defense-in-depth design

Designs, builds, and analyzes layered protective architectures and engineering practices that combine multiple independent controls—technical, procedural, and physical—to prevent, detect, and mitigate faults, attacks, and failures across system components and the system lifecycle. Work includes specifying overlapping controls and trust boundaries, integrating monitoring and incident response, modeling failure modes and inter-layer dependencies, and evaluating residual risk and escalation paths.

defense-in-depthdesign

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
-0.05
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$176K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Safety and Security Risk Mitigation in Satellite Missions via Attack-Fault-Defense Trees

Apr 01, 2025
RS
Reza Soltani
🏛️ University of Twente | Ascentio Technologies S.A. | Radboud University

To address cascading risks arising from the fragmentation of security, functional safety, and defensive mechanisms in mission-critical satellite ground-segment systems, this paper proposes the Attack-Fault-Defense Tree (AFDT)—a unified modeling framework that integrates attack trees, fault trees, and defense strategies for cross-domain collaborative modeling and qualitative risk root-cause analysis. AFDT formally captures the coupling mechanisms among adversarial attacks, system faults, and defensive actions, identifying six critical cascading vulnerability paths and proposing twelve synergistic hardening measures. Experimental evaluation demonstrates that the AFDT-based approach significantly enhances system resilience and reliability under concurrent malicious attacks and stochastic failures. The framework provides a scalable analytical paradigm and practical engineering support for resilient design of space–ground integrated information systems.

Enhancing resilience in cyber-physical satellite systemsIntegrating safety security defense satellite missionsMitigating risks via Attack-Fault-Defense Tree framework

This study addresses the inadequacy of current IT compliance–oriented cybersecurity policies in safeguarding the physical safety of cyber-physical systems, as digital failures often precipitate real-world harm. By coding 292 critical infrastructure policies (2000–2025) and aligning them with the NIST SP 800-160 Vol. 2 resilience lifecycle, the research reveals a significant misalignment between prevailing policy approaches—overreliant on IT control catalogs during resistance and recovery phases—and actual physical risks. The work proposes a modernized “duty of reasonable care” standard centered on hazard-specific traceability, structured assurance cases, and cyber resilience engineering. It identifies three critical disconnects: misaligned delegation of standards, reduction of recovery mechanisms to mere incident reporting, and uneven sectoral adaptability. The study further outlines a viable pathway for federal policy that integrates engineering implementation with targeted incentives.

critical infrastructurecyber safetycyber-physical systems

The convergence of AI and cloud computing in critical cyber-physical systems introduces cross-layer attack risks, yet existing security and governance frameworks lack lifecycle-wide coordination. This work proposes a unified security architecture spanning data, models, and runtime environments, introducing a novel threat taxonomy grounded in attacker capability tiers. By integrating standards including NIST AI RMF, MITRE ATLAS, OWASP AI Exchange, CSA MAESTRO, and NERC CIP, the framework enables automated, coordinated defense mechanisms. Demonstrated in the Grid-Guard case study for power transmission, the architecture is the first to simultaneously satisfy AI governance, adversarial robustness, agent safety, and industrial compliance requirements within a single cloud-native platform, successfully mitigating multi-layered physical-financial manipulation attacks.

AI-Cloud ConvergenceCross-layer AttacksCyber-Physical Infrastructure

MISSION AWARE: Evidence-Based, Mission-Centric Cybersecurity Analysis

Dec 05, 2017
GB
Georgios Bakirtzis
🏛️ Télécom Paris | Institut Polytechnique de Paris | University of Virginia | Iowa State University | Virginia Commonwealth University

Traditional perimeter-based defenses fail against advanced persistent threats (APTs), compromising mission continuity. Method: This paper proposes a mission-success-oriented cybersecurity analysis framework. It introduces a novel hierarchical modeling approach integrating mission requirements, functional behaviors, and system architecture, supported by structured requirement elicitation, HAZOP hazard analysis, SysML modeling, and evidence-chain traceability to quantify attack impact pathways on mission objectives. Contribution/Results: The framework enables a paradigm shift from tactical defense to strategic resilience assessment, significantly improving identification accuracy of critical mission components and efficiency of protective resource allocation. Its capability for interpretable, impact-path modeling under APT scenarios is empirically validated across multiple defense information system prototypes.

It identifies components whose compromise destabilizes mission objectivesMission Aware addresses cyber-physical attacks on mission-critical systemsThe approach prioritizes vulnerabilities impacting mission requirements and assets

Latest Papers

What's happening recently
View more

This work addresses the challenge of identifying and prioritizing multi-step attack paths in industrial control systems (ICS). The authors propose a semi-automated approach that integrates network topology and vulnerability data to construct a system model, and for the first time apply state-aware attack graph generation to a Siemens PCS7 water treatment plant blueprint. Leveraging a state-aware traversal algorithm, the method derives multi-step attack chains driven by CVEs and misconfigurations, enabling visualization of critical attack paths. Experimental results demonstrate that a single point of failure can compromise network segmentation, while remediation of key vulnerabilities effectively protects entire security zones. These findings offer actionable security insights for ICS risk mitigation.

attack pathscritical infrastructureIndustrial Control Systems

This work addresses the security risks propagated across stages in multi-stage workflows involving large language model (LLM) agents, a challenge inadequately handled by existing approaches that focus on isolated stages without holistic coordination. To bridge this gap, the authors introduce the abstraction of Stage-Specific Safety Skills, which modularizes heterogeneous safety mechanisms into reusable and composable components. They further develop an automated transformation pipeline and a community-driven safety skill repository. Building upon this foundation, they propose the $S^3$ (Stage-Specific Safety Skills) multi-stage defense framework, wherein guardian agents orchestrate stage-specific skills to enable end-to-end risk detection and mitigation. Experimental results demonstrate that $S^3$ significantly outperforms current methods in both safety effectiveness and task utility, highlighting its potential for constructing trustworthy LLM agent systems.

comprehensive protectionLLM agentsmulti-stage workflows

This study addresses the vulnerability of autonomous driving systems to cyber-physical attacks that jeopardize their safety and operational continuity. The authors propose a hierarchical attack taxonomy and develop a resilient architecture integrating redundancy, diversity, and adaptive reconfiguration, uniquely bridging layered threat modeling with practical defense mechanisms. Key innovations include an intrusion detection method combining anomaly detection and hashing, a depth-camera-specific anti-blinding strategy, tamper-resistant software design for perception modules, and enhanced V2X communication security. Experimental validation on the Quanser QCar platform demonstrates the approach’s effectiveness in detecting depth camera blinding and perception software tampering attacks, significantly improving system resilience, operational continuity, and safety under adversarial conditions.

Autonomous VehiclesCyberattacksResilience

Hot Scholars

MC

Mauro Conti

IEEE Fellow - Prof.@University of Padua - Wallenberg WASP Guest.Prof.@Örebro U.- Affiliate Prof.@UW
SecurityPrivacy
DS

Dongdong She

Hong Kong University of Science and Technology
SecurityMachine LearningProgram AnalysisFuzzing
ZL

Zesen Liu

Ph.D. Student, HKUST
Security
NL

Ninghui Li

Professor of Computer Science, Purdue University
Privacy