Next Article in Journal
Evolving IoT Botnet Threats and Practical Honeypot Observation: A Summary Review and Experimental Study
Previous Article in Journal
The Evaluation of a Double-Spend Attack Probability for Ouroboros-like Proof-of-Stake Consensus
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems

1
Department of Information Security and Communication Technology, Norwegian University of Science and Technology, 2815 Gjøvik, Norway
2
Department of Applied Research ICT (DART), Norwegian Computing Center, 0373 Oslo, Norway
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(3), 81; https://doi.org/10.3390/jcp6030081
Submission received: 4 March 2026 / Revised: 13 April 2026 / Accepted: 28 April 2026 / Published: 1 May 2026
(This article belongs to the Section Security Engineering & Applications)

Abstract

Industrial Control Systems (ICSs), which are essential components of critical infrastructures, are inherently complex and vulnerable to cyberattacks. Advanced Persistent Threats (APTs) that target these systems are multi-stage, coordinated attacks that can lead not only to information loss but also to physical damage and loss of life. Traditional threat modeling approaches fall short in adapting to the dynamic nature of ICSs, necessitating new methodologies to predict and prevent such complex attacks. This work presents a digital twin-assisted dynamic threat modeling framework for ICS environments. The framework leverages a knowledge graph that integrates system data and cyber threat intelligence to predict potential attacks. In addition, the digital twin environment enables the validation of mitigation strategies before deployment in the physical system, while also supporting adaptive response and real-time mitigation. To predict the attacker’s next move, we propose a Relational Graph Convolutional Network (RGCN)-based model that utilizes enriched relational data such as tactics, campaigns, groups, techniques, and assets. The proposed RGCN model achieves a recall of 0.887, an F1-score of 0.893, and an AUC of 0.957 in predicting potential attack sequences. These results demonstrate that the model provides reliable and well-balanced predictive performance.
Keywords: digital twins; threat modeling; cyber–physical systems; cybersecurity; attack prediction; advanced persistent threat; ATT&CK framework; knowledge graphs digital twins; threat modeling; cyber–physical systems; cybersecurity; attack prediction; advanced persistent threat; ATT&CK framework; knowledge graphs

Share and Cite

MDPI and ACS Style

Erceylan, G.; Abraham, D.; Akbarzadeh, A.; Gkioulos, V.; Pirbhulal, S. A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems. J. Cybersecur. Priv. 2026, 6, 81. https://doi.org/10.3390/jcp6030081

AMA Style

Erceylan G, Abraham D, Akbarzadeh A, Gkioulos V, Pirbhulal S. A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems. Journal of Cybersecurity and Privacy. 2026; 6(3):81. https://doi.org/10.3390/jcp6030081

Chicago/Turabian Style

Erceylan, Gizem, Doney Abraham, Aida Akbarzadeh, Vasileios Gkioulos, and Sandeep Pirbhulal. 2026. "A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems" Journal of Cybersecurity and Privacy 6, no. 3: 81. https://doi.org/10.3390/jcp6030081

APA Style

Erceylan, G., Abraham, D., Akbarzadeh, A., Gkioulos, V., & Pirbhulal, S. (2026). A Digital Twin-Assisted Threat Modeling Framework for Predicting APT Attack Flows in Industrial Control Systems. Journal of Cybersecurity and Privacy, 6(3), 81. https://doi.org/10.3390/jcp6030081

Article Metrics

Back to TopTop