Thesis of Jean-Baptiste Lepidi
Subject:
Start date: 12/09/2026
End date (estimated): 12/09/2029
Advisor: Lionel Brunie
Coadvisor: Nadia Bennani
Summary:
Against a backdrop of ever-increasing cyber threats [11], corporate information systems are exposed to increasingly frequent and sophisticated attacks. Both nationally and internationally, the geopolitical landscape—as well as the proliferation of Cybercrime-as-a-Service (CaaS)—has led to a drastic increase in cyberattacks in recent years, whether their objectives are financial gain, political destabilization, or espionage.
Today, Security Operations Centers (SOCs) have a wide range of solutions and tools at their disposal. These traditional defenses are almost exclusively reactive and therefore struggle to keep pace with the rapid evolution of threats. With this in mind, digital twins (or DTs) are beginning to gain traction in the field of information system (IS) security. A digital twin is a virtual replica of a real-world system that mirrors its behavior in real time. This virtual copy enables continuous monitoring of the system, analysis of its current state, and prediction of its future behavior. Digital twins have been used in many fields, such as urban applications, healthcare, and industry. Initiatives to create digital twins for information systems are still in the very early stages of development. A digital twin applied to an IS therefore involves creating a dynamic, accurate, and actionable replica of the infrastructure, workflows, applications, and internal interactions. Furthermore, if this twin also models the IS’s security system, it becomes a testing ground and a tool for strengthening the company’s cybersecurity posture.
The central objective of this thesis is to study the use of the digital twin paradigm to replicate a company’s information system infrastructure, with the aim of strengthening its cybersecurity posture. Such a digital twin will make it possible to (i) better detect security vulnerabilities in the real system (audit + monitoring), (ii) proactively test the IT system’s resilience against known attacks (https://attack.mitre.org/), and (iii) generate scenarios for as-yet-unknown attacks to better identify weaknesses in the IS security infrastructure. It will also be able to identify system vulnerabilities in the event of major changes, such as code or architecture migration, joining consortia, or IS integration.