中文
相关论文

相关论文: HARMer: Cyber-attacks Automation and Evaluation

200 篇论文

Identifying, analyzing, and evaluating cybersecurity risks are essential to assess the vulnerabilities of modern manufacturing infrastructures and to devise effective decision-making strategies to secure critical manufacturing against…

密码学与安全 · 计算机科学 2023-12-21 Md Habibor Rahman , Erfan Yazdandoost Hamedani , Young-Jun Son , Mohammed Shafae

The security of cyber-physical systems is first and foremost a safety problem, yet it is typically handled as a traditional security problem, which means that solutions are based on defending against threats and are often implemented too…

密码学与安全 · 计算机科学 2017-11-03 Bryan Carter , Georgios Bakirtzis , Carl Elks , Cody Fleming

While prior red-teaming efforts have focused on eliciting harmful text outputs from large language models (LLMs), such approaches fail to capture agent-specific vulnerabilities that emerge through multi-step tool execution, particularly in…

密码学与安全 · 计算机科学 2026-03-25 Hyomin Lee , Sangwoo Park , Yumin Choi , Sohyun An , Seanie Lee , Sung Ju Hwang

In this work we start walking the path to a new perspective for viewing cyberwarfare scenarios, by introducing conceptual tools (a formal model) to evaluate the costs of an attack, to describe the theater of operations, targets, missions,…

密码学与安全 · 计算机科学 2010-06-11 Ariel Futoransky , Luciano Notarfrancesco , Gerardo Richarte , Carlos Sarraute

Existing safety evaluation methods for large language models (LLMs) suffer from inherent limitations, including evaluator bias and detection failures arising from model homogeneity, which collectively undermine the robustness of risk…

The increasing digitization of smart grids has improved operational efficiency but also introduced new cybersecurity vulnerabilities, such as False Data Injection Attacks (FDIAs) targeting Automatic Generation Control (AGC) systems. While…

密码学与安全 · 计算机科学 2025-08-27 Muhammad Sharshar , Ahmad Mohammad Saber , Davor Svetinovic , Amr M. Youssef , Deepa Kundur , Ehab F. El-Saadany

We introduce a method for Intrusion Detection based on the classification, understanding and prediction of behavioural deviance and potential threats, issuing recommendations, and acting to address eminent issues. Our work seeks a practical…

分布式、并行与集群计算 · 计算机科学 2018-11-14 Kleber Vieira , Fernando Koch , Joao Bosco Mangueira Sobral , Carlos Becker Westphall , Jorge Lopes de Souza Leao

With the continuous improvement of attack methods, there are more and more distributed, complex, targeted attacks in which the attackers use combined attack methods to achieve the purpose. Advanced cyber attacks include multiple stages to…

密码学与安全 · 计算机科学 2021-10-26 Xiaoyu Wang , Xiaorui Gong , Lei Yu , Jian Liu

Despite advancements in machine learning for security, rule-based detection remains prevalent in Security Operations Centers due to the resource intensiveness and skill gap associated with ML solutions. While traditional rule-based methods…

密码学与安全 · 计算机科学 2025-12-10 Sadegh Momeni , Ge Zhang , Birkett Huber , Hamza Harkous , Sam Lipton , Benoit Seguin , Yanis Pavlidis

As large language models (LLMs) grow in power and influence, ensuring their safety and preventing harmful output becomes critical. Automated red teaming serves as a tool to detect security vulnerabilities in LLMs without manual labor.…

人工智能 · 计算机科学 2025-06-03 Weiyang Guo , Zesheng Shi , Zhuo Li , Yequan Wang , Xuebo Liu , Wenya Wang , Fangming Liu , Min Zhang , Jing Li

Penetration testing is the process of searching for security weaknesses by simulating an attack. It is usually performed by experienced professionals, where scanning and attack tools are applied. By automating the execution of such tools,…

密码学与安全 · 计算机科学 2024-07-23 Norman Becker , Daniel Reti , Evridiki V. Ntagiou , Marcus Wallum , Hans D. Schotten

It is important to predict any adversarial attacks and their types to enable effective defense systems. Often it is hard to label such activities as malicious ones without adequate analytical reasoning. We propose the use of Hidden Markov…

密码学与安全 · 计算机科学 2021-06-04 Shuvalaxmi Dass , Prerit Datta , Akbar Siami Namin

Automating penetration testing is crucial for enhancing cybersecurity, yet current Large Language Models (LLMs) face significant limitations in this domain, including poor error handling, inefficient reasoning, and an inability to perform…

人工智能 · 计算机科学 2025-10-30 He Kong , Die Hu , Jingguo Ge , Liangxiong Li , Hui Li , Tong Li

Power grids are becoming more digitized, resulting in new opportunities for the grid operation but also new challenges, such as new threats from the cyber-domain. To address these challenges, cybersecurity solutions are being considered in…

密码学与安全 · 计算机科学 2023-12-22 Ömer Sen , Philipp Malskorn , Simon Glomb , Immanuel Hacker , Martin Henze , Andreas Ulbig

Large Language Models (LLMs) have been used in cybersecurity such as autonomous security analysis or penetration testing. Capture the Flag (CTF) challenges serve as benchmarks to assess automated task-planning abilities of LLM agents for…

While penetration testing plays a vital role in cybersecurity, achieving fully automated, hands-off-the-keyboard execution remains a significant research challenge. In this paper, we introduce the "Planner-Executor-Perceptor (PEP)" design…

密码学与安全 · 计算机科学 2025-12-15 Lingzhi Wang , Xinyi Shi , Ziyu Li , Yi Jiang , Shiyu Tan , Yuhao Jiang , Junjie Cheng , Wenyuan Chen , Xiangmin Shen , Zhenyuan LI , Yan Chen

Network Intrusion Detection (NID) systems can benefit from Machine Learning (ML) models to detect complex cyber-attacks. However, to train them with a great amount of high-quality data, it is necessary to perform reliable simulations of…

密码学与安全 · 计算机科学 2024-12-03 Tiago Dias , João Vitorino , Eva Maia , Isabel Praça

We expect an increase in the frequency and severity of cyber-attacks that comes along with the need for efficient security countermeasures. The process of attributing a cyber-attack helps to construct efficient and targeted mitigating and…

密码学与安全 · 计算机科学 2020-01-22 Erisa Karafili , Linna Wang , Emil C. Lupu

Industrial control systems (ICS) of critical infrastructure are increasingly connected to the Internet for remote site management at scale. However, cyber attacks against ICS - especially at the communication channels between humanmachine…

密码学与安全 · 计算机科学 2021-01-29 Taejun Choi , Guangdong Bai , Ryan K L Ko , Naipeng Dong , Wenlu Zhang , Shunyao Wang

Techniques for verifying or invalidating the security of computer systems have come a long way in recent years. Extremely sophisticated tools are available to specify and formally verify the behavior of a system and, at the same time,…

密码学与安全 · 计算机科学 2024-04-16 Matteo Busi , Riccardo Focardi , Flaminia Luccio