7 papers
Synthetic APTs: the Collapse of TTP-Based Attribution
Francesco Balassone, VÃctor Mayoral-Vilches, MarÃa Sanz-Gómez +8
Cyber Threat Intelligence CTI attribution relies on identifying the Tactics, Techniques, and Procedures TTPs that distinguish one threat actor from another. This approach presuppos…
Security Incentivization: An Empirical Study of how Micropayments Impact Code Security
Stefan Rass, Martin Pinzger, Rainer W. Alexandrowicz +5
Security often receives insufficient developer attention because it does not directly generate visible value, leading to underinvestment in practice. We evaluate a countermeasure b…
Towards Cybersecurity Superintelligence: from AI-guided humans to human-guided AI
VÃctor Mayoral-Vilches, Stefan Rass, Martin Pinzger +14
Cybersecurity superintelligence -- artificial intelligence exceeding the best human capability in both speed and strategic reasoning -- represents the next frontier in security. Th…
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense
VÃctor Mayoral-Vilches, MarÃa Sanz-Gómez, Francesco Balassone +6
AI-driven penetration testing now executes thousands of actions per hour but still lacks the strategic intuition humans apply in competitive security. To build cybersecurity superi…
Cybersecurity AI: Evaluating Agentic Cybersecurity in Attack/Defense CTFs
Francesco Balassone, VÃctor Mayoral-Vilches, Stefan Rass +4
We empirically evaluate whether AI systems are more effective at attacking or defending in cybersecurity. Using CAI (Cybersecurity AI)'s parallel execution framework, we deployed a…
Koney: A Cyber Deception Orchestration Framework for Kubernetes
Mario Kahlhofer, Matteo Golinelli, Stefan Rass
System operators responsible for protecting software applications remain hesitant to implement cyber deception technology, including methods that place traps to catch attackers, de…