الأمن السيبراني المدعوم بالمحاكاة: تقييم المخاطر في الوقت الحقيقي عبر التوأم الأمني غير المتطفل
Simulation-powered cybersecurity: real-time risk assessment via non-intrusive security twin

شارك:
المجلة: The Journal of Supercomputing، المجلد: 82، العدد: 5
DOI: https://doi.org/10.1007/s11227-026-08454-0
تاريخ النشر: 2026-04-01
المؤلف: F. Baiardi وآخرون
الموضوع الرئيسي: الشبكات المعرفة بالبرمجيات و5G

نظرة عامة

تقدم الورقة NotLine، وهي منصة جديدة مصممة لتعزيز الأمن السيبراني من خلال تطوير توأم أمني – نموذج ديناميكي قائم على الرسوم البيانية يعكس البنى التحتية المعقدة لتكنولوجيا المعلومات والاتصالات. يتم تعزيز هذا النموذج بمعلومات حول الثغرات ويتيح التنبؤ بالاختراقات من قبل الجهات الفاعلة المهددة دون تعطيل بيئات الإنتاج الحية. تتناول NotLine تحدي التزامن عالي الدقة بين البنية التحتية والتوأم الأمني من خلال استخدام استيعاب بيانات الشبكة السلبية الآلية غير المتطفلة. تستخدم المنصة بنية مراقبة موزعة لمعالجة وارتباط بيانات حركة المرور المتنوعة في الوقت الحقيقي، مما يربط هذه البيانات بالتوأم الأمني. الابتكار الرئيسي هو دمج محرك محاكاة مونت كارلو المدفوع بالذكاء الاصطناعي، الذي يقيم بشكل احتمالي تعرض المخاطر من خلال محاكاة سلوك الجهات الفاعلة المهددة بناءً على حقوق الوصول والمعلومات المكتسبة.

تؤكد النتائج على تحول في نموذج الأمن السيبراني من التقييمات الثابتة إلى المحاكاة الديناميكية المستمرة. تساهم NotLine في ثلاثة مجالات: توفر إطارًا منهجيًا لبناء نماذج عالية الدقة دون مسح نشط، وتقدم نموذجًا هايبوإكسبونينشيال موثقًا للتقارب في الاكتشاف السلبي، وتدمج محرك محاكاة مونت كارلو القابل للتوسع الذي يمكنه استكشاف العديد من مسارات الهجوم بسرعة. أظهرت التحقق التجريبي في بيئة الإنتاج فعالية NotLine في تحقيق جرد أصول شبه كامل وتوليد معلومات تهديد قابلة للتنفيذ، مع تأكيد التحقق التجريبي أن مسارات الهجوم المحاكية تتوافق مع الثغرات الحقيقية. هذا يضع NotLine كحل قوي لجسر المراقبة التشغيلية وتحليل المخاطر التنبؤية، مما يمكّن فرق الأمن من تحديد أولويات جهود الإصلاح بناءً على المخاطر الفعلية بدلاً من التقييمات النظرية.

مقدمة

تتناول مقدمة الورقة عدم كفاية نماذج الأمن السيبراني التقليدية في مواجهة النمو الأسي وتعقيد البنى التحتية الحديثة لتكنولوجيا المعلومات والاتصالات/التكنولوجيا التشغيلية. مع تطور هذه البنى التحتية إلى أنظمة بيئية مترابطة، يصبح الحفاظ على فهم في الوقت الحقيقي لوضعها الأمني أمرًا متزايد الصعوبة. لمواجهة هذه المشكلة، يقترح المؤلفون مفهوم التوأم الأمني (ST)، وهو شكل متخصص من التوأم الرقمي (DT) يركز على تقييم المرونة السيبرانية بدلاً من مجرد تحسين العمليات. تم تصميم ST لنمذجة سطح الهجوم والاختراقات، مما يمكّن من تقييم وإدارة المخاطر السيبرانية بشكل استباقي من خلال محاكاة سلوك الجهات الفاعلة المهددة دون التأثير على البنية التحتية الفعلية.

يسلط المؤلفون الضوء على قيود المنهجيات الحالية التي تعتمد على تقنيات المسح النشط المتطفلة، والتي يمكن أن تزعزع استقرار البيئات الحساسة وتخلق “فجوات في الرؤية”. للتغلب على هذه التحديات، يقدمون منهجية جديدة تستخدم المراقبة السلبية للشبكة، ونظرية الرسوم البيانية، والمحاكاة العشوائية لبناء وصيانة ST قوي باستخدام تدفقات بيانات مستمرة من بروتوكولات الشبكة القياسية. يقوم النظام المقترح، NotLine، بأتمتة إنشاء وتحديث ST، مما يدمج بيانات المراقبة المجزأة في رسم بياني شامل للمعرفة معزز بمعلومات الثغرات في الوقت الحقيقي. يسمح هذا الإطار بإجراء محاكاة مونت كارلو لسلوك الخصوم، مما يسهل تقييم المخاطر والتحقق من استراتيجيات التخفيف في بيئة افتراضية خالية من المخاطر. توضح الورقة ثلاث مساهمات رئيسية: بنية قابلة للتوسع للاكتشاف السلبي، نموذج رسمي لديناميات الاكتشاف، ومنهجية تقييم المخاطر القائمة على المحاكاة، مما يمهد الطريق لتعزيز المرونة السيبرانية في الأنظمة الرقمية المعقدة.

الطرق

في هذا القسم، يصف المؤلفون التحقق التجريبي من إطار عمل NotLine، مع التركيز على حملة محددة تهدف إلى معالجة ثلاثة أسئلة بحث رئيسية تتعلق بالأنظمة القائمة على المحاكاة. السؤال الأول (RQ1) يستقصي ما إذا كانت عملية الاكتشاف السلبي تتماشى مع النموذج الهايبوإكسبونينشيال الموضح في القسم 7. السؤال الثاني (RQ2) يقيم دقة أداة المحاكاة (ST) من حيث تغطية العقد ورسم خرائط الثغرات، مقارنةً بهذه النتائج مع حقيقة مادية تم تأسيسها من خلال المسح النشط. السؤال الثالث (RQ3) يقيم قابلية التوسع الحاسوبية لمحرك المحاكاة لتقييم المخاطر في الوقت الحقيقي.

تضمنت الإعدادات التجريبية جمع البيانات من بنية تحتية قسم جامعي، والتي شملت مجموعة متنوعة من الأصول مثل الخوادم ومحطات العمل وأجهزة إنترنت الأشياء. جمعت NotLine بيانات حركة المرور من منفذ عاكس أساسي (SPAN) يراقب واجهة فعلية واحدة (eno1) على مدار 42 يومًا. لضمان وجود حقيقة قوية لـ RQ2، قام المؤلفون بإجراء مسح نشط شامل باستخدام أدوات مثل Nmap وOpenVAS في نهاية فترة المراقبة.

النتائج

في نتائج التحقق، قامت الدراسة بتقييم أعلى 20 مسار هجوم من حيث الاحتمالية التي حددها محرك المحاكاة، وبالتحديد تلك التي لديها احتمال أكبر من 0.8. كشفت النتائج أن كلا المسارين تم تنفيذهما بنجاح في بيئة حية، مما أدى إلى معدل تحقق بنسبة 100% للتنبؤات عالية المخاطر.

بالإضافة إلى ذلك، أظهرت المحاكاة وعيًا بالسياق من خلال التنبؤ بدقة بأن جهاز إنترنت الأشياء يمكن أن يتحول إلى الخادم. تم عزو هذه القدرة إلى استخدام أوزان الحواف \( W(e_{ij}) \) المشتقة من تدفقات mDNS الملاحظة، مما يتناقض مع نموذج ثابت نظري كان سيفترض خطأً وجود تقسيم للشبكة.

المناقشة

تسلط قسم المناقشة في ورقة البحث الضوء على الأهمية الحاسمة لبناء توأم أمني (ST) بدقة لتقييمات الأمن السيبراني الفعالة. ويؤكد أن صحة تحليلات المخاطر تعتمد على دقة ST وكماله، والتي تتأثر بتكرار جمع المعلومات من البنية التحتية المستهدفة. تحدد الورقة تحديات كبيرة في المنهجيات الحالية لجمع المعلومات، لا سيما التكاليف التشغيلية المرتبطة بالمسح النشط وقيود الرؤية للمراقبة السلبية. يمكن أن disrupt المسح النشط أداء الشبكة وغالبًا ما يقتصر على نوافذ الصيانة غير المتكررة، مما يؤدي إلى “فترات عمياء”. على العكس من ذلك، قد تفوت المراقبة السلبية الاتصالات غير المتكررة من الأصول “الهادئة” وتكافح لإعادة بناء الطوبولوجيات الشبكية بدقة بسبب تعقيد ربط المعرفات المتباينة.

لمعالجة هذه التحديات، يقترح المؤلفون إطار عمل NotLine، الذي يستخدم خط أنابيب بناء مستمر وسلبي لـ ST. يسمح هذا النهج المبتكر بالتحديثات في الوقت الحقيقي لـ ST، مما يقلل من فجوة الواقع ويمكّن من تمثيل ديناميكي للبنية التحتية. تدعم بنية NotLine قابلية التوسع والمرونة، لا سيما في البيئات ذات حركة المرور المشفرة، من خلال التركيز على التدفق والبيانات الوصفية بدلاً من محتوى الحمولة. يدمج الإطار محرك محاكاة مونت كارلو الذي لا يحدد الثغرات فحسب، بل يتنبأ أيضًا بمسارات الاستغلال المحتملة، مما ينتقل من نموذج أمني وصفي إلى نموذج وصفي. تعزز هذه القدرة على المحاكاة المستمرة من قابلية التكيف للتدابير الأمنية السيبرانية، مما يسمح للمنظمات بالاستجابة بشكل استباقي للتهديدات المتطورة.

القيود

تسلط قسم القيود الضوء على التحديات المرتبطة بالمنهجيات الحالية لبناء التوائم الرقمية، لا سيما في سياق تكنولوجيا المعلومات والاتصالات (ICT) والبنى التحتية للتكنولوجيا التشغيلية (OT). يتم تصنيف الأساليب السائدة لاكتشاف الأصول والموارد إلى استراتيجيات نشطة وسلبية. تقدم كل من هذه المنهجيات صعوبات فريدة يمكن أن تعيق تطوير توائم رقمية عالية الدقة، والتي تعتبر ضرورية للتمثيل الدقيق والمحاكاة للأنظمة الواقعية.

غالبًا ما تتطلب طرق الاكتشاف النشط موارد كبيرة ويمكن أن تعطل العمليات الجارية، بينما قد تفتقر الطرق السلبية إلى الدقة اللازمة للنمذجة التفصيلية. تؤكد هذه القيود على الحاجة إلى تحسين نماذج الاكتشاف التي يمكن أن توازن بشكل فعال بين متطلبات الدقة واستمرارية العمليات في إنشاء التوائم الرقمية.

Journal: The Journal of Supercomputing, Volume: 82, Issue: 5
DOI: https://doi.org/10.1007/s11227-026-08454-0
Publication Date: 2026-04-01
Author(s): F. Baiardi et al.
Primary Topic: Software-Defined Networks and 5G

Overview

The paper introduces NotLine, a novel platform designed to enhance cybersecurity through the development of a security twin—a dynamic, graph-based model that mirrors complex ICT infrastructures. This model is enriched with vulnerability intelligence and enables the prediction of intrusions by threat actors without disrupting live production environments. NotLine addresses the challenge of high-fidelity synchronization between the infrastructure and the security twin by employing non-intrusive, automated passive network telemetry ingestion. The platform utilizes a distributed monitoring architecture to process and correlate heterogeneous traffic metadata in real time, mapping this data to the security twin. A key innovation is the integration of an AI-driven Monte Carlo simulation engine, which probabilistically quantifies risk exposure by simulating threat actor behavior based on their access rights and acquired information.

The findings emphasize a paradigm shift in cybersecurity from static assessments to dynamic, continuous simulation. NotLine’s contributions are threefold: it provides a methodological framework for building high-fidelity models without active scanning, introduces a validated hypoexponential model for passive discovery convergence, and incorporates a scalable Monte Carlo simulation engine capable of exploring numerous attack paths rapidly. Experimental validation in a production environment demonstrated NotLine’s effectiveness in achieving near-complete asset inventory and generating actionable threat intelligence, with empirical validation confirming that the simulated attack paths correspond to real vulnerabilities. This positions NotLine as a robust solution for bridging operational monitoring and predictive risk analysis, enabling security teams to prioritize remediation efforts based on actual risk rather than theoretical assessments.

Introduction

The introduction of the paper addresses the inadequacies of traditional cybersecurity paradigms in the face of the exponential growth and complexity of modern ICT/OT infrastructures. As these infrastructures evolve into interconnected ecosystems, maintaining a real-time understanding of their security posture becomes increasingly challenging. To tackle this issue, the authors propose the concept of a security twin (ST), a specialized form of a digital twin (DT) that focuses on assessing cyber-resilience rather than merely operational optimization. The ST is designed to model the attack surface and intrusions, enabling proactive cyber risk assessment and management through simulations of threat actor behavior without impacting the actual infrastructure.

The authors highlight the limitations of current methodologies that rely on intrusive active scanning techniques, which can destabilize sensitive environments and create “observability gaps.” To overcome these challenges, they introduce a novel methodology that employs passive network monitoring, graph theory, and stochastic simulation to construct and maintain a robust ST using continuous metadata streams from standard network protocols. The proposed system, NotLine, automates the generation and updating of the ST, synthesizing fragmented telemetry into a comprehensive knowledge graph enriched with real-time vulnerability intelligence. This framework allows for Monte Carlo simulations of adversarial behavior, facilitating risk quantification and validation of mitigation strategies in a risk-free virtual environment. The paper outlines three key contributions: a scalable architecture for passive discovery, a formal model for discovery dynamics, and a simulation-based risk assessment methodology, setting the stage for enhanced cyber resilience in complex digital ecosystems.

Methods

In this section, the authors describe the experimental validation of the NotLine framework, focusing on a specific campaign aimed at addressing three key research questions related to simulation-based systems. The first question (RQ1) investigates whether the passive discovery process adheres to the hypoexponential model outlined in Section 7. The second question (RQ2) assesses the fidelity of the simulation tool (ST) in terms of node coverage and vulnerability mapping, comparing these results to a physical ground truth established through active scanning. The third question (RQ3) evaluates the computational scalability of the simulation engine for real-time risk assessment.

The experimental setup involved data collection from a university departmental infrastructure, which included a diverse array of assets such as servers, workstations, and IoT devices. NotLine collected traffic data from a core mirroring port (SPAN) monitoring a single physical interface (eno1) over a 42-day period. To ensure a robust ground truth for RQ2, the authors conducted an extensive active scan using tools like Nmap and OpenVAS at the conclusion of the observation period.

Results

In the validation results, the study assessed the top 20 highest-probability attack paths identified by the simulation engine, specifically those with a probability greater than 0.8. The findings revealed that both paths were successfully executed in a live environment, resulting in a 100% validation rate for the high-risk predictions.

Additionally, the simulation demonstrated context awareness by accurately predicting that the IoT device could pivot to the server. This capability was attributed to the use of edge weights \( W(e_{ij}) \) derived from observed mDNS flows, contrasting with a theoretical static model that would have erroneously assumed the presence of network segmentation.

Discussion

The discussion section of the research paper highlights the critical importance of accurately constructing a Security Twin (ST) for effective cybersecurity assessments. It emphasizes that the validity of risk analyses is contingent upon the ST’s accuracy and completeness, which are influenced by the frequency of information collection from the target infrastructure. The paper identifies significant challenges in current methodologies for information gathering, particularly the operational costs associated with active scanning and the visibility limitations of passive monitoring. Active scanning can disrupt network performance and is often limited to infrequent maintenance windows, leading to “blind intervals.” Conversely, passive monitoring may miss infrequent communication from “quiet” assets and struggles with accurately reconstructing network topologies due to the complexity of correlating disparate identifiers.

To address these challenges, the authors propose the NotLine framework, which employs a continuous, passive construction pipeline for the ST. This innovative approach allows for real-time updates of the ST, thereby minimizing the reality gap and enabling a dynamic representation of the infrastructure. NotLine’s architecture supports scalability and resilience, particularly in environments with encrypted traffic, by focusing on flow and metadata rather than payload content. The framework integrates a Monte Carlo simulation engine that not only identifies vulnerabilities but also predicts potential exploitation paths, thus transitioning from a descriptive to a prescriptive security model. This continuous simulation capability enhances the adaptability of cybersecurity measures, allowing organizations to respond proactively to evolving threats.

Limitations

The section on limitations highlights the challenges associated with current methodologies for constructing digital twins, particularly in the context of Information and Communication Technology (ICT) and Operational Technology (OT) infrastructures. The predominant approaches to asset and resource discovery are categorized into active and passive strategies. Each of these methodologies presents unique difficulties that can hinder the development of high-fidelity digital twins, which are essential for accurate representation and simulation of real-world systems.

Active discovery methods often require significant resources and can disrupt ongoing operations, while passive methods may lack the granularity needed for detailed modeling. These limitations underscore the need for improved discovery paradigms that can effectively balance the demands of accuracy and operational continuity in the creation of digital twins.

شارك: