AI-Based Vulnerability Assessment Capability and Cyber Attack Graph Analysis

📅 2026-09-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge of defending critical infrastructure against sophisticated cyber threats arising from complex, combinatorial attack surfaces. We propose an operational technology (OT) network risk assessment method that integrates multi-agent reinforcement learning with probabilistic attack graphs. The approach employs knowledge graphs and cross-validates findings using the Vortex/Crow framework alongside the Aalto model. Through hierarchical baseline evaluations and node elimination experiments, it precisely identifies critical targets such as industrial control systems, while risk quantification is achieved by comparing CVSS and IronMiner scoring metrics. Empirical analysis based on the Ukrainian power grid incident demonstrates that the proposed method successfully reproduces historical attack paths and exhibits strong scalability in large-scale networks. Ultimately, this work provides structured support for defense prioritization decisions in resource-constrained environments.
📝 Abstract
Cyber threats targeting mission-critical infrastructure are becoming more sophisticated while the barrier to launching attacks continues to fall. Traditional point solutions like antivirus and firewalls are reactive and fail to address the combinatorial complexity of modern attack surfaces. This paper presents an investigation combining two complementary methodologies: Lockheed Martin's Vortex/Crow framework, which applies multi-agent reinforcement learning (MARL) over industry-standard cyber knowledge graph to identify and prioritize attack vectors and TTPs (tactics, techniques, and procedures); and Aalto's probabilistic attack graph model that combines network topology and its vulnerabilities to compute system-level risk metrics. The 2015 Ukraine Power Grid cyberattack serves as a well-documented validation scenario. Applied independently to the same operational technology (OT) network topology, both methodologies converge on the same attack vectors and exploit sequences as those documented in the incident record, thus providing mutual cross-validation. Attack graph analyses using node-level elimination experiments identify industrial control systems (ICS) as the most critical enablers of attack propagation, representing high-priority targets for defensive hardening. Comparison of CVSS (v2.0) and IronMiner vulnerability scoring yields in general consistent results, with IronMiner providing more actionable differentiation at network periphery nodes. The layered methodology of baseline assessment and node-level elimination proves to be scalable to large enterprise networks, thus offering defenders a structured, AI-enabled path to prioritize mitigation under realistic time and resource constraints.
Problem

Research questions and friction points this paper is trying to address.

Vulnerability Assessment
Attack Graph Analysis
Cyber Threats
Critical Infrastructure
System-level Risk
Innovation

Methods, ideas, or system contributions that make the work stand out.

Multi-Agent Reinforcement Learning
Probabilistic Attack Graph
Cross-Validation
Node-Level Elimination
Operational Technology
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Joni Herttuainen
Aalto University School of Science
K
Kirsi Hellsten
Aalto University School of Science
V
Vesa Kuikka
Aalto University School of Science
A
Ambrose Kam
Lockheed Martin
A
Arlanda Johnson
Lockheed Martin
David Welsh
David Welsh
Lockheed Martin
K
Kimmo K. Kaski
Aalto University School of Science