Modern cyber threats demand defense strategies that are adaptive, risk-aware, and capable of misdirecting adversaries in real time. Traditional static deception systems lack the flexibility to respond to evolving attack patterns and changing mission priorities. To address this, we introduce a framework for risk-aware adaptive cyber deception assisted by Large Language Models. The architecture integrates dynamic risk assessment, AI-assisted deception strategy generation, and modular deployment mechanisms. At its core, the Decision and Policy Engine uses an LLM-driven agent to interpret MITRE CAPEC-aligned threat intelligence and generate semantically rich deception recommendations. These are then translated into executable deception playbooks by the Dynamic Cyber Deception module, which manages tactic selection and deployment. The framework includes a feedback loop where telemetry and mission impact assessments inform ongoing refinement of deception strategies, enabling mission-aware adaptation over time. This work lays a foundation for the next generation of intelligent cyber defense systems that combine structured risk models with language-model reasoning to support resilient, adaptive, and context-driven deception capabilities.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Risk-Aware Adaptive Cyber Deception Guided by Large Language Models

  • David Lopes Antunes,
  • Pavlos Cheimonidis,
  • Eleftherios Batzolis,
  • Kyriakos Ovaliadis,
  • Salvador Llopis Sanchez,
  • Konstantinos Rantos

摘要

Modern cyber threats demand defense strategies that are adaptive, risk-aware, and capable of misdirecting adversaries in real time. Traditional static deception systems lack the flexibility to respond to evolving attack patterns and changing mission priorities. To address this, we introduce a framework for risk-aware adaptive cyber deception assisted by Large Language Models. The architecture integrates dynamic risk assessment, AI-assisted deception strategy generation, and modular deployment mechanisms. At its core, the Decision and Policy Engine uses an LLM-driven agent to interpret MITRE CAPEC-aligned threat intelligence and generate semantically rich deception recommendations. These are then translated into executable deception playbooks by the Dynamic Cyber Deception module, which manages tactic selection and deployment. The framework includes a feedback loop where telemetry and mission impact assessments inform ongoing refinement of deception strategies, enabling mission-aware adaptation over time. This work lays a foundation for the next generation of intelligent cyber defense systems that combine structured risk models with language-model reasoning to support resilient, adaptive, and context-driven deception capabilities.