arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.02955cs.CR

数字孪生辅助的ICS遥测到ATT&CK for ICS映射:基于证据驱动的依赖推理

Digital Twin-Assisted Mapping of ICS Telemetry to ATT&CK for ICS with Evidence-Driven Dependency Reasoning

Konstantinos E. Kampourakis, Vyron Kampourakis, Vasileios Gkioulos, Sokratis Katsikas

首次发表
浏览论文内容

中文总结 AI 辅助

提出数字孪生辅助框架,通过LLM推理将ICS遥测映射到ATT&CK for ICS并构建依赖图;实验显示FP平均减少34.1%,但召回率无提升,优势未迁移至外部数据集,揭示潜力与局限。

中文摘要 AI 辅助

从工业控制系统(ICS)遥测数据中重建对抗行为是困难的,因为过程观测直接揭示的是物理变化,而非产生这些变化的行为。本文提出了一种数字孪生(DT)辅助框架,该框架提取同步状态变化,将其转换为保留证据的描述,通过检索增强的大语言模型(LLM)推理将其映射到ATT&CK for ICS,并构建类型化依赖图。评估包括在九个保留的SWaT场景(包含十个可遥测评估的真实地面实况事件)上的四配置消融实验、主要映射配置的三次独立生成,以及在BATADAL和WADI上的外部评估。在三次SWaT生成中,DT增强映射在每次运行中都产生更少的注释相对假阳性(FP)事件,每次运行平均减少34.1%。两种配置的平均召回率均为0.633,尽管召回率在0.50至0.70之间变化,且DT增强并非在每次运行中都能提高F1分数。这些观察是描述性的:主要运行的配对比较未达到统计显著性,且映射优势未迁移到任一外部数据集。一个探索性的仅正例依赖基准在DT上下文中恢复了九个已记录共现关系中的八个。另一个包含一个正例对和25个负例对照的端到端基准揭示了映射错误传播到不支持的边。研究结果既识别了DT上下文在语义安全解释中的潜力,也指出了其局限性,但未能建立可靠的自主动态归因、通用因果重建或实际分析人员效益。

英文摘要

Reconstructing adversarial behavior from Industrial Control System (ICS) telemetry is difficult because process observations reveal physical changes more directly than the actions that produced them. This paper presents a Digital Twin (DT)-assisted framework that extracts synchronized state changes, converts them into evidence-preserving descriptions, maps them to ATT&CK for ICS through retrieval-augmented Large Language Model (LLM) reasoning, and constructs a typed dependency graph. Evaluation comprises a four-configuration ablation on nine held-out SWaT scenarios containing ten telemetry-evaluable ground-truth episodes, three independent generations of the principal mapping configurations, and external evaluation on BATADAL and WADI. Across the three SWaT generations, DT-enriched mapping produces fewer annotation-relative False Positive (FP) episodes in every run, with a mean per-run reduction of 34.1%. Both configurations obtain a mean recall of 0.633, although recall varies between 0.50 and 0.70 and DT enrichment does not improve F1 in every run. These observations are descriptive: the primary-run paired comparisons do not reach statistical significance, and the mapping advantage does not transfer to either external dataset. An exploratory positive-only dependency benchmark recovers eight of nine documented Co-occurrence relationships with DT context. A separate end-to-end benchmark containing one positive pair and 25 negative controls exposes propagation of mapping errors into unsupported edges. The findings identify both the potential and limitations of DT context for semantic security interpretation, without establishing reliable autonomous attribution, general causal reconstruction, or practical analyst benefit.

发表机构

  • Norwegian University of Science and Technology(挪威科技大学)

机构由 AI 辅助整理,请以论文原文为准。

↑