6 papers
Breaking Ambient Trust: In-Network Per-Process Access Control Against Lateral Movement
Osama Bajaber, Bo Ji, Peng Gao
Enterprise networks remain vulnerable to Advanced Persistent Threats (APTs), where adversaries gain an initial foothold and move laterally across the network, accumulating access p…
BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence
Changze Li, Yutong Cheng, Tsania Camila Finnisa +3
Cyber threat intelligence (CTI) is foundational to modern cyber defense, yet much of it resides in unstructured reports whose volume and heterogeneity far exceed manual analysis, m…
AgentFlow: A Flow-Centric Policy Language and Framework for Securing LLM Agent Systems
Basavesh Ammanaghatta Shivakumar, Swarn Priya, Peng Gao
LLM agents increasingly read untrusted content, invoke external tools, access private data, and delegate work to other agents. Harm often arises not from a single unsafe action but…
CTIFoundry: An Agent-Native Corpus Scaffold for Cyber Threat Intelligence
Yutong Cheng, Changze Li, Qian Cui +4
Cyber threat intelligence (CTI) is increasingly consumed not by human analysts but by LLM agents that compose multi-step investigations at query time. The harness side of this shif…
eMicro: Real-Time Multi-Hop Access Control for Microservices with eBPF
Rizky Ramadhana Putra, Osama Bajaber, Saimon Amanuel Tsegai +4
Modern cloud applications often comprise thousands of microservices whose interactions form complex request paths. Traditional inter-service access control restricts individual ser…
CTINexus: Automatic Cyber Threat Intelligence Knowledge Graph Construction Using Large Language Models
Yutong Cheng, Osama Bajaber, Saimon Amanuel Tsegai +2
Textual descriptions in cyber threat intelligence (CTI) reports, such as security articles and news, are rich sources of knowledge about cyber threats, crucial for organizations to…