AEGIS: White-Box Attack Path Generation using LLMs and Training Effectiveness Evaluation for Large-Scale Cyber Defence Exercises

πŸ“… 2026-01-30
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF

career value

205K/year
πŸ€– AI Summary
This work proposes a dynamic attack path generation framework that integrates large language models (LLMs), white-box system access, and Monte Carlo Tree Search (MCTS) to automatically construct and validate attack paths in real-world vulnerable environments without relying on pre-built vulnerability graphs or exploit databases. Unlike traditional cyber defense exercises that depend on manual path construction by experts, the proposed approach achieves end-to-end attack path generation without prior knowledge of the target environment, thereby shifting the expert’s role from technical validation to scenario design and significantly accelerating development cycles. Evaluated in the CIDeX 2025 exercise involving 46 hosts, the generated paths matched human-crafted scenarios in terms of pedagogical value, engagement, credibility, and challenge level, while reducing scenario development time from months to days.

Technology Category

Application Category

πŸ“ Abstract
Creating attack paths for cyber defence exercises requires substantial expert effort. Existing automation requires vulnerability graphs or exploit sets curated in advance, limiting where it can be applied. We present AEGIS, a system that generates attack paths using LLMs, white-box access, and Monte Carlo Tree Search over real exploit execution. LLM-based search discovers exploits dynamically without pre-existing vulnerability graphs, while white-box access enables validating exploits in isolation before committing to attack paths. Evaluation at CIDeX 2025, a large-scale exercise spanning 46 IT hosts, showed that AEGIS-generated paths are comparable to human-authored scenarios across four dimensions of training experience (perceived learning, engagement, believability, challenge). Results were measured with a validated questionnaire extensible to general simulation-based training. By automating exploit chain discovery and validation, AEGIS reduces scenario development from months to days, shifting expert effort from technical validation to scenario design.
Problem

Research questions and friction points this paper is trying to address.

attack path generation
cyber defence exercises
vulnerability graphs
exploit discovery
scenario development
Innovation

Methods, ideas, or system contributions that make the work stand out.

LLM-based attack path generation
white-box exploit validation
Monte Carlo Tree Search
automated cyber exercise
dynamic vulnerability discovery
πŸ”Ž Similar Papers
No similar papers found.
I
Ivan K. Tung
Cyber Defence Test and Evaluation Centre (CyTEC), The Digital and Intelligence Service (DIS), Singapore Armed Forces
Y
Yu Xiang Shi
Cyber Defence Test and Evaluation Centre (CyTEC), The Digital and Intelligence Service (DIS), Singapore Armed Forces
A
Alex Chien
Cyber Defence Test and Evaluation Centre (CyTEC), The Digital and Intelligence Service (DIS), Singapore Armed Forces
W
Wenkai Liu
Cyber Defence Test and Evaluation Centre (CyTEC), The Digital and Intelligence Service (DIS), Singapore Armed Forces
L
Lawrence Zheng
Cyber Defence Test and Evaluation Centre (CyTEC), The Digital and Intelligence Service (DIS), Singapore Armed Forces