Score
Designs and implements mechanisms to generate, craft, and deliver synthetic or forged system events (for example, logs, interrupts, network packets, API calls, or scheduled tasks) into hardware or software environments, controlling timing, sequencing, and state to exercise, test, or manipulate system behavior. Analyzes the effects of injected events, their failure modes and side effects, and builds delivery interfaces, validation harnesses, detection/mitigation measures, and cleanup procedures.
This work addresses the limitations of existing adversarial simulation tools, which rely on agent-based instrumentation of target systems, often leaving anomalous artifacts and failing to faithfully replicate human attacker behavior—particularly in critical phases of the cyber kill chain such as initial access and interactive operations. To overcome these shortcomings, the authors propose and implement an open-source attack scripting language coupled with an agentless execution engine that closely emulates real-world attacker tactics. This approach enables high-fidelity, interactive simulation of complete kill chain stages, including initial access, privilege escalation, and lateral movement. Experimental results demonstrate that system logs generated by this method exhibit significantly greater behavioral similarity to those produced by actual human-driven attacks, thereby enhancing the realism and effectiveness of security testing and intrusion detection research.
To address the lack of systematic continuous verification and secure release mechanisms in open-source hardware design, this paper pioneers the systematic adaptation of software CI/CD paradigms to the hardware domain, proposing a general-purpose framework for automatic hardware specification mining and continuous deployment. Methodologically, it integrates HDL static analysis, machine learning–driven specification inference, formal verification, and cloud-native automated pipelines, implemented in the prototype system Myrtha. Key contributions include: (1) the first CI/CD architecture supporting continuous hardware specification generation, verification, and release; (2) a scalable, automated specification mining mechanism that overcomes traditional manual modeling bottlenecks; and (3) substantial improvements in quality assurance, experimental reproducibility, and cross-team collaboration efficiency for open-source hardware development.
Attack scenario descriptions in cybersecurity automation lack formal semantic foundations, hindering systematic analysis and automation. Method: This paper proposes an abstract, formal model based on UML class diagrams, enabling the first unified modeling of attack context and attack scenarios. The model supports structured input, automated processing, and cross-process reuse, directly facilitating two core tasks: attack analysis and automated attack script generation. Contribution/Results: Evaluated on real-world attack analysis and cybersecurity training script generation, the model demonstrates strong feasibility and effectiveness. It fills a critical gap in formal attack scenario modeling and establishes a scalable, verifiable semantic foundation for security process automation—enhancing interoperability, reproducibility, and formal reasoning in cyber defense systems.
Current STIX/ATT&CK frameworks describe threat behaviors solely in terms of *what* actions are performed, omitting critical procedural semantics—such as execution order, preconditions, and environmental assumptions—hindering accurate multi-stage APT simulation. Method: We first quantitatively assess ATT&CK’s coverage of real-world campaigns and intrusion sets (only 35.6% of techniques covered) and structural reusability. Then, we propose a three-stage semantic completion framework that explicitly models the procedural logic of attack chains, integrating STIX 2.1 parsing, Longest Common Subsequence (LCS)-based sequence modeling, Caldera operation mapping, and parameterized injection. Contribution/Results: With minimal human annotation of key assumptions, our approach enables Caldera to successfully reproduce real-world APT campaigns—including ShadowRay and Soft Cell. This work identifies the critical semantic gap between descriptive cyber threat intelligence (CTI) and machine-executable CTI, establishing both theoretical foundations and practical methodology for operationalizing threat intelligence.
Industrial Control Systems (ICS) face escalating cyber threats due to increased connectivity, yet conventional honeypots—relying on firmware reverse engineering and expert-crafted rules—struggle to efficiently and realistically emulate multi-vendor protocols and PLC control logic. To address this, we propose the first large language model (LLM)-based, dynamically configurable ICS honeypot framework, leveraging LLaMA-3 and Qwen. Our approach integrates protocol semantic parsing, prompt-engineered control logic generation, and finite-state machine modeling to enable zero-shot, vendor-agnostic automation of both protocol and control behavior simulation. Evaluated across seven industrial protocols and twelve representative control scenarios, our framework achieves 98.2% session-level interaction fidelity, improves attack traffic capture rate by 3.8×, and reduces configuration time from hours to seconds—effectively overcoming the core bottlenecks of high manual effort and poor generalizability in ICS honeypot deployment.
研究通过构建PLCBENCH框架,评估自主LLM代理能否将网络可访问的PLC转化为持续物理影响,采用硬件在环测试方法。
This study addresses the high cost of manual RTL analysis, vulnerability localization, and stealthy payload generation in hardware Trojan construction by proposing the first Data Flow Graph (DFG)-augmented Large Language Model framework. The method leverages structured CWE semantics to guide LLMs in automatically identifying vulnerabilities and performing intent-driven RTL modifications, thereby enabling the automated synthesis of minimal, interface-compatible, and stealthy Trojans with ultra-rare trigger conditions. Experimental results demonstrate that the generated Trojans achieve a 100% syntactic correctness rate, remain undetectable under large-scale random simulations while triggering precisely, and exhibit strong scalability.
MimicSat通过提供一个可重构的软硬件测试平台,解决小卫星系统及网络安全研究中行为变化对任务结果影响的问题。
This work addresses the inefficiencies and semantic inconsistencies arising from separately implementing driver and monitor programs in traditional hardware module testing. To overcome this, the authors propose a domain-specific language (DSL) tailored to hardware communication protocols, which enables the unified specification of both driver and monitor logic through an imperative syntax, thereby ensuring their semantic consistency for the first time. Building upon this DSL, they develop a prototype tool that leverages waveform parsing and transaction-level trace inference techniques to accurately reconstruct protocol-compliant transaction sequences from raw signal waveforms. Experimental results demonstrate that the approach significantly improves development efficiency, with further validation planned on real-world interconnect protocols such as Wishbone and AXI-Stream.
This work addresses the lack of a unified analytical framework for prompt injection attacks, which are typically represented as unstructured strings, hindering systematic annotation, comparison, and evolution. The authors propose the first structured seven-component model—comprising carrier, delivery vector, obfuscation mechanism, context boundary breach, privilege escalation, payload, and exfiltration channel—that focuses on attacker intent rather than surface-level text to establish a reusable attack parsing framework. This model integrates existing techniques, aligns with Cyber Threat Intelligence (CTI) standards, and enables attack flow graph modeling. Notably, minimal jailbreaking is formalized as a subspace within this framework. Empirical validation on EchoLeak (CVE-2025-32711) and real-world AI evasion malware demonstrates its effectiveness in systematically describing and reproducing prompt injection attacks.