paper-with-me

Papers

Optimizing Cyber Response Time on Temporal Active Directory Networks Using Decoys

2024-03-27 · Huy Q. Ngo, Mingyu Guo, Hung Nguyen

Microsoft Active Directory (AD) is the default security management system for Window domain network. We study the problem of placing decoys in AD network to detect potential attacks. We model the problem as a Stackelberg game between an attacker and a defender on AD attack graphs where the defender employs a set of decoys to detect the attacker on their way to Domain Admin (DA). Contrary to previous works, we consider time-varying (temporal) attack graphs. We proposed a novel metric called response time, to measure the effectiveness of our decoy placement in temporal attack graphs. Response time is defined as the duration from the moment attackers trigger the first decoy to when they compromise the DA. Our goal is to maximize the defender's response time to the worst-case attack paths. We establish the NP-hard nature of the defender's optimization problem, leading us to develop Evolutionary Diversity Optimization (EDO) algorithms. EDO algorithms identify diverse sets of high-quality solutions for the optimization problem. Despite the polynomial nature of the fitness function, it proves experimentally slow for larger graphs. To enhance scalability, we proposed an algorithm that exploits the static nature of AD infrastructure in the temporal setting. Then, we introduce tailored repair operations, ensuring the convergence to better results while maintaining scalability for larger graphs.

📄 PDF Abstract BibTeX arXiv:2403.18162

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically

Similar Papers 제목 키워드 기반

StagePilot: Stage-Level Planning for Long-Horizon Dialogue Simulation in Cybergrooming

2026-02-04 · Heajun An, Qi Zhang, Minqian Liu, Xinyi Zhang 외 arxiv

Cybergrooming is an evolving threat to youth, requiring proactive educational interventions. We address this by modeling dialogue progression as a structured planning problem over stage-wise interactions. We propose Stag…

Reinforcement LearningResponse Generation

Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports

2024-01-03 · Md Rayhanur Rahman, Brandon Wroblewski, Quinn Matthews, Brantley Morgan 외

Defending from cyberattacks requires practitioners to operate on high-level adversary behavior. Cyberthreat intelligence (CTI) reports on past cyberattack incidents describe the chain of malicious actions with respect to…

Multi-Agent Collaboration in Incident Response with Large Language Models

2024-12-01 · Zefang Liu

Incident response (IR) is a critical aspect of cybersecurity, requiring rapid decision-making and coordinated efforts to address cyberattacks effectively. Leveraging large language models (LLMs) as intelligent agents off…

Decision Making

AgenticCyber: A GenAI-Powered Multi-Agent System for Multimodal Threat Detection and Adaptive Response in Cybersecurity

2025-12-06 · Shovan Roy arxiv

The increasing complexity of cyber threats in distributed environments demands advanced frameworks for real-time detection and response across multimodal data streams. This paper introduces AgenticCyber, a generative AI …

Intrusion Detection

Cybonto: Towards Human Cognitive Digital Twins for Cybersecurity

2021-08-01 · Tam N. Nguyen

Cyber defense is reactive and slow. On average, the time-to-remedy is hundreds of times larger than the time-to-compromise. In response to the expanding ever-more-complex threat landscape, Digital Twins (DTs) and particu…