SPEAR: Security Posture Evaluation using AI Planner-Reasoning on Attack-Connectivity Hypergraphs
Podder, Rakesh, Caglar, Turgay, Bashir, Shadaab Kawnain, Sreedharan, Sarath, Ray, Indrajit, Ray, Indrakshi
–arXiv.org Artificial Intelligence
Graph-based frameworks are often used in network hardening to help a cyber defender understand how a network can be attacked and how the best defenses can be deployed. However, incorporating network connectivity parameters in the attack graph, reasoning about the attack graph when we do not have access to complete information, providing system administrator suggestions in an understandable format, and allowing them to do what-if analysis on various scenarios and attacker motives is still missing. We fill this gap by presenting SPEAR, a formal framework with tool support for security posture evaluation and analysis that keeps human-in-the-loop. SPEAR uses the causal formalism of AI planning to model vulnerabilities and configurations in a networked system. It automatically converts network configurations and vulnerability descriptions into planning models expressed in the Planning Domain Definition Language (PDDL). SPEAR identifies a set of diverse security hardening strategies that can be presented in a manner understandable to the domain expert. These allow the administrator to explore the network hardening solution space in a systematic fashion and help evaluate the impact and compare the different solutions.
arXiv.org Artificial Intelligence
Jun-3-2025
- Country:
- Europe
- Austria
- Burgenland > Eisenstadt (0.04)
- Vienna (0.14)
- France (0.04)
- Germany > Bavaria
- Upper Bavaria > Munich (0.04)
- Iceland > Capital Region
- Reykjavik (0.04)
- Poland > Lower Silesia Province
- Wroclaw (0.04)
- Austria
- North America
- Canada > Ontario
- Toronto (0.04)
- United States
- Colorado > Larimer County
- Fort Collins (0.04)
- Maryland
- Baltimore (0.04)
- Prince George's County > College Park (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- New York
- New York County > New York City (0.04)
- Suffolk County > Stony Brook (0.05)
- South Carolina > Charleston County
- Charleston (0.04)
- Virginia > Albemarle County
- Charlottesville (0.04)
- Colorado > Larimer County
- Canada > Ontario
- Europe
- Genre:
- Research Report (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: