Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Jayasankar Kumar Santhirani, Deivanai Shankar, Arjun Shetty, Karthik Venkatesh, Jesmilan Jesu
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range featuring a legitimate workload, an unscripted attacker, and a policy engine enforcing deny-only actions, the research compares no defense, a stateful static playbook, and an AI defender across 40 measured episodes and four controls. The empirical results demonstrate that the static playbook prevented secret retrieval in all eight of its episodes, whereas the AI defender allowed retrieval in three of eight episodes with a fixed canary and four of eight with adaptive placement, while also inflicting greater availability losses on legitimate traffic. When the attacker adapted by switching routes post-block, both defenders successfully achieved containment in every instance, with the AI defender responding within a median of one to seven seconds compared to the playbook's twenty-one seconds. Ultimately, the study shows that in this environment, within-incident adaptation did not reduce overall attack success or impact compared to a fixed policy, leading to a proposed Adaptive Containment Requirement (ACR) emphasizing bounded authority and third-party verifiable conformance.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
},
author={
Jayasankar Kumar Santhirani, Deivanai Shankar, Arjun Shetty, Karthik Venkatesh, Jesmilan Jesu
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


