Enabling End-to-End APT Emulation in Industrial Environments: Design and Implementation of the SIMPLE-ICS Testbed
Yogha Restu Pramadi, Theodoros Spyridopoulos, Vijay Kumar

TL;DR
The paper introduces SIMPLE-ICS, a comprehensive virtualized testbed that emulates multi-stage APT campaigns across industrial IT, OT, and IIoT environments, enabling realistic cybersecurity research and detection strategies.
Contribution
It presents the design, implementation, and validation of a novel industrial cybersecurity testbed supporting end-to-end APT emulation across diverse industrial networks.
Findings
Supports multi-stage APT campaign emulation
Enables synchronized data collection across domains
Validated for attack trace observability and repeatability
Abstract
Research on Advanced Persistent Threats (APTs) in industrial environments requires experimental platforms that support realistic end-to-end attack emulation across converged enterprise IT, operational technology (OT), and Industrial Internet of Things (IIoT) networks. However, existing industrial cybersecurity testbeds typically focus on isolated IT or OT domains or single-stage attacks, limiting their suitability for studying multi-stage APT campaigns. This paper presents the design, implementation, and validation of SIMPLE-ICS, a virtualised industrial enterprise testbed that enables emulation of multi-stage APT campaigns across IT, OT, and IIoT environments. The testbed architecture is based on the Purdue Enterprise Reference Architecture, NIST SP 800-82, and IEC 62443 zoning principles and integrates enterprise services, industrial control protocols, and digital twin based process…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Information and Cyber Security · Network Security and Intrusion Detection
