Inference of Optimal Cyber Defense Strategies
Disciplines
Computer Sciences (100%)
Keywords
- Security Model,
- Serious Game,
- Intrusion Detection,
- Model Checking,
- Reinforcement Learning,
- Decision Support
It is becoming increasingly difficult to plan and implement an organization`s defense against the wide range and variety of todays cyber-threats. Current detection and mitigation systems offer little in terms of attack interpretation, which would help to better understand attacker motivations and objectives. Few existing threat models provide a means to map concrete system events as captured by intrusion detection systems (IDS) to a description, known system flaw, or definitive countermeasure. The questions of how specific attack techniques enable hostile actors of varying skill and motivation to achieve their malicious objectives and of which attack strategies/vectors can be considered the most dangerous for a given infrastructure are not comprehensively answered. In short, there is a distinct lack of models that are able to deal with the increasing complexity of cyber-attacks, which is a major obstacle to automated attack (risk) assessment, intrusion detection, and security testing. These challenges will be addressed by our proposed project. Researching the inference of cyber defense strategies through reinforced threat modelling, INODES focuses on methods of simulating attacker/defender behavior through the means of a strategy game that does not only consider the technical aspects of cyber-defense, but also actor motivation, assets deployed, and various organizational factors. By researching the application of both model checking and reinforcement learning techniques to our newly created model, we will be able to play through a wide range of possible attacks, thereby inferring optimal defender strategies that minimize the adversarys probability of success as well as the impact on an affected system. Using INODES, we seek to provide organizations with the foundation for a new and automated way of planning and testing their cyber-defense. At the same time, we work to bridge the gap between monitoring data and attack semantics by mapping IDS records directly to the model. This helps analysts and security operators by providing them with a short explanation about possible ongoing attacks and how they might be mitigated. INODES merges the domains of threat modeling, IT management and data analysis into one integrated concept. To facilitate this multifaceted approach, our research team is comprised of security experts with background in formal methods, machine learning, security management, digital forensics, as well as APT mitigation.
The INODES project set out to improve how cyber-attacks and defenses can be modeled, analyzed, and understood. Many current approaches in cybersecurity focus on detection and mitigation but lack the ability to explain attacker objectives or evaluate the effectiveness of defense strategies in a structured way. To address this, we developed a formal model that represents cyber-attacks as strategic interactions between attackers and defenders. The model goes beyond purely technical aspects by also incorporating factors such as attacker motivation, system assets, and organizational context. This allows for a more comprehensive understanding of how and why certain attacks succeed, and what defensive strategies can be effective under different conditions. We applied techniques from reinforcement learning and model checking to simulate various attack scenarios. Notably, we built our own reinforcement learning framework, PenQuestEnv, which serves as a training environment for the gamified model. PenQuestEnv allows agents to learn defensive (and offensive) strategies in varied game scenarios. These simulations were used to analyze the success rates of attacks, the cost and impact of various defense strategies, and the conditions under which specific defenses are most effective. The resulting data supports a more systematic and reproducible approach to security planning, testing, and evaluation. A key research output of the project is PenQuest, a gamified version of the INODES model. PenQuest abstracts the formal framework into an interactive format that makes it accessible for experimentation and learning. It has been used in educational and outreach contexts, including events with schools, university courses, and business audiences. The game is based on the same strategic principles as the formal model and serves both as a communication tool and a way to test the model's assumptions in practice. Throughout the project, we exchanged ideas and discussed research approaches with the ALFA group at Massachusetts Institute of Technology (MIT), focusing on topics such as agent-based systems and machine learning. Mutual lab visits during the project period supported this collaboration and encouraged ongoing academic exchange. In summary, INODES combines insights from threat modeling, formal methods, reinforcement learning, and cyber defense strategy. Its main result is a structured, analyzable framework for simulating and evaluating cyber-attacks and defensive responses. The model and its practical implementation PenQuest offer a foundation for more rigorous and explainable cybersecurity analysis.
- Universität Wien - 100%
- Andreas Holzinger, Universität für Bodenkultur Wien , national collaboration partner
- Helge Janicke, Edith Cowan University - Australia
- Jungwoo Ryoo, The Pennsylvania State University - USA
Research Output
- 20 Citations
- 9 Publications
- 3 Datasets & models
- 1 Software
- 12 Disseminations
- 4 Scientific Awards
- 1 Fundings
-
2025
Title Gamifying information security: Adversarial risk exploration for IT/OT infrastructures DOI 10.1016/j.cose.2024.104287 Type Journal Article Author Luh R Journal Computers & Security Pages 104287 Link Publication -
2025
Title PenQuestEnv: A Reinforcement Learning Environment for Cyber Security DOI 10.5220/0013122700003899 Type Conference Proceeding Abstract Author Eresheim S Pages 217-224 -
2023
Title Enhancing Trust in Machine Learning Systems by Formal Methods DOI 10.1007/978-3-031-40837-3_11 Type Book Chapter Author Tavolato-Wötzl C Publisher Springer Nature Pages 170-187 Link Publication -
2023
Title Standing Still Is Not an Option: Alternative Baselines for Attainable Utility Preservation DOI 10.1007/978-3-031-40837-3_15 Type Book Chapter Author Eresheim S Publisher Springer Nature Pages 239-257 Link Publication -
2023
Title A Game Theoretic Analysis of Cyber Threats DOI 10.5220/0011792700003405 Type Conference Proceeding Abstract Author Tavolato P Pages 706-713 Link Publication -
2024
Title Quantifying the Odds in Real World Attack Scenarios DOI 10.1109/csr61664.2024.10679461 Type Conference Proceeding Abstract Author Tavolato P Pages 845-852 -
2024
Title Comparing the Effectivity of Planned Cyber Defense Controls in Order to Support the Selection Process DOI 10.5220/0012421800003648 Type Conference Proceeding Abstract Author Tavolato P Pages 211-218 Link Publication -
2022
Title Formalizing Real-world Threat Scenarios DOI 10.5220/0010781300003120 Type Conference Proceeding Abstract Author Tavolato P Pages 281-289 Link Publication -
2022
Title PenQuest Reloaded: A Digital Cyber Defense Game for Technical Education DOI 10.1109/educon52537.2022.9766700 Type Conference Proceeding Abstract Author Luh R Pages 906-914
-
2025
Link
Title Foundation model DOI 10.5281/zenodo.16422965 Type Computer model/algorithm Public Access Link Link -
2025
Link
Title PenQuestEnv Type Computer model/algorithm Public Access Link Link -
2025
Link
Title Probabilistic Security Models for Attack Scenarios DOI 10.5281/zenodo.16621253 Type Computer model/algorithm Public Access Link Link
-
2021
Title Talk at OCG Think Tank Type A talk or presentation -
2020
Link
Title PenQuest Website Type Engagement focused website, blog or social media channel Link Link -
2022
Link
Title sec4dev Type Participation in an activity, workshop or similar Link Link -
2022
Title Workshop at UIIN Unlock Type Participation in an activity, workshop or similar -
2022
Title N'Cyan Workshop Type Participation in an activity, workshop or similar -
2020
Title PenQuest Newsletter Type A magazine, newsletter or online publication -
2021
Link
Title ITsecX Type Participation in an activity, workshop or similar Link Link -
2021
Title Seminar at the University of Luxemburg Type Participation in an activity, workshop or similar -
2022
Title Guest talk at Reykjavík University Type A talk or presentation -
2021
Title Invited talk at MIT Type A talk or presentation -
2022
Title Workshop at LSZ congress Type Participation in an activity, workshop or similar -
2022
Link
Title IKT Sicherheitskonferenz Type Participation in an activity, workshop or similar Link Link
-
2025
Title Visiting staff (Prof. Francesco Mercaldo) Type Attracted visiting staff or user to your research group Level of Recognition Continental/International -
2024
Title ERCIM News Type Appointed as the editor/advisor to a journal or book series Level of Recognition Continental/International -
2021
Title Keynote at ICSSA 2021 Type Personally asked as a key note speaker to a conference Level of Recognition Continental/International -
2023
Title Guest Editor Computer & Security Type Appointed as the editor/advisor to a journal or book series DOI 10.1016/j.cose.2023.103662 Level of Recognition Continental/International
-
2024
Title Christian Doppler Laboratory AsTra Type Research grant (including intramural programme) Start of Funding 2024 Funder Christian Doppler Research Association