FORMALIZATION OF A METHODOLOGY FOR ANALYZING INFORMATION SECURITY THREATS OF CRITICAL INFORMATION INFRASTRUCTURE FACILITIES USING DIGITAL TWINS BASED ON FINITE STATE MACHINE ALGEBRA
The paper presents a formalization of a methodology for analyzing information security threats to critical information infrastructure (CII) objects based on the application of digital twins. A digital twin automata model is proposed, built on the algebra of finite state machines (DTA), which allows describing the behavior of physical and virtual assets and their composition into a single cyber-physical system. The operations of direct product, superposition, and system composition are defined to model component interactions and attack propagation processes. The relationship between the formal automata model and the stages of the threat analysis methodology is established: from system formalization and digital twin construction to attack simulation, threat detection, prioritization, protection adaptation, and model verification. A logical architecture of the digital twin is developed, including data, analytics, visualization, and integration modules that enable the implementation of the proposed formalization. Examples of model specification for CII objects of various significance categories are given. The proposed formalization provides a theoretical foundation for building adaptive security systems operating in a dynamically changing cyber threat landscape.