Hospital ITOT Digital Twin Testbed
Abstract
Modern hospitals increasingly rely on integrated Information Technology (IT) and Operational Technology (OT) infrastructures to support critical healthcare services. However, this convergence expands the cybersecurity attack surface and makes safe validation of defensive mechanisms difficult on live systems. Existing testbeds often focus on isolated IT or OT environments and do not capture realistic cross-domain healthcare interactions. This work presents a hospital ITOT cybersecurity testbed coupled with a digital twin for monitoring, experimentation, and validation of countermeasures. The testbed emulates a central server, Electronic Health Record (EHR) systems, SCADA-based infrastructure, and segmented IT, OT, and DMZ networks. It supports controlled cyberattack execution, software-patch evaluation, and training of RL-based defense agents. The testbed is further extended to a digital twin that models the real-time state of the environment using log and network statistics and enables bidirectional interaction through command execution and container lifecycle orchestration. Modbus/TCP and FHIR/HL7 support realistic communication across healthcare and industrial components. Experimental evaluation shows low computation overhead, with average normalized CPU utilization below 0.4% per container and most lightweight services operating below 0.01%. OpenPLC Modbus TCP operations achieve a median round-trip latency of 0.901 ms. The testbed also captures a multi-stage SSH-based attack propagating from the DMZ to the IT and PLC networks. The framework provides a foundation for extending the emulated environment toward a hardware-enabled hospital digital twin.