面向医院IT与OT环境网络攻防分析的仿真锚定数字孪生测试平台
An Emulation Anchored Digital Twin Testbed for Cyberattack and Defense Analysis in Hospital IT OT Environments
浏览论文内容
中文总结 AI 辅助
本研究构建了结合数字孪生的医院IT与OT网络安全测试平台,可仿真医疗相关网络环境,支持攻防实验与防御智能体训练,且计算开销低,为医院数字孪生扩展提供基础。
中文摘要 AI 辅助
现代医院日益依赖集成的信息技术(IT)与运营技术(OT)基础设施来支撑关键医疗服务,但这种融合扩大了网络攻击面,且难以在实际系统上安全验证防御机制。现有测试平台往往聚焦于孤立的IT或OT环境,无法捕捉现实中跨域的医疗交互。本研究提出了一种医院IT与OT网络安全测试平台,结合数字孪生用于监控、实验及防御措施验证。该平台仿真中央服务器、电子健康记录(EHR)系统、基于SCADA的基础设施,以及分段的IT、OT和DMZ网络,支持受控网络攻击执行、软件补丁评估和基于强化学习(RL)的防御智能体训练。该平台进一步扩展为数字孪生,通过日志和网络统计数据对环境实时状态建模,并通过命令执行和容器生命周期编排实现双向交互。Modbus/TCP和FHIR/HL7协议支持医疗与工业组件间的真实通信。实验评估显示计算开销较低,每个容器的平均归一化CPU利用率低于0.4%,多数轻量级服务运行时低于0.01%;OpenPLC Modbus TCP操作的中位数往返延迟为0.901毫秒。该测试平台还捕获了多阶段SSH攻击从DMZ网络向IT网络及PLC网络的传播过程,该框架为将仿真环境扩展为支持硬件的医院数字孪生奠定了基础。
英文摘要
Modern hospitals increasingly rely on integrated Information Technology (IT) and Operational Technology (OT) infrastructures to support critical healthcare services. However, this convergence expands the cybersecurity attack surface and makes safe validation of defensive mechanisms difficult on live systems. Existing testbeds often focus on isolated IT or OT environments and do not capture realistic cross-domain healthcare interactions. This work presents a hospital IT and OT cybersecurity testbed coupled with a digital twin for monitoring, experimentation, and validation of countermeasures. The testbed emulates a central server, Electronic Health Record (EHR) systems, SCADA-based infrastructure, and segmented IT, OT, and DMZ networks. It supports controlled cyberattack execution, software-patch evaluation, and training of RL-based defense agents. The testbed is further extended to a digital twin that models the real-time state of the environment using log and network statistics and enables bidirectional interaction through command execution and container lifecycle orchestration. Modbus/TCP and FHIR/HL7 support realistic communication across healthcare and industrial components. Experimental evaluation shows low computation overhead, with average normalized CPU utilization below 0.4 % per container and most lightweight services operating below 0.01%. OpenPLC Modbus TCP operations achieve a median round-trip latency of 0.901 ms. The testbed also captures a multi-stage SSH-based attack propagating from the DMZ to the IT and PLC networks. The framework provides a foundation for extending the emulated environment toward a hardware-enabled hospital digital twin.