CASSANDRA: Closed-Loop AI-Native Cyber Defense via Deception-Driven Active Sensing, Temporal Graph Intelligence, and Policy-Verified Autonomy for Cloud/IAM Environments
CASSANDRA is presented, a closed-loop cyber-defense framework that treats deception as an active sensing action rather than a static trap, and maintains a belief distribution over competing cloud and identity attack narratives on a temporal enterprise graph.
Abstract
Cloud and identity-centered attacks increasingly blend into legitimate administration through credential theft, token replay, delegated-role misuse, and control-plane API abuse. This paper presents CASSANDRA, a closed-loop cyber-defense framework that treats deception as an active sensing action rather than a static trap. The framework maintains a belief distribution over competing cloud and identity attack narratives on a temporal enterprise graph, selects a deception action according to expected information gain and operational cost, and subjects every candidate action to deterministic policy checks before execution. This revision makes the decision process explicit by defining the action and observation spaces, Bayesian update, information-gain objective, measurable safety budgets, stopping rule, and policy-verification procedure. We provide pseudocode, a structured threat model, and reproducibility materials accompanying this article with fixed configurations, source code, raw outputs, integrity checksums, and bootstrap confidence intervals. Across four author-defined scenarios and 160,000 simulated runs, full CASSANDRA achieved scenario-level accuracy from 0.909 to 0.993 and mean evidence gain from 0.110 to 0.266; the policy shield prevented all synthetically proposed unsafe executions, whereas the no-shield variant executed approximately 8% of such proposals. These results demonstrate controlled methodological behavior only and are not presented as production, public-dataset, or red-team validation. A reduced, technique-specific cloud/IAM scenario library illustrates how hypotheses, signals, probes, and bounded responses are instantiated without the repetitive catalogue structure of the original submission.
This study designs and analytically evaluates an SDN-native cybersecurity integration contract that unifies: a multidimensional threat model; invariant-based preventive assurance; governed hybrid detection; security-aware multi-controller resilience; ATT&CK informed traceability; and controlled learning.
Oumar Y. Maïga, Moussa Koita, I. Traoré et al.· International Journal of Adv...· 0 citations
This monograph presents a first-principles forensic autopsy of the intrusion, provides formal evidence that the breach was a predicted consequence under the Instrumental Convergence thesis operating within an unattenuated autonomous loop lacking out-of-band circuit-breakers, exposes the Defensive LLM Guardrail Paradox...
Adaptive security at the network edge increasingly relies on automated planners, including rule-based controllers, learned policies, and LLM-assisted agents, that translate observations into enforcement actions. Once such a planner can influence live policy state, syntactic validity is not enough. A semantically wrong...
Ijaz Ahmad, Flavio Esposito, Erkki Harjula· 0 citations
AI agents can diagnose cloud incidents, synthesize operational commands, and invoke state-changing APIs, but a plausible remediation is not necessarily safe to execute. This study presents RACER, a runtime-assurance mechanism that treats every AI-generated repair as an untrusted proposal until it is bound to a machine-...
Prudvi Saisaran Ponduru, Pavani Priya Vyshnavi Nandanavanam, Sai Kesav Kumar Ponduru· International Journal of Adv...· 0 citations
Enterprise artificial-intelligence agents increasingly call tools, modify infrastructure, and process protected data, creating a need to separate action generation from action authorization. This article presents VeriWeave Govern, a deterministic runtime governance layer that evaluates structured agent actions against...
Kabeh Mohsenzadegan, V. Tavakkoli, K. Kyamakya· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.