Full text
Melisetal. EURASIP Journal on Information Security (2025) 2025:26 https://doi.org/10.1186/s13635-025-00213-7 RESEARCH Open Access © The Author(s) 2025. Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/. EURASIP Journal on Information Security Time-Sensitive Networking Digital Twin forSTRIDE-based security testing Andrea Melis1*, Andrea Giovine1 and Lorenzo Rinieri1 Abstract Time-sensitive networking is set to play a pivotal role in the evolution of modern industrial and 5G networks, enabling them to meet the strictest communication requirements for guaranteed low latency and high reliability. Given the critical and complex environments in which TSN will be deployed, such as industrial automation, autonomous systems, and mission-critical applications, ensuring robust protection against security threats becomes an essential design consideration. The inherent low-latency and deterministic characteristics of TSN, while beneficial for performance, also introduce unique vulnerabilities that attackers could exploit. Consequently, safeguarding time-sensitive networks is fundamental to their successful implementation and reliability in real-world applications. In this paper, we present a flexible and reconfigurable Digital Twin for TSN protocol validation and security testing. Its deployment in different and heterogeneous testing scenarios is fully automated via the Infrastructure as Code approach. Our proposed TSN Digital Twin employs advanced virtualization technologies and network emulation tools to replicate the stringent requirements of TSN. It also implements advanced Linux queuing disciplines to emulate TSN scheduling and traffic shaping. Finally, we assess the potential for adaptability of the proposed architecture for TSN security testing by simulating two attack scenarios derived from the TSN STRIDE threat model. Keywords TSN, STRIDE, Cybersecurity, Digital Twin 1 Introduction The manufacturing industry increasingly depends on advanced networking technologies to enhance machinery and streamline processes. This shift underpins the foundation of Industry 4.0—the fourth industrial revolution—characterized by the convergence of Operational Technology (OT) and Information Technology (IT) systems. While this integration drives innovation and efficiency, it simultaneously introduces significant cybersecurity risks[1]. Connecting OT networks to IT systems and the broader Internet exposes manufacturing environments to numerous cyber threats, a concern highlighted by different high-profile incidents in recent years[2, 3]. Amid these challenges, industrial networks demand low-latency, real-time communications to ensure the seamless operation of critical processes[4]. Time-Sensitive Networking (TSN) has emerged as a vital technology for addressing these requirements, enabling precise and deterministic communication across networks[5]. As TSN protocols enhance standard Ethernet with timesensitive capabilities, they inherit not only the traditional Ethernet vulnerabilities but also introduce new attack vectors based on time synchronization and determinism[6]. In industrial environments, where synchronized operations are crucial, attacks on synchronization protocols can cause process errors, machinery damage, or production halts[7]. Furthermore, legacy equipment integrated with TSN creates security gaps, increasing the risk of unauthorized access and data breaches. *Correspondence: Andrea Melis [email protected] 1 Department of Computer Science and Engineering, University of Bologna, Bologna, Italy
Page 2 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 However, testing TSN technologies in physical environments for security purposes poses significant practical challenges. The specialized nature of TSN switches and devices often requires a substantial financial investment, making it challenging for small-scale organizations or research institutions to establish robust testbeds[8]. Furthermore, physical test setups are inherently inflexible, as testing new configurations or scenarios frequently requires additional hardware or extensive modifications to existing setups [9]. This lack of scalability not only increases costs but also delays testing cycles, limiting the pace of development and innovation. To address these challenges, virtualized testing environments and Digital Twins (DTs) are gaining traction in the Industry 4.0 landscape[10, 11]. These approaches enable researchers and organizations to simulate complex network configurations and attack scenarios without the high costs and rigidity of physical testbeds[12]. When applied to TSN, Digital Twins enable proactive threat detection and mitigation, thereby enhancing the reliability and security of TSN-enabled systems while preserving the operational integrity of industrial processes. In this work, we propose a scalable and fully virtualized TSN Digital Twin, designed to address the critical need for security testing in Time-Sensitive Networking. By leveraging advanced virtualization techniques and the Infrastructure as Code paradigm, our Digital Twin enables automated deployment, reconfiguration, and simulation of diverse TSN scenarios, providing a cost-effective and flexible alternative to physical testbeds. The Digital Twin emulates real-world TSN behaviors by integrating precise time synchronization using Precision Time Protocol (PTP), advanced queuing disciplines for traffic shaping and prioritization, and deterministic communication through virtualized Ethernet networks. Existing virtual labs and emulation platforms tend to focus on functional or performance aspects, often neglecting the specific timing constraints and security threat models relevant to TSN deployments. Our work addresses this gap by integrating well-established virtualization technologies into a cohesive framework that supports STRIDE-based threat modeling, synchronized traffic flows, and automated security testing. The originality of our approach lies in the orchestration of these components to create a domain-specific Digital Twin tailored for security experimentation. This enables practitioners and researchers to replicate time-sensitive scenarios, inject realistic threats, and evaluate system behavior in a controlled and repeatable way. We demonstrate the Digital Twin capabilities through the simulation of two STRIDE-based attack scenarios: PTP Clock Poisoning and Credit-Based Shaper Denialof-Service. These scenarios highlight vulnerabilities in TSN systems and showcase the Digital Twin’s potential for identifying security gaps and testing mitigation strategies. In summary, we make the following contributions: • We propose a flexible, scalable, and reconfigurable Digital Twin for TSN protocol validation and security testing. By leveraging virtualization and the Infrastructure as Code paradigm, the Digital Twin is fully automated, enabling rapid adaptation to different testing scenarios while reducing manual effort. • We evaluate the Digital Twin’s suitability for security testing by implementing two attack scenarios based on the TSN STRIDE threat model. The first attack, PTP Clock Poisoning, undermines TSN time synchronization, while the second attack, Credit-Based Shaper Denial of Service, tampers with the TSN scheduling. • The TSN Digital Twin and the code for reproducing the presented attacks are publicly available1. The remainder of this paper is organized into eight main sections. The Sect.2 discusses the IEEE 802.1 TSN set of standards and classifies TSN security threats using the STRIDE framework. The Sect.3 motivates the need for a TSN Digital Twin, illustrating the high costs, logistical challenges, and complexity of testing TSN protocols in physical environments. Then, the Sect.4 presents an overview of the proposed TSN Digital Twin architecture, emphasizing its design objectives. The Sect.5 provides a comprehensive description of the implementation of the TSN Digital Twin across its three layers, focusing on the integration of virtualization technologies and network emulation tools. Subsequently, by simulating two attack scenarios and proposing corresponding countermeasures, the Sect.6 demonstrates how the Digital Twin can be effectively employed for TSN security testing purposes. Finally, the Sect.7 analyzes related work, and the Sect.8 draws our conclusions. 2 Background 2.1 Time Sensitive Networking Time-Sensitive Networking is an advanced set of open standards developed under the IEEE 802.1 working group to enable deterministic communication over Ethernet-based networks. A notable advantage of TSN lies in its capability to enable ultra-low latency communication with deterministic delivery guarantees. It addresses the challenges of ensuring real-time data transmission with low latency, reliability, and precision, 1 https:// github. com/ Unibo Secur ityRe search/ TSNdigit altwin
Page 3 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 making it suitable for critical applications in industries such as manufacturing, aerospace, automotive, and telecommunications. For instance, in industrial safety systems, TSN ensures instantaneous responses, such as the immediate halting of machinery upon activation of an emergency stop button—something traditional networks cannot reliably accomplish. TSN encompasses a suite of protocols based on standards such as IEEE 802.1Q-2018, which provide mechanisms for time-sensitive, real-time transmission. These protocols address stringent communication requirements, supporting enhanced Quality of Service (QoS). The TSN protocol family can be classified focusing on time synchronization, scheduling, control and orchestration, and policing and redundancy. As described in Table 1, TSN protocols are organized into four key categories: Time Synchronization, Scheduling, Control and Orchestration, and Policing and Redundancy. Each one addresses a specific aspect of deterministic networking for reliable, real-time communication. Time synchronization refers to protocols that keep all networked devices precisely aligned in time. Every device must be synchronized to a standard clock for TSN to achieve deterministic behavior. The IEEE 802.1AS standard[13], using the Generalized Precision Time Protocol (gPTP)[25], enables this synchronization, allowing timesensitive data to be transmitted with the exact timing required for critical applications. Scheduling includes protocols that manage prioritizing and organizing network traffic, ensuring that high-priority data reaches its destination without delay. Protocols like IEEE 802.1Qbv Time-Aware Shaper[14] divide network communication into fixed time slots, allowing critical data to pass without interruption. Additional protocols, such as IEEE 802.3bu Frame Preemption[16], allow time-sensitive frames to interrupt ongoing lower-priority transmissions. Meanwhile, IEEE 802.1Qav [18] enables forwarding and queuing enhancements that prevent high-priority frames from being delayed by less critical traffic. Control and orchestration are dedicated to overseeing network resources and routing paths to achieve efficient data flow. IEEE 802.1Qat[19] and IEEE 802.1Qcc[21] protocols manage resource reservation, guaranteeing that critical data streams have adequate bandwidth and resources. Meanwhile, IEEE 802.1Qca [20] supports path control, enabling redundant and optimized routing to enhance fault tolerance. Collectively, these protocols ensure that time-sensitive traffic is prioritized, managed, and consistently controlled throughout the network. Policing and redundancy address network reliability and data integrity. Policing protocols[23] enforce rules to filter out unauthorized or malformed data streams, thereby preventing congestion and protecting the network from potential security threats, such as Denialof-Service (DoS) attacks. Redundancy protocols [24] instead duplicate critical frames and transmit them over separate paths, ensuring data delivery even in the event of a network failure. By combining these categories, TSN provides a comprehensive framework that enables precise, reliable, and secure data transmission, establishing itself as a foundational technology for industries requiring deterministic communication. Table 1 Classification of TSN protocols, divided into categories Category Protocol Time synchronization IEEE 802.1AS Time Synchronization for Time-sensitive Applications [13] Scheduling IEEE 802.1Qbv Time-Aware Shaper (TAS) [14] IEEE 802.1Qch Cyclic Queuing and Forwarding (CQF) [15] IEEE 802.3bu Frame Preemption [16] IEEE 802.1Qcr Asynchronous Traffic Shaping (ATS) [17] IEEE 802.1Qav Forwarding and Queuing for Time-Sensitive Streams (FQTSS) [18] Control and orchestration IEEE 802.1Qat Stream Reservation Protocol (SRP) [19] IEEE 802.1Qca Path Control and Reservation (PCR) [20] IEEE 802.1Qcc SRP Enhancements and Central Management [21] IEEE 802.1CM TSN for Fronthaul [22] Policing and redundancy IEEE 802.1Qci Per-Stream Filtering and Policing (PSFP) [23] IEEE 802.1CB Frame Replication and Elimination for Reliability (FRER) [24]
Page 4 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 2.2 TSN STRIDE threat model In[6], authors systematically categorized TSN threats using the STRIDE framework [26], which identifies potential threats as Spoofing, Tampering, Repudiation, Information disclosure, Denial of Service (DoS), and Elevation of Privilege. Table2 shows how STRIDE threats apply to various TSN protocols, targeting their key mechanisms and potentially compromising the deterministic guarantees essential for mission-critical systems. In the context of time synchronization, spoofing attacks can compromise the integrity of the clocking hierarchy, for example, by impersonating a master clock or intervening in the grandmaster selection process [27]. Similarly, tampering with synchronization packets or timestamps can introduce delays or inconsistent timing information, undermining network reliability[28, 29]. Even cryptographic protections cannot fully mitigate these issues, as delay attacks exploit the propagation delay adjustments inherent in the synchronization process[30]. Scheduling mechanisms are particularly vulnerable to tampering and DoS attacks[31]. Unauthorized modifications to gate control lists or excessive injection of highpriority traffic can disrupt the balance of traffic priorities, causing resource exhaustion and degraded Quality of Table 2 TSN threats matching with corresponding STRIDE threats Category Threat type Description Time synchronization Spoofing Compromised or impersonated master clock Intervening the grandmaster selection Unauthorized join as master clock Denial of service Sabotaging the grandmaster Delaying packets Tampering Tampering or forging synchronization packets Altering timestamps Mixing protocol version specifications Scheduling Tampering Tampering or forging configuration packets Malicious and inconsistent scheduling Denial of service Injecting excessive high-priority traffic Elevation of privilege Calibrated attacks on backbone nodes Promoting low-priority traffic Reservation Denial of service Intervening resource request propagation Blocking control packets on ports and VLANs Flooding management database Exhausting resources by malicious reservation Tampering Tampering or forging request packets Modifying announced stream characteristics Orchestration Spoofing Compromised or impersonated controller Malicious configuration of streams and resource reservations Adding malicious end-points and bridges Denial of service Sabotaging the controller Various interfaces Targeting various interfaces Redundancy Spoofing Forging malicious packets with fake sequence numbers Deceiving late error detection Tampering Tampering packets by manipulating sequence numbers Deliberate changes for replay attacks Changing by random sequence numbers Denial of service Malicious multipath configuration Assigning intersecting paths Configuring delay-induced paths Policing Denial of service Loosening filtering and rate-limiting rules Misconfiguration Misconfiguration or contradicting configuration
Page 5 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 Service (QoS). The deterministic nature of TSN scheduling also makes it susceptible to calibrated attacks that target specific nodes at predictable times. Control and orchestration threats include elevation of privilege attacks on centralized controllers, where attackers may misconfigure critical paths or resources, introduce malicious endpoints, or sabotage orchestration processes entirely [32]. Even subtle misconfigurations, such as rerouting critical traffic through suboptimal paths, can degrade performance over time[33]. Finally, spoofing or tampering with sequence numbers in redundancy protocols can cause packet duplication, out-of-order delivery, or replay attacks[34]. Misconfigured filtering and policing rules can either fail to prevent malicious traffic or inadvertently block legitimate communication, creating additional vulnerabilities[35]. 3 Problem statement The establishment of a virtualized testing infrastructure has become a strategic necessity in the advancement of Time-Sensitive Networking technologies [36]. TSN, as a core enabler for deterministic networking in missioncritical systems, requires rigorous testing and validation to ensure performance and reliability [37]. However, testing these technologies in physical environments is fraught with significant challenges. The high cost of TSN switches[38] and the complexity of setting up physical testbeds pose substantial barriers, making traditional methods impractical for many organizations. Testing TSN technologies in physical environments is both costly and time-intensive. TSN switches and devices are highly specialized, often requiring significant investment to establish a comprehensive physical testbed. This expense can be prohibitive, particularly for small-scale organizations or research institutions. Additionally, the time needed to set up, maintain, and reconfigure physical devices for testing various scenarios can slow down development cycles[39]. These constraints limit the scalability and flexibility of physical testing, as each new configuration or scenario may require additional hardware or significant modifications to the test setup. In this context, the concept of virtualized Digital Twins provides a pivotal solution for overcoming these challenges and limitations. A Digital Twin replicates TSN environments in a fully digitalized form, enabling comprehensive testing, configuration validation, and performance analysis without the need for physical hardware[40]. Virtualized environments facilitate rapid reconfiguration and the simulation of diverse network scenarios, such as failure conditions and highload situations, that would be challenging to replicate in physical setups. By doing so, they reduce financial barriers, accelerate testing processes, and enable more detailed data collection and analysis, thereby enhancing the overall understanding of TSN performance and security. Despite these advantages, the adoption of virtualized testing environments presents its own set of challenges. Ensuring that virtualized environments accurately emulate real-world TSN behaviors is a critical concern, as inaccuracies in emulation can lead to misleading results and reduce the reliability of tests. Additionally, the complexity of developing a robust virtualized testing framework requires expertise in both TSN protocols and virtualization technologies, which may not be readily available. Integrating virtualized environments with physical components for hybrid testing scenarios further adds to the complexity, potentially leading to inconsistencies and additional costs[41]. 4 TSN Digital Twin Based on these practical problems and challenges, we present a flexible, completely virtual TSN Digital Twin for security experimentation, including example attack scenarios. First, we discuss the design objectives that we consider most relevant, and then proceed with the conceived Digital Twin architecture. 4.1 Design objectives The TSN Digital Twin we developed is grounded in the Infrastructure as Code paradigm [42], a modern approach that ensures the flexibility and reconfigurability required for advanced testing environments. By adopting IaC, the entire Digital Twin can be managed through declarative code, allowing for automated deployment, reconfiguration, and scaling. This approach eliminates the traditional barriers of manual infrastructure management, enabling users to adapt the environment to different testing scenarios quickly. Whether it involves evaluating vulnerabilities in TSN protocols or simulating attack scenarios, the reconfigurability offered by IaC ensures that the Digital Twin remains a dynamic and versatile tool. The Digital Twin is designed to support security experimentation with a focus on attacks targeting TSN Time Synchronization protocols and scheduling mechanisms. These two areas are critical in TSN environments, as they ensure deterministic network behavior. By simulating a range of attacks, including those categorized under the STRIDE model, the Digital Twin enables users to test and evaluate the impact of spoofing, tampering, denialof-service, and other threats. These simulations offer valuable insights into the vulnerabilities of TSN systems, helping to identify robust mitigation strategies. The
Page 6 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 STRIDE framework serves as the foundation for structuring the attack scenarios, ensuring comprehensive coverage of potential threats, and aligning the experimentation with established threat modeling practices. The primary goals of the TSN Digital Twin are to provide organizations with the ability to gain hands-on experience with TSN communication protocols without the need for extensive physical infrastructure. By offering a virtual testing environment, the Digital Twin eliminates the high costs and logistical challenges associated with physical testbeds. It enables users to evaluate the impact of configuration changes in a controlled environment, thereby avoiding real-world risks. The Digital Twin also facilitates testing the interoperability of TSN protocols with various security configurations, ensuring that components function reliably even under diverse conditions. Our objective in developing the TSN Digital Twin is to create a tool that can be effectively used for security experimentation. The Digital Twin is intended not only for attack simulation but also for education and training purposes, enabling users to explore the complexities of TSN systems in a safe and flexible environment. To achieve this, the Digital Twin emphasizes characteristics that are both functional and structural, ensuring a balance between accuracy and practicality. Fidelity is a key consideration, referring to how closely the Digital Twin emulates real-world TSN environments. While physical replicas offer the highest degree of fidelity, the use of virtualization and emulation techniques in the Digital Twin provides a cost-effective yet meaningful alternative. The choice of these techniques is guided by the need to achieve testing goals without compromising scalability or usability. 4.2 Digital Twin architecture The implementation of the TSN Digital Twin was achieved through a combination of virtualization technologies, automation tools, and network simulation frameworks. The primary goal was to create a flexible, scalable, and automated virtualized testing environment that enables experimentation with TSN protocols, with a particular focus on attacks targeting time synchronization and scheduling mechanisms. The design leverages the Infrastructure as Code (IaC) paradigm, which is implemented using Ansible 2. This tool enables the deployment, reconfiguration, and scaling of the entire environment through declarative code, significantly reducing setup complexity and enhancing reproducibility. Ansible’s agentless architecture ensures that configurations can be applied seamlessly over SSH, automating the provisioning and management of virtual machines and network configurations with efficiency and consistency[43]. The architecture of the TSN Digital Twin is represented in Fig.1. The TSN Digital Twin architecture is structured across four main layers, each contributing specific functionalities: the hardware layer, the kernel layer, the VirtIO layer, and the user space layer. The hardware layer represents the physical resources of the host machine, which serves as the foundation for the entire TSN Digital Twin infrastructure. This layer includes the CPU, RAM, GPU, and network interfaces, providing the computational power and connectivity required to support the virtualized environment. As the ground of the architecture, the hardware layer ensures that the performance and scalability of the Digital Twin meet the demands of TSN testing and experimentation. At the kernel layer, the system employs KVM (Kernelbased Virtual Machine) and QEMU to enable hardwareaccelerated virtualization. This combination ensures efficient resource utilization and near-native performance, creating a robust base for hosting the virtualized components. The VirtIO layer is the core enabler of TSN capabilities within the Digital Twin. It supports ultra-low latency communication and real-time constraints essential for TSN operations. By implementing VirtIO at both the kernel and user space levels, this layer minimizes I/O overhead through direct memory sharing between host and guest systems. Moreover, it incorporates the necessary mechanisms for TSN scheduling, including multi-queue support and advanced queuing disciplines, to ensure precise traffic shaping and deterministic delivery of network traffic. The user space layer consists of QEMU processes, each representing a virtual machine (VM) configured as a TSN endpoint, such as a client, server, or switch. These VMs run the Precision Time Protocol[44] to synchronize clocks across the network following the schema in Fig.2, a critical requirement for maintaining deterministic behavior in TSN environments. This layer, combined with the capabilities of the VirtIO layer, enables the emulation of realistic TSN scenarios, providing a comprehensive platform for testing, experimentation, and validation. 5 Digital Twin implementation In this section, we provide a comprehensive overview of the implementation of each layer of the TSN Digital Twin, with a focus on the key enabling technologies that make this framework an effective tool for emulating TSN environments. Each layer of the architecture has been meticulously designed to replicate the stringent requirements of TSN, including low-latency 2 https:// www. ansib le. com/
Page 7 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 communication, deterministic packet delivery, and precise time synchronization. It is essential to note that by utilizing Infrastructure-asCode development, we facilitate the automated deployment of each layer without requiring additional manual configuration. This automation ensures a consistent and efficient setup process across all system components. The only user-defined parameters are the number and type of TSN endpoints specified in the host user space layer, offering both flexibility and scalability to adapt to varying network scenarios. This approach simplifies the deployment process while providing a robust and versatile Digital Twin for testing, validating, and optimizing TSN protocols under realistic conditions. 5.1 Kernel layer implementation The kernel layer of the TSN Digital Twin utilizes KVM and QEMU for efficient virtualization, providing a robust foundation for hosting TSN-specific applications. Integral to this layer is the implementation of Virtual Distributed Ethernet (VDE), a key technology that emulates Ethernet network environments entirely in software[45]. VDE introduces virtual switches and virtual cables, mirroring the architecture of physical Ethernet networks. VDE switches function like hardware switches, dynamically associating MAC addresses with virtual ports to enable seamless packet forwarding. Virtual cables interconnect these switches, allowing network topology flexibility without the constraints of physical hardware. Fig. 1 Architecture of the TSN Digital Twin Fig. 2 PTP Grandmaster, Boundary, and Slave Clocks. In the figure, “M” stands for Master while “S” denotes Slave
Page 8 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 The inclusion of VDE in the kernel layer is essential for several reasons. It enables the creation of complex, distributed virtual networks where components such as switches and endpoints can run on different physical hosts. This distribution mirrors real-world TSN environments, allowing for realistic testing scenarios. VDE also scales with the infrastructure, supporting multiple interconnected switches and virtual machines. This scalability is crucial for simulating large-scale TSN networks, particularly for testing scenarios involving high device density or diverse topologies. Additionally, VDE networks are entirely virtual, ensuring that experimental traffic remains isolated from the physical network. This isolation enables the safe execution of experiments, including testing malicious scenarios such as DoS attacks, without risking real-world disruptions. VDE integrates with various virtualization platforms, including QEMU and User-Mode Linux, making it highly adaptable. Its virtual interfaces are based on the TAP interface, appearing as hardware interfaces to the operating system, offering compatibility with existing tools and protocols. TAP (terminal access point) interfaces play a pivotal role in this architecture [46]. TAP interfaces emulate Ethernet devices, enabling the transmission and reception of raw Ethernet frames between virtual machines and the kernel’s network stack. Their ability to mimic the behavior of physical network interfaces makes them indispensable for testing TSN protocols. TAP devices are instantiated within the kernel using the tun driver, which is configured with the IFF_TAP flag, allowing them to function as Ethernet endpoints. Each TAP interface is linked to a file descriptor that acts as a communication channel between the user space and the kernel. Ethernet frames transmitted by a virtual machine through its TAP interface are received by the kernel’s network stack and routed to their destination. Similarly, incoming frames from the virtual network reach the TAP interface and are presented to the virtual machine as if they originated from a physical Ethernet port. In the TSN Digital Twin, TAP interfaces are seamlessly integrated with VDE. Each TAP device is connected to a VDE switch port, creating a fully virtualized Ethernet network. This connection emulates the functionality of a physical Ethernet switch, including MAC address learning, traffic forwarding, and packet isolation. The VDE switches and TAP interfaces collectively create a realistic Ethernet environment where TSNspecific features, such as deterministic traffic scheduling and time synchronization, can be thoroughly tested. The combination of TAP and VDE ensures a high-fidelity emulation of TSN behaviors, such as traffic shaping, delay simulations, and packet dropping, providing a cost-effective alternative to physical TSN-specific hardware switches and cabling. By incorporating VDE into the kernel layer, the TSN Digital Twin ensures a robust, scalable, and cost-effective environment for evaluating and enhancing TSN protocols. This emulation framework not only supports advanced testing scenarios but also bridges the gap between theoretical analysis and practical implementation. TAP interfaces enable virtual machines in the TSN testbed to function as fully operational TSN nodes. These interfaces connect to VDE switches, forming a cohesive network where TSN protocols can be deployed and evaluated under controlled, reproducible conditions. The use of TAP interfaces in conjunction with VDE offers multiple advantages. TAP interfaces emulate Ethernet devices with high fidelity, making them ideal for testing TSN protocols that depend on precise Ethernetlayer behavior. By operating directly at Layer 2, TAP interfaces enable the testbed to replicate TSN-specific traffic patterns, including features such as frame preemption and priority-based scheduling. Furthermore, their direct communication with the kernel bypasses the traditional socket API, reducing I/O overhead and ensuring low-latency packet handling, which is critical for maintaining the strict timing requirements of TSN protocols. In practice, TAP interfaces enable virtual machines in the TSN testbed to function as fully operational TSN nodes, such as end devices or switches. These interfaces connect to VDE switches, forming a cohesive network where TSN protocols can be deployed and evaluated under controlled, reproducible conditions. The combination of TAP interfaces and VDE ensures that the virtualized TSN network accurately replicates real-world conditions, facilitating detailed testing of protocol behavior, performance, and resilience under diverse scenarios. Ultimately, the TAP-VDE integration ensures the precise emulation of features such as frame scheduling and clock synchronization, making it possible to analyze the behavior of TSN standards in detail. 5.2 VirtIO layer implementation The VirtIO layer serves as a critical component of the TSN Digital Twin, enabling efficient communication between guest virtual machines and the host system. The integration between VirtIO and QEMU permits to expose virtual devices such as network adapters through drivers that operate directly with the guest Operative System[47], minimizing the overhead of hardware emulation. This efficiency is essential for replicating the deterministic and low-latency behaviors required in TSN environments. At its core, VirtIO relies on two primary components: the VirtIO devices implemented in QEMU and the
Page 9 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 VirtIO drivers within the guest operating system. These components work together to deliver high-performance I/O operations with minimal overhead, aligning perfectly with the deterministic and low-latency requirements of TSN protocols. VirtIO devices are virtual representations of hardware components, including network interfaces, block devices, and consoles. These devices are implemented within QEMU and are exposed to the guest operating system through standardized transport mechanisms, Peripheral Component Interconnect (PCI) or Memorymapped I/O and port-mapped I/O (MMIO). Although these devices appear as physical hardware to the guest, their functionality is entirely virtual, relying on QEMU to execute the actual I/O operations. In the context of the TSN Digital Twin, the VirtIO-net device serves as a virtual network adapter, interacting seamlessly with the host system’s resources through the TAP interface. This setup ensures that TSN-specific traffic flows can be emulated accurately. On the guest side, the VirtIO driver facilitates communication with the VirtIO devices presented by QEMU. These drivers, optimized for paravirtualized environments, utilize shared memory buffers and circular buffer structures, known as virtqueues, to handle I/O operations. When the guest OS needs to transmit data, such as a TSN packet, the VirtIO driver places the packet and its associated metadata into a virtqueues. The driver then notifies QEMU through a virtual interrupt, signaling that the data is ready for processing. QEMU retrieves the packet from the virtqueue and transmits it through the host network stack using a TAP interface. This process ensures the efficient and low-latency delivery of TSN traffic. In the reverse direction, when the host system receives data for the guest, QEMU places the incoming data into the virtqueues shared with the guest OS. A notification is sent to the VirtIO driver, which retrieves the data and delivers it to the appropriate application or network stack in the guest. This bidirectional interaction ensures a seamless flow of TSN packets, crucial for maintaining the precise timing and reliability required in TSN environments. This process is illustrated in Fig.3. The VirtIO layer in the TSN Digital Twin is significantly enhanced by the multiqueue feature, a solution designed to overcome the scalability limitations of single-queue network configurations. In traditional setups, VMs with multiple virtual CPUs (vCPUs) are constrained by the presence of a single ingress (RX) and egress (TX) queue. This creates a bottleneck where increasing the number of Fig. 3 VirtIO layer implementation on Qemu and interactions with the kernel and user space layers through the VirtIO device and driver
Page 16 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 Consent for publication Not applicable. Competing interests The authors declare that they have no competing interests. Received: 13 February 2025 Accepted: 11 August 2025 References 1. D. Berardi, F. Callegati, A. Giovine, A. Melis, M. Prandini, L. Rinieri, When operation technology meets information technology: challenges and opportunities. Future Internet 15(3), 95 (2023) 2. L. Salazar, S.R. Castro, J. Lozano, K. Koneru, E. Zambon, B. Huang, R. Baldick, M. Krotofil, A. Rojas, A.A. Cardenas, in 2024 IEEE Symposium on Security and Privacy (SP). A tale of two industroyers: It was the season of darkness (IEEE, Piscataway, NJ, USA, 2024), pp. 312–330 3. K.E. Hemsley, E. Fisher et al., History of industrial control system cyber incidents. Technical report, Idaho National Lab.(INL), Idaho Falls, ID (United States) (2018) 4. T. Zhang, G. Wang, C. Xue, J. Wang, M. Nixon, S. Han, Time-sensitive networking (TSN) for industrial automation: current advances and future directions. ACM Comput. Surv. 57(2), 1–38 (2024) 5. A. Nasrallah, A.S. Thyagaturu, Z. Alharbi, C. Wang, X. Shao, M. Reisslein, H. ElBakoury, Ultra-low latency (ULL) networks: the IEEE TSN and IETF DetNet standards and related 5G ULL research. IEEE Commun. Surv. Tutor. 21(1), 88–145 (2018) 6. D. Ergenç, C. Brülhart, J. Neumann, L. Krüger, M. Fischer, in 2021 IEEE International Conference on Communications Workshops (ICC Workshops). On the security of IEEE 802.1 time-sensitive networking (IEEE, Piscataway, NJ, USA, 2021), pp. 1–6 7. L.L. Bello, W. Steiner, A perspective on IEEE time-sensitive networking for industrial communication and automation systems. Proc. IEEE. 107(6), 1094–1120 (2019) 8. C. Xue, T. Zhang, S. Han, in Proceedings of the 61st ACM/IEEE Design Automation Conference. Towards cost-effective real-time high-throughput end station design for time-sensitive networking (tsn) (Association for Computing Machinery (ACM), New York, NY, USA, 2024), pp. 1–6 9. M. Bosk, F. Rezabek, K. Holzinger, A.G. Marino, A.A. Kane, F. Fons, J. Ott, G. Carle, Methodology and infrastructure for TSN-based reproducible network experiments. IEEE Access 10, 109203–109239 (2022) 10. J. Leng, D. Wang, W. Shen, X. Li, Q. Liu, X. Chen, Digital twins-based smart manufacturing system design in industry 4.0: a review. J. Manuf. Syst. 60, 119–137 (2021) 11. C. Grasselli, A. Melis, L. Rinieri, D. Berardi, G. Gori, A. Al Sadi, in 2022 International Symposium on Networks, Computers and Communications (ISNCC). An industrial network digital twin for enhanced security of cyber-physical systems (IEEE, Piscataway, NJ, USA, 2022), pp. 1–7 12. M. Javaid, A. Haleem, R. Suman, Digital twin applications toward industry 4.0: a review. Cogn. Robot. 3, 71–92 (2023) 13. IEEE, IEEE Standard for Local and Metropolitan Area Networks–Timing and Synchronization for Time-Sensitive Applications. IEEE Std 802.1AS-2020 (Revision of IEEE Std 802.1AS-2011) pp. 1–421 (2020). https:// doi. org/ 10. 1109/ IEEES TD. 2020. 91218 45 14. IEEE, IEEE Standard for Local and metropolitan area networks – Bridges and Bridged Networks - Amendment 25: Enhancements for Scheduled Traffic. IEEE Std 802.1Qbv-2015 (Amendment to IEEE Std 802.1Q-2014 as amended by IEEE Std 802.1Qca-2015, IEEE Std 802.1Qcd-2015, and IEEE Std 802.1Q-2014/Cor 1-2015) pp. 1–57 (2016). https:// doi. org/ 10. 1109/ IEEES TD. 2016. 86130 95 15. IEEE, IEEE Standard for Local and metropolitan area networks–Bridges and Bridged Networks–Amendment 29: Cyclic Queuing and Forwarding. IEEE 802.1Qch-2017 (Amendment to IEEE Std 802.1Q-2014 as amended by IEEE Std 802.1Qca-2015, IEEE Std 802.1Qcd(TM)-2015, IEEE Std 802.1Q2014/Cor 1-2015, IEEE Std 802.1Qbv-2015, IEEE Std 802.1Qbu-2016, IEEE Std 802.1Qbz-2016, and IEEE Std 802.1Qci-2017) pp. 1–30 (2017). https:// doi. org/ 10. 1109/ IEEES TD. 2017. 79613 03 16. IEEE, IEEE Standard for Ethernet–Amendment 8: Physical Layer and Management Parameters for Power over Data Lines (PoDL) of Single Balanced Twisted-Pair Ethernet. IEEE Std 802.3bu-2016 (Amendment to IEEE Std 802.3-2015 as amended by IEEE Std 802.3bw-2015, IEEE Std 802.3by2016, IEEE Std 802.3bq-2016, IEEE Std 802.3bp-2016, IEEE Std 802.3br2016, IEEE Std 802.3bn-2016, and IEEE Std 802.3bz-2016) pp. 1–77 (2017). https:// doi. org/ 10. 1109/ IEEES TD. 2017. 78511 24 17. IEEE, IEEE Standard for Local and Metropolitan Area Networks–Bridges and Bridged Networks - Amendment 34: Asynchronous Traffic Shaping. IEEE Std 802.1Qcr-2020 (Amendment to IEEE Std 802.1Q-2018 as amended by IEEE Std 802.1Qcp-2018, IEEE Std 802.1Qcc-2018, IEEE Std 802.1Qcy-2019, and IEEE Std 802.1Qcx-2020) pp. 1–151 (2020). https:// doi. org/ 10. 1109/ IEEES TD. 2020. 92530 13 18. IEEE, IEEE Standard for Local and metropolitan area networks– Virtual Bridged Local Area Networks Amendment 12: Forwarding and Queuing Enhancements for Time-Sensitive Streams. IEEE Std 802.1Qav-2009 (Amendment to IEEE Std 802.1Q-2005) pp. 1–72 (2010). https:// doi. org/ 10. 1109/ IEEES TD. 2010. 86846 64 19. IEEE, IEEE Standard for Local and metropolitan area networks–Virtual Bridged Local Area Networks Amendment 14: Stream Reservation Protocol (SRP). IEEE Std 802.1Qat-2010 (Revision of IEEE Std 802.1Q-2005) pp. 1–119 (2010). https:// doi. org/ 10. 1109/ IEEES TD. 2010. 55949 72 20. IEEE, ISO/IEC/IEEE International Standard – Information technology – Telecommunications and information exchange between systems – Local and metropolitan area networks – Specific requirements – Part 1Q: Bridges and bridged networks AMENDMENT 1: Path control and reservation. ISO/IEC/IEEE 8802-1Q:2016/Amd.1:2017(E) pp. 1–122 (2017). https:// doi. org/ 10. 1109/ IEEES TD. 2017. 85111 00 21. IEEE, IEEE/ISO/IEC International Standard-Telecommunications and exchange between information technology systems – Requirements for local and metropolitan area networks – Part 1Q: Bridges and bridged networks AMENDMENT 31: Stream Reservation Protocol (SRP) enhancements and performance improvements. IEEE/ISO/IEC 8802-1Q-2020/Amd312021 pp. 1–211 (2021). https:// doi. org/ 10. 1109/ IEEES TD. 2021. 95996 25 22. IEEE, IEEE Standard for Local and metropolitan area networks – Time-Sensitive Networking for Fronthaul. IEEE Std 802.1CM-2018 pp. 1–62 (2018). https:// doi. org/ 10. 1109/ IEEES TD. 2018. 83760 66 23. IEEE, IEEE/ISO/IEC International Standard - Information technology - Telecommunications and information exchange between systems - Local and metropolitan area networks - Specific requirements - Part 1Q:Bridges and bridged networksAMENDMENT 6: Per-stream filtering and policing. ISO/IEC/IEEE 8802-1Q:2016/Amd.6:2019(E) pp. 1–68 (2019). https:// doi. org/ 10. 1109/ IEEES TD. 2019. 86646 96 24. IEEE, IEEE Standard for Local and metropolitan area networks–Frame Replication and Elimination for Reliability. IEEE Std 802.1CB-2017 pp. 1–102 (2017). https:// doi. org/ 10. 1109/ IEEES TD. 2017. 80911 39 25. V. Shankarkumar, L. Montini, T. Frost, G. Dowd. Precision Time Protocol Version 2 (PTPv2) Management Information Base. RFC 8173 (2017). https:// doi. org/ 10. 17487/ RFC81 73. https:// www. rfceditor. org/ info/ rfc81 73 26. S. Hernan, S. Lambert, T. Ostwald, A. Shostack, Threat modeling—uncover security design flaws using the stride approach (MSDN Magazine-Microsoft Corporation, Louisville, 2006) pp. 68–75 27. C. DeCusatis, R.M. Lynch, W. Kluge, J. Houston, P.A. Wojciak, S. Guendert, Impact of cyberattacks on precision time protocol. IEEE Trans. Instrum. Meas. 69(5), 2172–2181 (2019) 28. B. Moussa, C. Robillard, A. Zugenmaier, M. Kassouf, M. Debbabi, C. Assi, Securing the precision time protocol (PTP) against fake timestamps. IEEE Commun. Lett. 23(2), 278–281 (2018) 29. D. Berardi, N.O. Tippenhauer, A. Melis, M. Prandini, F. Callegati, Time sensitive networking security: issues of precision time protocol and its implementation. Cybersecurity 6(1), 8 (2023) 30. M. Ullmann, M. Vögeler, in 2009 International Symposium on Precision Clock Synchronization for Measurement, Control and Communication. Delay attacks—Implication on NTP and PTP time synchronization (IEEE, Piscataway, NJ, USA, 2009), pp. 1–6 31. P. Meyer, T. Häckel, F. Korf, T.C. Schmidt, in Proceedings of the 2019 IEEE Vehicular Networking Conference (VNC). DoS Protection through Credit Based Metering–Simulation-Based Evaluation for Time-Sensitive Networking in Cars. (IEEE, Piscataway, NJ, USA, 2019) pp. 1–8. https:// doi. org/ 10. 1109/ VNC48 660. 2019. 90627 70
Page 17 of 17 Melisetal. EURASIP Journal on Information Security (2025) 2025:26 32. S.B.H. Said, Q.H. Truong, M. Boc, SDN-based configuration solution for IEEE 802.1 time sensitive networking (TSN). ACM SIGBED Review 16(1), 27–32 (2019) 33. E. Grossman, T. Mizrahi, A. Hacker, Deterministic networking (DetNet) security considerations. Internet Engineering Task Force Request Comments RFC 9055, 1–25 (RFC Editor, Fremont, CA, USA, 2021) https:// doi. org/ 10. 17487/ RFC90 55 34. D. Ergenç, M. Fischer, in IEEE INFOCOM 2021-IEEE Conference on Computer Communications. On the reliability of ieee 802.1 cb frer (IEEE, Piscataway, NJ, USA, 2021), pp. 1–10 35. R. Hofmann, B. Nikolić, R. Ernst, Challenges and limitations of IEEE 802.1 CB-2017. IEEE Embed. Syst. Lett. 12(4), 105–108 (2019) 36. Y. Seol, D. Hyeon, J. Min, M. Kim, J. Paek, Timely survey of time-sensitive networking: past and future directions. IEEE Access 9, 142506–142527 (2021) 37. L. Silva, P. Pedreiras, P. Fonseca, L. Almeida, in 2019 IEEE 22nd international symposium on real-time distributed computing (ISORC). On the adequacy of SDN and TSN for Industry 4.0 (IEEE, Piscataway, NJ, USA, 2019), pp. 43–51 38. The Business Research Company. Time-Sensitive Networking (TSN) Global Market Report 2023 (2023). https:// www. thebu sines srese archc ompany. com/ report/ timesensi tivenetwo rkingtsnglobalmarketreport. Accessed 15 Nov 2024 39. M. Ulbricht, S. Senk, H.K. Nazari, H.H. Liu, M. Reisslein, G.T. Nguyen, F.H.P. Fitzek, Tsn-flextest: flexible tsn measurement testbed. IEEE Trans. Netw. Serv. Manag. 21(2), 1387–1402 (2024). https:// doi. org/ 10. 1109/ TNSM. 2023. 33271 08 40. S.B.H. Said, M.T. Thi, M. Kellil, A. Olivereau, in 2023 IEEE 28th International Conference on Emerging Technologies and Factory Automation (ETFA). On the management of TSN networks in 6G: A network digital twin approach (IEEE, Piscataway, NJ, USA, 2023), pp. 1–7 41. Y. Huang, J. Farkas, Challenges of digital twins in complex systems. IEEE Trans. Syst. Man Cybern. Syst. 50(6), 365–377 (2020) 42. K. Morris, Infrastructure as code (O’Reilly Media, Inc., Sebastopol, CA, USA, 2020) 43. L. Hochstein, R. Moser, Ansible: Up and Running: Automating configuration management and deployment the easy way (O’Reilly Media, Inc., Sebastopol, CA, USA, 2017) 44. J.C. Eidson, M. Fischer, J. White, in Proceedings of the 34th Annual Precise Time and Time Interval Systems and Applications Meeting. IEEE-1588™ standard for a precision clock synchronization protocol for networked measurement and control systems (IEEE, Piscataway, NJ, USA, 2002), pp. 243–254 45. R. Davoli, in First international conference on testbeds and research infrastructures for the development of networks and communities. Vde: Virtual distributed ethernet (IEEE, Piscataway, NJ, USA, 2005), pp. 213–220 46. L. Torvalds, M. Krasnyansky, M. Yevmenkin, F. Thiel, TUN/TAP device driver documentation (2002). https:// www. kernel. org/ doc/ Docum entat ion/ netwo rking/ tuntap. txt. Accessed 16 Nov 2024 47. R. Russell, Virtio: towards a de-facto standard for virtual I/O devices. ACM SIGOPS Oper. Syst. Rev. 42(5), 95–103 (2008) 48. S. Braithwaite, Queuing disciplines on Linux made easy. Ph.D. thesis, University of Southern Queensland (2006) 49. Y. Kuperman, E. Moscovici, J. Nider, R. Ladelsky, A. Gordon, D. Tsafrir, Paravirtual remote i/o. ACM Sigarch Comput. Archit. News 44(2), 49–65 (2016) 50. M. Topsakal, S. Cevher, in 2022 30th Signal Processing and Communications Applications Conference (SIU). Impact Analysis of Denial of Service Attacks in IEEE 802.1 Time Sensitive Networking (IEEE, Piscataway, NJ, USA, 2022), pp. 1–4 51. openSUSE, Managing the Clock in KVM (2024). https:// doc. opens use. org/ docum entat ion/ leap/ virtu aliza tion/ html/ bookvirtu aliza tion/ seckvmmanag ingclock. html. Accessed 16 Nov 2024 52. M. Langer, S. Fries, M. Rohde, K. Heine, D. Sibold, R. Bermbach, in 2021 IEEE International Symposium on Precision Clock Synchronization for Measurement, Control, and Communication (ISPCS). PTP Security key management solutions (IEEE, Piscataway, NJ, USA, 2021), pp. 1–6 53. E. Shereen, F. Bitard, G. Dán, T. Sel, S. Fries, in 2019 IEEE International Symposium on Precision Clock Synchronization for Measurement, Control, and Communication (ISPCS). Next steps in security for time synchronization: Experiences from implementing IEEE 1588 v2. 1 (IEEE, Piscataway, NJ, USA, 2019), pp. 1–6 54. N.H. Abd Wahab, K. Hasikin, K.W. Lai, K. Xia, L. Bei, K. Huang, X. Wu, Systematic review of predictive maintenance and digital twin technologies challenges, opportunities, and best practices. PeerJ Comput. Sci. 10, e1943 (2024) 55. K. Zanbouri, M. Noor-A-Rahim, J. John, C.J. Sreenan, H.V. Poor, D. Pesch, A comprehensive survey of wireless time-sensitive networking (tsn): Architecture, technologies, applications, and open issues. IEEE Commun. Surv. Tutor. 1–1 (2024). https:// doi. org/ 10. 1109/ COMST. 2024. 34866 18 56. Y. Yigit, H. Ahmadi, G. Yurdakul, B. Canberk, T. Hoang, T.Q. Duong, Digiinfrastructure: Digital twin-enabled traffic shaping with low-latency for 6G smart cities. IEEE Commun. Stand. Mag. 8(3), 28–34 (2024). https:// doi. org/ 10. 1109/ MCOMS TD. 0002. 23000 27 57. S.B. Hadj Said, M.T. Thi, M. Kellil, A. Olivereau, in 2023 IEEE 28th International Conference on Emerging Technologies and Factory Automation (ETFA). On the management of tsn networks in 6g: A network digital twin approach (2023), pp. 1–7. https:// doi. org/ 10. 1109/ ETFA5 4631. 2023. 10275 568 58. J. Sasiain, D. Franco, A. Atutxa, J. Astorga, E. Jacob, Towards the integration and convergence between 5g and tsn technologies and architectures for industrial communications: A survey. IEEE Commun. Surv. Tutor. 1–1 (2024). https:// doi. org/ 10. 1109/ COMST. 2024. 34226 13 59. Y. Lu, G. Zhao, C. Xu, M. Imran, K. Yu, J.J. Rodrigues, in ICC 2023 - IEEE International Conference on Communications. A framework for digital twinbased deterministic communication in satellite time sensitive networks (2023), pp. 6301–6306. https:// doi. org/ 10. 1109/ ICC45 041. 2023. 10279 611 60. R. Tavva, Time-sensitive networking in advanced manufacturing environments: A framework for industry 4.0 implementation. J. Comput. Sci. Technol. Stud. 7(6), 672–678 (2025) 61. L.V. Cakir, C.J. Thomson, M. Özdem, B. Canberk, V.L. Nguyen, T.Q. Duong, Intelligent digital twin communication framework for addressing accuracy and timeliness tradeoff in resource-constrained networks. IEEE Trans. Cogn. Commun. Netw. (2024) Publisher’s Note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.