10 papers
SherAgent: Scaling Attack Investigation in the Wild via LLM-Empowered Iterative Query-Filter Backtracking
Zhenyuan Li, Zhengkai Wang, Ling Jiang +5
Provenance-based attack investigation enables viable automation by standardizing data and query logic; however, it is critically hindered in practice by dependency explosions and f…
Minos: A Multi-Agent Collaborative Framework for Provenance-Based Backward Tracking
Jiahui Wang, Zhenyuan Li, Zhengkai Wang +2
Sophisticated cyber attacks, particularly Advanced Persistent Threats (APTs), require effective post-intrusion forensic analysis. Provenance-based backward tracking reconstructs at…
Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems
Qizhi Cai, Yangyang Wei, Yijie Xu +4
Agentic systems increasingly orchestrate complex, tool-using workflows within agentic execution environments, where high-level goals and tool invocations at the application layer m…
From Sands to Mansions: Towards Automated Cyberattack Emulation with Classical Planning and Large Language Models
Lingzhi Wang, Zhenyuan Li, Yi Jiang +4
Evolving attacker capabilities demand realistic and continuously updated cyberattack emulation for threat-informed defense and security benchmarking. Towards automated attack emula…
AEAS: Actionable Exploit Assessment System
Xiangmin Shen, Wenyuan Cheng, Yan Chen +6
Security practitioners face growing challenges in exploit assessment, as public vulnerability repositories are increasingly populated with inconsistent and low-quality exploit arti…
PentestAgent: Incorporating LLM Agents to Automated Penetration Testing
Xiangmin Shen, Lingzhi Wang, Zhenyuan Li +5
Penetration testing is a critical technique for identifying security vulnerabilities, traditionally performed manually by skilled security specialists. This complex process involve…