cybersecurity

Designs, implements, and evaluates technical and organizational measures to protect computer networks, systems, endpoints, and data from unauthorized access, disruption, or exploitation. Builds secure architectures, access controls, cryptographic protections, intrusion detection/prevention and monitoring, incident response processes, and conducts threat/vulnerability analysis and risk assessment to prioritize mitigations.

cybersecurity

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
2.72
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$189K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

A Systematic Approach to Estimate the Security Posture of a Cyber Infrastructure: A Technical Report

Aug 29, 2025
QS
Qishen Sam Liang
🏛️ USC Information Sciences Institute

Scientific research cyberinfrastructure (CI) faces unique challenges—including high collaboration requirements, component heterogeneity, and the absence of adaptable security assessment frameworks. To address these, we propose a mission-centric security posture assessment method: first, top-down identification of critical assets and unacceptable losses; second, construction of a security knowledge graph integrating system components, dependencies, and threat behaviors; and third, integration with directed attack graphs to quantify multi-hop attack paths from entry points to critical assets—enabling visualization of attacker-defender relationships and identification of security blind spots. Unlike conventional generic standards, our approach is the first to deeply couple mission-driven assessment, knowledge graphs, and attack graphs. It supports risk prioritization and generation of actionable defensive strategies, significantly enhancing the precision and effectiveness of CI security defense.

Addressing lack of practical security assessment frameworksEstimating security posture of collaborative cyber infrastructuresSystematically mapping adversary attack paths to critical assets

Towards Centralized Orchestration of Cyber Protection Condition (CPCON)

May 19, 2025
MT
Mark Timmons
🏛️ Naval Postgraduate School | Naval Information Forces

Current U.S. military CPCON (Cyber Protection Conditions) implementation suffers from manual dependency, inconsistent enforcement, and error-prone operations. To address these challenges, this paper proposes a policy-driven, centralized orchestration approach for automated security posture escalation and real-time response across heterogeneous defense networks. Our method introduces a standardized CPCON instruction mapping model and a verifiable policy execution framework, enabling subnet-level automatic isolation, host-level intrusion response extension, and human-in-the-loop supervision. We further design a lightweight state verification protocol to ensure auditable, closed-loop policy enforcement. Evaluation on a simulation platform demonstrates that the system reduces CPCON transition latency by 83% and achieves 100% accuracy—marking the first realization of end-to-end, real-time verifiability of policy execution states.

Automating inconsistent manual CPCON enforcement in DoD networksCentralizing orchestration for real-time threat response across networksStandardizing security actions and verifying enforcement status

This work addresses the challenge of identifying and prioritizing multi-step attack paths in industrial control systems (ICS). The authors propose a semi-automated approach that integrates network topology and vulnerability data to construct a system model, and for the first time apply state-aware attack graph generation to a Siemens PCS7 water treatment plant blueprint. Leveraging a state-aware traversal algorithm, the method derives multi-step attack chains driven by CVEs and misconfigurations, enabling visualization of critical attack paths. Experimental results demonstrate that a single point of failure can compromise network segmentation, while remediation of key vulnerabilities effectively protects entire security zones. These findings offer actionable security insights for ICS risk mitigation.

attack pathscritical infrastructureIndustrial Control Systems

ESASCF: Expertise Extraction, Generalization and Reply Framework for Optimized Automation of Network Security Compliance

Jul 20, 2023
MG
M. Ghanem
🏛️ London Metropolitan University | University of Liverpool | City, University of London | Technology Innovation Institute

To address high manual dependency, lengthy processes, elevated false-positive rates, and poor knowledge reuse in enterprise cybersecurity compliance, this paper proposes an expert system–driven security compliance automation framework. The framework innovatively models domain expertise as persistent, transferable, and inferable knowledge units, integrating rule-based reasoning, knowledge graphs, VA/PT toolchain orchestration, automated workflow scheduling, and feedback-driven incremental learning. It overcomes the limitations of siloed security tools by enabling cross-scenario, cross-cycle adaptive auditing and continuous capability evolution. Experimental evaluation in representative enterprise networks demonstrates a 50% reduction in initial assessment time and a 20% reduction in re-assessment time, alongside significant decreases in false negatives, improved compliance coverage and result consistency, and markedly reduced reliance on human experts.

Automated CybersecurityRule-based SystemsThreat Mitigation

Latest Papers

What's happening recently
View more

This work addresses the challenge faced by small and resource-constrained organizations in affording the high costs and operational complexity of commercial endpoint detection and response (EDR) systems by proposing a lightweight, open-source EDR solution based on a three-tier client-server architecture. The system employs a Flutter- and Kotlin-based endpoint agent and a Node.js-powered central server, ensuring secure communication through WebSocket Secure (WSS), JSON Web Token (JWT) authentication, and HMAC. Threat detection is achieved via a static signature database. Experimental evaluation demonstrates that the system achieves an average command latency of approximately 1.5 seconds under 50 concurrent endpoints, enabling sub-second responsiveness while effectively mitigating invalid token usage, SQL injection, and replay attacks. These results confirm its practical value in delivering low overhead, strong security, and ease of deployment.

cybersecurityEndpoint Detection and Responselightweight architecture

This study addresses the escalating threat of unauthorized data access confronting enterprises and proposes an integrated defense framework that synergistically combines technological, human, and organizational dimensions. The framework establishes a robust security foundation through technical measures such as firewalls, intrusion detection systems, and encryption, while simultaneously reinforcing this infrastructure with employee security awareness training and rigorous enforcement of data access policies. By integrating these layers into a cohesive, defense-in-depth architecture, the approach not only substantially mitigates the risk of data breaches but also enhances organizational compliance and overall cyber resilience. This work thus offers a practical, holistic solution for effective data governance in complex enterprise environments.

data breach preventiondata securityregulatory compliance

This work addresses the challenge of automatically translating unstructured natural language security requirements into compliant, executable network topologies. It presents the first end-to-end framework that compiles ambiguous security intents into network architectures adhering to CIS Controls v8.1.2. The approach leverages schema contracts to constrain intent semantics, employs dense vector retrieval to match reference architectures, and fuses user intent with templates in a staged manner, followed by structure-preserving incremental editing to complete security policies. The system supports human-in-the-loop validation for uncovered scenarios and exports configurations for Mininet and iptables. Evaluated on financial and governmental test sets, the framework achieves full CIS compliance—raising topology compliance from 0.78 to 1.00—with an average of only 1.5 refinement rounds, while access control list (ACL) policies attain a one-round feedback pass rate of 0.88.

access controlcompliance checkingenterprise security

This work addresses the challenge of efficiently and accurately translating high-level security intents into deployable device-level policies in complex heterogeneous networks, where topological reachability and device capabilities often lead to misconfigurations and delayed responses. To overcome these limitations, the authors propose an end-to-end automated framework that uniquely integrates network topology, device capabilities, and real-time cyber threat intelligence (CTI). By leveraging formal modeling, policy compilation, and constraint solving, the approach automatically refines abstract security intents into concrete, network-compliant filtering rules. Experimental validation in real-world environments demonstrates the system’s ability to correctly generate both packet-filtering and web-filtering policies, confirming its practicality, correctness, and dynamic adaptability to emerging threats.

cyber threatsmisconfigurationsnetwork constraints