• Skip to content (access key 1)
  • Skip to search (access key 7)
FWF — Austrian Science Fund
  • Go to overview page Discover

    • Research Radar
      • Research Radar Archives 1974–1994
      • Open API
    • Discoveries
      • Emmanuelle Charpentier
      • Adrian Constantin
      • Monika Henzinger
      • Ferenc Krausz
      • Wolfgang Lutz
      • Walter Pohl
      • Christa Schleper
      • Elly Tanaka
      • Anton Zeilinger
    • Impact Stories
      • Ruth Breu
      • Verena Gassner
      • Wolfgang Lechner
      • Birgit Mitter
      • Oliver Spadiut
      • Georg Winter
    • scilog Magazine
    • Austrian Science Awards
      • FWF Wittgenstein Awards
      • FWF ASTRA Awards
      • FWF START Awards
      • Award Ceremony
    • excellent=austria
      • Clusters of Excellence
      • Emerging Fields
    • In the Spotlight
      • Elise Richter Program
      • 40 Years of Erwin Schrödinger Fellowships
      • Quantum Austria
    • Dialogs and Talks
      • think.beyond Summit
    • Knowledge Transfer Events
    • E-Book Library
  • Go to overview page Funding

    • Portfolio
      • excellent=austria
        • Clusters of Excellence
        • Emerging Fields
      • Projects
        • Principal Investigator Projects
        • Principal Investigator Projects International
        • Clinical Research
        • 1000 Ideas
        • Arts-Based Research
        • FWF Wittgenstein Award
      • Careers
        • ESPRIT
        • FWF ASTRA Awards
        • Erwin Schrödinger
        • doc.funds
        • doc.funds.connect
      • Collaborations
        • Specialized Research Groups
        • Special Research Areas
        • International – Multilateral Initiatives
        • #ConnectingMinds
      • Communication
        • Top Citizen Science
        • Science Communication
        • Book Publications
        • Digital Publications
        • Open-Access Block Grant
      • Subject-Specific Funding
        • Belmont Forum
        • ERA-NET HERA
        • ERA-NET NORFACE
        • ERA-NET QuantERA
        • Alternative Methods to Animal Testing
        • European Partnership BE READY
        • European Partnership Biodiversa+
        • European Partnership BrainHealth
        • European Partnership ERA4Health
        • European Partnership ERDERA
        • European Partnership EUPAHW
        • European Partnership FutureFoodS
        • European Partnership OHAMR
        • European Partnership PerMed
        • European Partnership Water4All
        • Gottfried and Vera Weiss Award
        • LUKE – Ukraine
        • netidee SCIENCE
        • Herzfelder Foundation Projects
        • Quantum Austria
        • Rückenwind Funding Bonus
        • TRANSCAN
        • WE&ME Award
        • Zero Emissions Award
      • International Collaborations
        • Belgium/Flanders
        • Germany
        • France
        • Israel
        • Italy/South Tyrol
        • Japan
        • Korea
        • Luxembourg
        • Poland
        • Switzerland
        • Slovakia
        • Slovenia
        • Taiwan
        • Tyrol-South Tyrol-Trentino
        • Czech Republic
        • Hungary
    • Step by Step
      • Find Funding
      • Submitting Your Application
      • International Peer Review
      • Funding Decisions
      • Carrying out Your Project
      • Closing Your Project
      • Further Information
        • Integrity and Ethics
        • Inclusion
        • Applying from Abroad
        • Personnel Costs
        • PROFI
        • Final Project Reports
        • Final Project Report Survey
    • FAQ
      • Project Phase PROFI
      • Project Phase Ad Personam
      • Expiring Programs
        • Elise Richter and Elise Richter PEEK
        • FWF START Awards
        • Research Groups
        • AI Mission Austria
  • Go to overview page About Us

    • Mission Statement
    • FWF Video
    • Values
    • Facts and Figures
    • Annual Report
    • What We Do
      • Research Funding
        • Matching Funds Initiative
      • International Collaborations
      • Studies and Publications
      • Equal Opportunities and Diversity
        • Objectives and Principles
        • Measures
        • Creating Awareness of Bias in the Review Process
        • Terms and Definitions
        • Your Career in Cutting-Edge Research
      • Open Science
        • Open-Access Policy
          • Open-Access Policy for Peer-Reviewed Publications
          • Open-Access Policy for Peer-Reviewed Book Publications
          • Open-Access Policy for Research Data
        • Research Data Management
        • Citizen Science
        • Open Science Infrastructures
        • Open Science Funding
      • Evaluations and Quality Assurance
      • Academic Integrity
      • Science Communication
      • Philanthropy
      • Sustainability
    • History
    • Legal Basis
    • Organization
      • Executive Bodies
        • Executive Board
        • Supervisory Board
        • Assembly of Delegates
        • Scientific Board
        • Juries
      • FWF Office
    • Jobs at FWF
  • Go to overview page News

    • News
    • Press
      • Logos
    • Calendar
      • Post an Event
      • FWF Informational Events
    • Job Openings
      • Enter Job Opening
    • Newsletter
  • Discovering
    what
    matters.

    FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

    SOCIAL MEDIA

    • LinkedIn, external URL, opens in a new window
    • , external URL, opens in a new window
    • Facebook, external URL, opens in a new window
    • Instagram, external URL, opens in a new window
    • YouTube, external URL, opens in a new window

    SCILOG

    • Scilog — The science magazine of the Austrian Science Fund (FWF)
  • elane login, external URL, opens in a new window
  • Scilog external URL, opens in a new window
  • de Wechsle zu Deutsch

  

Inference of Optimal Cyber Defense Strategies

Sebastian Schrittwieser (ORCID: 0000-0003-2115-2022)
  • Grant DOI 10.55776/P33656
  • Funding program Principal Investigator Projects
  • Status Ended
  • Start October 1, 2020
  • End March 31, 2025
  • Funding amount € 340,199

Disciplines

Computer Sciences (100%)

Keywords

  • Security Model,
  • Serious Game,
  • Intrusion Detection,
  • Model Checking,
  • Reinforcement Learning,
  • Decision Support
Abstract Final report

It is becoming increasingly difficult to plan and implement an organization`s defense against the wide range and variety of todays cyber-threats. Current detection and mitigation systems offer little in terms of attack interpretation, which would help to better understand attacker motivations and objectives. Few existing threat models provide a means to map concrete system events as captured by intrusion detection systems (IDS) to a description, known system flaw, or definitive countermeasure. The questions of how specific attack techniques enable hostile actors of varying skill and motivation to achieve their malicious objectives and of which attack strategies/vectors can be considered the most dangerous for a given infrastructure are not comprehensively answered. In short, there is a distinct lack of models that are able to deal with the increasing complexity of cyber-attacks, which is a major obstacle to automated attack (risk) assessment, intrusion detection, and security testing. These challenges will be addressed by our proposed project. Researching the inference of cyber defense strategies through reinforced threat modelling, INODES focuses on methods of simulating attacker/defender behavior through the means of a strategy game that does not only consider the technical aspects of cyber-defense, but also actor motivation, assets deployed, and various organizational factors. By researching the application of both model checking and reinforcement learning techniques to our newly created model, we will be able to play through a wide range of possible attacks, thereby inferring optimal defender strategies that minimize the adversarys probability of success as well as the impact on an affected system. Using INODES, we seek to provide organizations with the foundation for a new and automated way of planning and testing their cyber-defense. At the same time, we work to bridge the gap between monitoring data and attack semantics by mapping IDS records directly to the model. This helps analysts and security operators by providing them with a short explanation about possible ongoing attacks and how they might be mitigated. INODES merges the domains of threat modeling, IT management and data analysis into one integrated concept. To facilitate this multifaceted approach, our research team is comprised of security experts with background in formal methods, machine learning, security management, digital forensics, as well as APT mitigation.

The INODES project set out to improve how cyber-attacks and defenses can be modeled, analyzed, and understood. Many current approaches in cybersecurity focus on detection and mitigation but lack the ability to explain attacker objectives or evaluate the effectiveness of defense strategies in a structured way. To address this, we developed a formal model that represents cyber-attacks as strategic interactions between attackers and defenders. The model goes beyond purely technical aspects by also incorporating factors such as attacker motivation, system assets, and organizational context. This allows for a more comprehensive understanding of how and why certain attacks succeed, and what defensive strategies can be effective under different conditions. We applied techniques from reinforcement learning and model checking to simulate various attack scenarios. Notably, we built our own reinforcement learning framework, PenQuestEnv, which serves as a training environment for the gamified model. PenQuestEnv allows agents to learn defensive (and offensive) strategies in varied game scenarios. These simulations were used to analyze the success rates of attacks, the cost and impact of various defense strategies, and the conditions under which specific defenses are most effective. The resulting data supports a more systematic and reproducible approach to security planning, testing, and evaluation. A key research output of the project is PenQuest, a gamified version of the INODES model. PenQuest abstracts the formal framework into an interactive format that makes it accessible for experimentation and learning. It has been used in educational and outreach contexts, including events with schools, university courses, and business audiences. The game is based on the same strategic principles as the formal model and serves both as a communication tool and a way to test the model's assumptions in practice. Throughout the project, we exchanged ideas and discussed research approaches with the ALFA group at Massachusetts Institute of Technology (MIT), focusing on topics such as agent-based systems and machine learning. Mutual lab visits during the project period supported this collaboration and encouraged ongoing academic exchange. In summary, INODES combines insights from threat modeling, formal methods, reinforcement learning, and cyber defense strategy. Its main result is a structured, analyzable framework for simulating and evaluating cyber-attacks and defensive responses. The model and its practical implementation PenQuest offer a foundation for more rigorous and explainable cybersecurity analysis.

Research institution(s)
  • Universität Wien - 100%
Project participants
  • Andreas Holzinger, Universität für Bodenkultur Wien , national collaboration partner
International project participants
  • Helge Janicke, Edith Cowan University - Australia
  • Jungwoo Ryoo, The Pennsylvania State University - USA

Research Output

  • 20 Citations
  • 9 Publications
  • 3 Datasets & models
  • 1 Software
  • 12 Disseminations
  • 4 Scientific Awards
  • 1 Fundings
Publications
  • 2025
    Title Gamifying information security: Adversarial risk exploration for IT/OT infrastructures
    DOI 10.1016/j.cose.2024.104287
    Type Journal Article
    Author Luh R
    Journal Computers & Security
    Pages 104287
    Link Publication
  • 2025
    Title PenQuestEnv: A Reinforcement Learning Environment for Cyber Security
    DOI 10.5220/0013122700003899
    Type Conference Proceeding Abstract
    Author Eresheim S
    Pages 217-224
  • 2023
    Title Enhancing Trust in Machine Learning Systems by Formal Methods
    DOI 10.1007/978-3-031-40837-3_11
    Type Book Chapter
    Author Tavolato-Wötzl C
    Publisher Springer Nature
    Pages 170-187
    Link Publication
  • 2023
    Title Standing Still Is Not an Option: Alternative Baselines for Attainable Utility Preservation
    DOI 10.1007/978-3-031-40837-3_15
    Type Book Chapter
    Author Eresheim S
    Publisher Springer Nature
    Pages 239-257
    Link Publication
  • 2023
    Title A Game Theoretic Analysis of Cyber Threats
    DOI 10.5220/0011792700003405
    Type Conference Proceeding Abstract
    Author Tavolato P
    Pages 706-713
    Link Publication
  • 2024
    Title Quantifying the Odds in Real World Attack Scenarios
    DOI 10.1109/csr61664.2024.10679461
    Type Conference Proceeding Abstract
    Author Tavolato P
    Pages 845-852
  • 2024
    Title Comparing the Effectivity of Planned Cyber Defense Controls in Order to Support the Selection Process
    DOI 10.5220/0012421800003648
    Type Conference Proceeding Abstract
    Author Tavolato P
    Pages 211-218
    Link Publication
  • 2022
    Title Formalizing Real-world Threat Scenarios
    DOI 10.5220/0010781300003120
    Type Conference Proceeding Abstract
    Author Tavolato P
    Pages 281-289
    Link Publication
  • 2022
    Title PenQuest Reloaded: A Digital Cyber Defense Game for Technical Education
    DOI 10.1109/educon52537.2022.9766700
    Type Conference Proceeding Abstract
    Author Luh R
    Pages 906-914
Datasets & models
  • 2025 Link
    Title Foundation model
    DOI 10.5281/zenodo.16422965
    Type Computer model/algorithm
    Public Access
    Link Link
  • 2025 Link
    Title PenQuestEnv
    Type Computer model/algorithm
    Public Access
    Link Link
  • 2025 Link
    Title Probabilistic Security Models for Attack Scenarios
    DOI 10.5281/zenodo.16621253
    Type Computer model/algorithm
    Public Access
    Link Link
Software
  • 2023 Link
    Title PenQuest
    Link Link
Disseminations
  • 2021
    Title Talk at OCG Think Tank
    Type A talk or presentation
  • 2020 Link
    Title PenQuest Website
    Type Engagement focused website, blog or social media channel
    Link Link
  • 2022 Link
    Title sec4dev
    Type Participation in an activity, workshop or similar
    Link Link
  • 2022
    Title Workshop at UIIN Unlock
    Type Participation in an activity, workshop or similar
  • 2022
    Title N'Cyan Workshop
    Type Participation in an activity, workshop or similar
  • 2020
    Title PenQuest Newsletter
    Type A magazine, newsletter or online publication
  • 2021 Link
    Title ITsecX
    Type Participation in an activity, workshop or similar
    Link Link
  • 2021
    Title Seminar at the University of Luxemburg
    Type Participation in an activity, workshop or similar
  • 2022
    Title Guest talk at Reykjavík University
    Type A talk or presentation
  • 2021
    Title Invited talk at MIT
    Type A talk or presentation
  • 2022
    Title Workshop at LSZ congress
    Type Participation in an activity, workshop or similar
  • 2022 Link
    Title IKT Sicherheitskonferenz
    Type Participation in an activity, workshop or similar
    Link Link
Scientific Awards
  • 2025
    Title Visiting staff (Prof. Francesco Mercaldo)
    Type Attracted visiting staff or user to your research group
    Level of Recognition Continental/International
  • 2024
    Title ERCIM News
    Type Appointed as the editor/advisor to a journal or book series
    Level of Recognition Continental/International
  • 2021
    Title Keynote at ICSSA 2021
    Type Personally asked as a key note speaker to a conference
    Level of Recognition Continental/International
  • 2023
    Title Guest Editor Computer & Security
    Type Appointed as the editor/advisor to a journal or book series
    DOI 10.1016/j.cose.2023.103662
    Level of Recognition Continental/International
Fundings
  • 2024
    Title Christian Doppler Laboratory AsTra
    Type Research grant (including intramural programme)
    Start of Funding 2024
    Funder Christian Doppler Research Association

Discovering
what
matters.

Newsletter

FWF-Newsletter Press-Newsletter Calendar-Newsletter Job-Newsletter scilog-Newsletter

Contact

Austrian Science Fund (FWF)
Georg-Coch-Platz 2
(Entrance Wiesingerstraße 4)
1010 Vienna

office(at)fwf.ac.at
+43 1 505 67 40

General information

  • Job Openings
  • Jobs at FWF
  • Press
  • Philanthropy
  • scilog
  • FWF Office
  • Social Media Directory
  • LinkedIn, external URL, opens in a new window
  • , external URL, opens in a new window
  • Facebook, external URL, opens in a new window
  • Instagram, external URL, opens in a new window
  • YouTube, external URL, opens in a new window
  • Cookies
  • Whistleblowing/Complaints Management
  • Accessibility Statement
  • Data Protection
  • IFG-Form
  • Acknowledgements
  • © Österreichischer Wissenschaftsfonds FWF
© Österreichischer Wissenschaftsfonds FWF