Modern applications and services are increasingly built on a large, pervasive, and heterogeneous computing continuum, where software, networks, devices, infrastructure, and data from different providers are combined in technology and business-value chains. Ensuring end-to-end confidentiality, integrity, and availability is extremely challenging today because it goes beyond protecting individual networks, software, and hardware from unauthorised access, attacks, or damage. Multi-layered frameworks are required that combine encryption, firewalls, multi-factor authentication (MFA), and endpoint protection in a seamless and homogeneous way across technological and business domains. Moreover, a transition from the prevailing reactive approach to a proactive posture is necessary to anticipate threats before they materialise and cause irreparable damage (e.g. data leaks, ransomware, loss of reputation, and large-scale failures of critical infrastructure).
Tight and complex dependencies in digital service chains require new simulation models, such as digital twins (DTs), which could be used to monitor infrastructures and services, investigate anomalies, detect the new breed of artificial intelligence (AI)-powered threats, and enforce security controls in a homogeneous way across the heterogeneous computing continuum. AI, in its various forms, is an indispensable tool for detecting, responding to, and orchestrating cybersecurity processes, effectively addressing complexity beyond human capacity. However, it also introduces many vulnerabilities, especially for non-explainable models.
This special issue encompasses theoretical work and practical approaches that advance research in all aspects of securing interconnected digital information technology (IT) systems and infrastructures. The contributions range from advanced technologies, applications, and innovative solutions for modelling, simulation, and predicting cyber threats in complex systems to modern cryptographic methods as well as the development of methods, conceptual and theoretical models, and simulations related to the secure operation of digital chains and services in large, heterogeneous, and multi-ownership systems.
Contents
This volume, comprising eight articles, presents the latest research on complex, intelligent conceptual, and theoretical models and simulations for the secure operation of digital supply chains and services as well as methodologies for securing interconnected digital services within IT systems and infrastructures. This publication also presents innovative solutions for modelling, simulating, and forecasting cyber threats and attacks in complex IT systems as well as modern post-quantum cryptography methods.
In the first article, Repetto and Canavese [1] discuss the concept of secure DTs and their potential application in securing large, interconnected systems owned by multiple parties. The authors first focus on a digital twin model that can detect real-time threats, identify lateral movement, and mitigate attacks using digital assets. Next, the authors discuss hybrid DTs, which incorporate physical devices into the model and can detect threats in critical infrastructures. Both models are characterised by their use in Smart City and Smart Grid projects.
Multidimensional digital twin models are implemented on complex platforms that use container technologies, such as Kubernetes, which has become an essential tool for digital service platforms, and where authorisation is a key security mechanism. Pizzato et al. [2] compare authorisation mechanisms in Kubernetes, based on operational requirements typical of shared clusters. The results of this analysis reveal the limitations of the existing authorisation methods and point to directions for further research in this area.
The modern critical infrastructure systems usually contain complex AI mechanisms embedded to support decision-making. Sood and Zeadally [3] defined a multi-level taxonomy of complex AI systems that accounts for cross-layer interactions and emerging security vulnerabilities. This taxonomy can serve as a basis for a new approach to threat modelling and the identification of architectural weaknesses. Risk mitigation strategies and architectural best practices aimed at building secure and trustworthy AI systems are also presented.
The next two articles focus on the vulnerabilities of AI-based IT systems and adversarial attacks. Kowalczyk et al. [4] survey adversarial attack models, defence methods against them, and the assessment of the resilience of complex AI-based systems. A taxonomy of defence methods was defined, encompassing both proactive and reactive approaches. The essential conclusion from the analysis is the need to build multi-layered defence mechanisms and to assess realistically their effectiveness and the threats they face in complex AI systems. Multimodal malware detection in mobile systems (Android) is discussed by Sackitey et al. [5]. They propose a malware-detection method that leverages image-based and tabular representations of Android applications based on visual and tabular representations of Android Package Kit (APK) files for the Android system. In the experiments, a ResNet-50 network was used to extract visual representations from ‘byte plot’ images. The tabular data was analysed using an autoencoder pre-trained on a multi-layer perceptron (MLP) network to model behavioural correlations.
Sherif [6] analyses IT system vulnerabilities using the MITRE ATT&CK framework. The author proposes a Bayesian co-occurrence model that estimates the conditional probability of common weakness enumeration (CWE) classes, given a specific ATT&CK technique, integrating three publicly available datasets. Experimental analysis shows that probabilistic models are highly effective at generating interpretable, practically useful priorities for corrective actions related to CWEs.
Syed [7] describes an AI-based platform for real-time identity risk assessment and adaptive access control. Anomaly detection using autoencoders is combined here with Bayesian risk assessment methods. The platform also features a built-in Q-learning reinforcement learning agent, which enables real-time adjustment of system access policies. This solution has been enhanced further with graph–theory-based centrality analysis, designed to increase the a priori risk for accounts holding structural permissions within the enterprise’s permission network, ensuring that identities with a high degree of exposure are subjected to proportionally greater control. A comprehensive experimental analysis confirms the high performance of AI-based Identity and Access Management (IAM) pipelines, compared to rule-based models under controlled test conditions.
Finally, Dybel and Kołodziej [8] survey post-quantum cryptography (PQC) methods. The authors employed a systematic methodology to evaluate the empirical trade-offs in performance of newly standardised PQC algorithms and to conduct a comparative analysis of data load, computational delay, and resource efficiency. A new, implementation-oriented taxonomy was defined that maps PQC standards to practical use cases, accounting for constraints in Internet of Things (IoT), cloud, and blockchain environments.
The list of authors includes the partners from the HE MIRANDA project, the external collaborators, and invited experts and scientists in the domain. We strongly believe that this issue will be of interest to a broad group of researchers, engineers, and professionals working in computer science and IT business units that use intelligent modelling to support their interdisciplinary projects and applications in distributed complex digital systems and data-intensive computing domains. We believe they would find a valuable survey of emerging technologies for realistic potential infrastructures and use cases.