Active cyber defense offers a promising approach to addressing the longstanding asymmetry between rapidly evolving cyber threats and static defense systems. However, active cyber defense requires fast responses and proactive reconfigurations that must be verified and tailored to observed attacker behaviour. Formal methods rely on rigorous mathematical and logical frameworks for verifying system specifications under welldefined assumptions. In particular, multi-agent system (MAS) verification, which examines formal properties of open systems, is well-suited for cybersecurity where attacker-defender interactions are central. This paper bridges the gap between system security modelling and MAS verification, providing active defense orchestration with formal guarantees. Our contributions are (i) a general methodology for controlling active cyber defenses with formally verified specifications based on the attack-defense movement model (ADM), a new model of attacker and defender actions, (ii) an application of this methodology for adaptive honeypot control, which relies on a MAS logic contribution to express strategic properties such as attacker attribution, and (iii) VeriPot, a tool which implements the honeypot adaptation strategy extraction from the ADM.
A tri-level defender–attacker–defender (DAD)-based attack strategy optimization model is proposed that identifies the most damaging coordinated cyber–physical attack strategies and that BTA-induced topology changes and cascading failure propagation significantly affect attack target selection.
Cyber defense in mission-critical environments requires integrated approaches capable of representing adversarial progression, defender-side uncertainty, mission impact, and defensive decision support within a unified framework. In operational domains, defenders must continuously estimate the evolving security posture...
Miguel Requena Micó, Mario Fernandez-Tarraga, Daniel Díaz-López et al.· ARES· 0 citations
As cyber threats to power grid infrastructures escalate, the urgency of understanding how to protect cyber-physical systems (CPS) has never been greater. These systems, which integrate physical processes with digital control, are increasingly susceptible to sophisticated cyberattacks that can lead to widespread disrupt...
A. Raptis, S. Gritzalis, A. Yannacopoulos· International Journal of Inf...· 0 citations
CyberLLM is presented, a multi-agent, LLM-orchestrated framework that autonomously detects vulnerabilities and executes remediations under a formal, runtime safety guard, and indicates that LLM agents can perform useful autonomous cyber-defense when wrapped in a deterministic, auditable safety envelope.
Nenad Petrovic, Oussama Jeddou, Feres Ben Fraj et al.· 0 citations
Cyber attacks are increasingly automated, narrowing the time available for human analysts to detect, reason about, and respond to intrusions. Large language models (LLMs) offer a promising foundation for autonomous cyber defense because they can correlate heterogeneous evidence and reason about previously unseen threat...
Simona Boboila, Xavier F. Cadet, Edward Koh et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.