Reconstructing adversarial behavior from industrial control system (ICS) telemetry is difficult because process observations reflect physical changes more directly than the actions that caused them. A new arXiv paper addresses this by proposing a digital twin-assisted approach to map ICS telemetry to the ATT&CK for ICS framework.
The method, as described in the abstract, uses evidence-driven dependency reasoning. Rather than relying on direct signatures, the system appears to model the process with a digital twin and then reason about which attack techniques could plausibly have produced the observed state changes.
Because the source is only an abstract, implementation details and evaluation results are not available. The main contribution is a structured way to connect low-level process measurements to high-level adversary techniques, which could aid analysts in incident reconstruction.