testing in the DT, detection/classification at the facility, and defines adaptation trigger. Key advantages include the ability to safely generate threat scenarios and train in the virtual DT environment, automated maintenance of threat detection models. Validation results on a synthetic model of energy facility control system show significant improvement in quality metrics after adaptation.</p></abstract><trans-abstract xml:lang="ru"><p>В статье представлен метод обнаружения признаков угроз информационной безопасности (ИБ) объектов критической информационной инфраструктуры (КИИ) на основе цифрового двойника (ЦД) с адаптивным механизмом. Рассматриваются ограничения традиционных подходов ИБ в условиях дефицита данных о реальных атаках, сложности тестирования на действующих объектах КИИ и трудностей выявления целенаправленных, маскирующихся угроз. Предложен двухконтурный метод обнаружения признаков угроз ИБ (контур ЦД и контур объекта КИИ), интегрированный с трехуровневым адаптационным механизмом (оперативный, тактический, стратегический режимы). Метод включает этапы генерации синтетических данных, обучения/тестирования моделей в ЦД, детектирования/классификации на объекте КИИ, а также определяет критерии (триггеры) инициирования адаптации. Ключевые преимущества метода: возможность безопасной генерации сценариев угроз и обучения в виртуальной среде ЦД, автоматизированное поддержание актуальности моделей обнаружения признаков угроз ИБ. Результаты апробации на синтетической модели АСУ ТП энергосистемы демонстрируют улучшение метрик качества после адаптации.</p></trans-abstract><kwd-group xml:lang="en"><kwd>information security threat detection</kwd><kwd>critical information infrastructure</kwd><kwd>digital twin</kwd><kwd>adaptive anomaly detection</kwd><kwd>synthetic data</kwd><kwd>Isolation Forest</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>обнаружение угроз информационной безопасности</kwd><kwd>критическая информационная инфраструктура</kwd><kwd>цифровой двойник</kwd><kwd>адаптивное обнаружение аномалий</kwd><kwd>синтетические данные</kwd><kwd>лес изоляции</kwd></kwd-group><funding-group/></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><citation-alternatives><mixed-citation xml:lang="en">Bozdal M. Security through digital twin-based intrusion detection: A SWaT dataset analysis. In: 16th International Conference on Information Security and Cryptology (ISCTürkiye). 2023. Pp. 1–6. DOI: 10.1109/ISCTrkiye61151.2023.10336137.</mixed-citation><mixed-citation xml:lang="ru">Bozdal M. Security through digital twin-based intrusion detection: A SWaT dataset analysis // 16th International Conference on Information Security and Cryptology (ISCTürkiye). 2023. Pp. 1–6. DOI: 10.1109/ISCTrkiye61151.2023.10336137.</mixed-citation></citation-alternatives></ref><ref id="B2"><label>2.</label><citation-alternatives><mixed-citation xml:lang="en">De Hoz Diego J., Temperekidis A., Katsaros P., Konstantinou C. An IoT digital twin for cyber-security defence based on runtime verification. LNCS. 2022. Pp. 556–574. DOI: 10.1007/978-3-031-19849-6_31.</mixed-citation><mixed-citation xml:lang="ru">De Hoz Diego J., Temperekidis A., Katsaros P., Konstantinou C. An IoT digital twin for cyber-security defence based on runtime verification // LNCS. 2022. Pp. 556–574. DOI: 10.1007/978-3-031-19849-6_31.</mixed-citation></citation-alternatives></ref><ref id="B3"><label>3.</label><citation-alternatives><mixed-citation xml:lang="en">Krishnaveni S., Chen T., Sathiyanarayanan M., Amutha B. CyberDefender: An integrated intelligent defense framework for digital-twin-based industrial cyber-physical systems. Cluster Computing. 2024. Vol. 27. Pp. 7273–7306. DOI: 10.1007/s10586-024-04320-x.</mixed-citation><mixed-citation xml:lang="ru">Krishnaveni S., Chen T., Sathiyanarayanan M., Amutha B. CyberDefender: An integrated intelligent defense framework for digital-twin-based industrial cyber-physical systems // Cluster Computing. 2024. Vol. 27. Pp. 7273–7306. DOI: 10.1007/s10586-024-04320-x.</mixed-citation></citation-alternatives></ref><ref id="B4"><label>4.</label><citation-alternatives><mixed-citation xml:lang="en">Lv H.B., Chen D.L., Cao B. et al. Secure deep learning in defense in deep-learning-as-a-service computing systems in digital twins. IEEE Transactions on Computers. 2024. Vol. 73. No. 3. Pp. 656–668. DOI: 10.1109/TC.2021.3077687.</mixed-citation><mixed-citation xml:lang="ru">Lv H.B., Chen D.L., Cao B. et al. Secure deep learning in defense in deep-learning-as-a-service computing systems in digital twins // IEEE Transactions on Computers. 2024. Vol. 73. No. 3. Pp. 656–668. DOI: 10.1109/TC.2021.3077687.</mixed-citation></citation-alternatives></ref><ref id="B5"><label>5.</label><citation-alternatives><mixed-citation xml:lang="en">Ma J., Guo Y., Fang Ch., Zhang Qi. Digital-twin-based cps anomaly diagnosis and security defense countermeasure recommendation. IEEE Internet of Things Journal. 2024. Vol. 11. Pp. 18726–18738. DOI: 10.1109/JIOT.2024.3366904.</mixed-citation><mixed-citation xml:lang="ru">Ma J., Guo Y., Fang Ch., Zhang Qi. Digital-twin-based cps anomaly diagnosis and security defense countermeasure recommendation // IEEE Internet of Things Journal. 2024. Vol. 11. Pp. 18726–18738. DOI: 10.1109/JIOT.2024.3366904.</mixed-citation></citation-alternatives></ref><ref id="B6"><label>6.</label><citation-alternatives><mixed-citation xml:lang="en">Masi M., Sellitto G., Aranha H., Pavleska T. Securing critical infrastructures with a cybersecurity digital twin. Software and Systems Modeling. 2023. Vol. 22. Pp. 689–707. DOI: 10.1007/s10270-022-01075-0.</mixed-citation><mixed-citation xml:lang="ru">Masi M., Sellitto G., Aranha H., Pavleska T. Securing critical infrastructures with a cybersecurity digital twin // Software and Systems Modeling. 2023. Vol. 22. Pp. 689–707. DOI: 10.1007/s10270-022-01075-0.</mixed-citation></citation-alternatives></ref><ref id="B7"><label>7.</label><citation-alternatives><mixed-citation xml:lang="en">Patel T., Jadav N., Rathod T. et al. AI-based secure intrusion detection framework for digital twin-enabled critical infrastructure. In: 14th International Conference on Information and Knowledge Technology (IKT). 2023. Pp. 24–29. DOI: 10.1109/IKT62039.2023.10433057.</mixed-citation><mixed-citation xml:lang="ru">Patel T., Jadav N., Rathod T. et al. AI-based secure intrusion detection framework for digital twin-enabled critical infrastructure // 14th International Conference on Information and Knowledge Technology (IKT). 2023. Pp. 24–29. DOI: 10.1109/IKT62039.2023.10433057.</mixed-citation></citation-alternatives></ref><ref id="B8"><label>8.</label><citation-alternatives><mixed-citation xml:lang="en">Salim M., Camacho D., Park J. Digital Twin and federated learning enabled cyberthreat detection system for IoT networks. Future Generation Computer Systems. 2024. Vol. 161. Pp. 701–713. DOI: 10.1016/j.future.2024.07.017.</mixed-citation><mixed-citation xml:lang="ru">Salim M., Camacho D., Park J. Digital Twin and federated learning enabled cyberthreat detection system for IoT networks // Future Generation Computer Systems. 2024. Vol. 161. Pp. 701–713. DOI: 10.1016/j.future.2024.07.017.</mixed-citation></citation-alternatives></ref><ref id="B9"><label>9.</label><citation-alternatives><mixed-citation xml:lang="en">Sousa B., Arieiro M., Pereira V. et al. ELEGANT: Security of critical infrastructures with digital twins. IEEE Access. 2021. Vol. 9. Pp. 107574–107588. DOI: 10.1109/ACCESS.2021.3100708.</mixed-citation><mixed-citation xml:lang="ru">Sousa B., Arieiro M., Pereira V. et al. ELEGANT: Security of critical infrastructures with digital twins // IEEE Access. 2021. Vol. 9. Pp. 107574–107588. DOI: 10.1109/ACCESS.2021.3100708.</mixed-citation></citation-alternatives></ref><ref id="B10"><label>10.</label><citation-alternatives><mixed-citation xml:lang="en">Bayanova Yu.A. Critical information infrastructure as an object of security. Innovatsionnaya nauka. 2021. No. 10-2. Pp. 63–65. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Баянова Ю.А. Критическая информационная инфраструктура как объект обеспечения безопасности // Инновационная наука. 2021. № 10-2. С. 63–65.</mixed-citation></citation-alternatives></ref><ref id="B11"><label>11.</label><citation-alternatives><mixed-citation xml:lang="en">Kochergin S.V., Artemova S.V., Bakaev A.A. et al. Anomaly detection in power systems: Application of the Isolation Forest model for identifying cyber threats. Information Technology Security. 2025. Vol. 32. No. 1. Pp. 112–121. (In Rus.). DOI: 10.26583/bit.2025.1.07.</mixed-citation><mixed-citation xml:lang="ru">Кочергин С.В., Артемова С.В., Бакаев А.А. и др. Обнаружение аномалий в энергосистемах: применение модели Isolation Forest для выявления киберугроз // Безопасность информационных технологий. 2025. Т. 32. № 1. С. 112–121. DOI: 10.26583/bit.2025.1.07.</mixed-citation></citation-alternatives></ref><ref id="B12"><label>12.</label><citation-alternatives><mixed-citation xml:lang="en">Kochergin S.V., Artemova S.V., Bakaev A.A. et al. Enhancing smart grid security: Spectral and fractal analysis as tools for cyberattack detection. Russian Technological Journal. 2025. Vol. 13. No. 1. Pp. 7–15. (In Rus.). DOI: 10.32362/2500-316X-2025-13-1-7-15.</mixed-citation><mixed-citation xml:lang="ru">Кочергин С.В., Артемова С.В., Бакаев А.А. и др. Повышение безопасности смарт-сетей: спектральный и фрактальный анализ как инструменты выявления кибератак // Russian Technological Journal. 2025. Т. 13. № 1. С. 7–15. DOI: 10.32362/2500-316X-2025-13-1-7-15.</mixed-citation></citation-alternatives></ref><ref id="B13"><label>13.</label><citation-alternatives><mixed-citation xml:lang="en">Mityakov E.S. Problems of using digital twins in information security of critical information infrastructure facilities. Information Technologies and Telecommunications. 2023. Vol. 11. No. 4. Pp. 36–47. (In Rus.). DOI: 10.31854/2307-1303-2023-11-4-36-47.</mixed-citation><mixed-citation xml:lang="ru">Митяков Е.С. Проблемы использования цифровых двойников в задачах обеспечения информационной безопасности объектов критической информационной инфраструктуры // Информационные технологии и телекоммуникации. 2023. Т. 11. № 4. С. 36–47. DOI: 10.31854/2307-1303-2023-11-4-36-47.</mixed-citation></citation-alternatives></ref><ref id="B14"><label>14.</label><citation-alternatives><mixed-citation xml:lang="en">Mityakov E.S. Digital twins and critical information infrastructure security: Legal and technological aspects. National Security and Strategic Planning. 2024. No. 4 (48). Pp. 29–34. (In Rus.). DOI: 10.37468/2307-1400-2024-4-29-34.</mixed-citation><mixed-citation xml:lang="ru">Митяков Е.С. Цифровые двойники и безопасность критической информационной инфраструктуры: правовые и технологические аспекты // Национальная безопасность и стратегическое планирование. 2024. № 4 (48). С. 29–34. DOI: 10.37468/2307-1400-2024-4-29-34.</mixed-citation></citation-alternatives></ref><ref id="B15"><label>15.</label><citation-alternatives><mixed-citation xml:lang="en">Saukh I.A. Objects of critical information infrastructure under information attacks. Innovations. Science. Education. 2022. No. 49. Pp. 1302–1306. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Саух И.А. Объекты критической информационной инфраструктуры в условиях возникновения информационных атак // Инновации. Наука. Образование. 2022. № 49. С. 1302–1306.</mixed-citation></citation-alternatives></ref></ref-list></back></article>
