{"id":{"repo_id":"colostate","oai_identifier":"oai:mountainscholar.org:10217/244800"},"canonical_url":"https://search.dev.ndltd.org/etd/colostate/oai:mountainscholar.org:10217/244800","repository":{"repo_id":"colostate","name":"Colorado State University","base_url":"https://api.mountainscholar.org/server/oai/request"},"display":{"title":"Characterizing anti-forensic attackers in cybersecurity domains with Stackelberg planning","abstract":"The rapid advancement of artificial intelligence has enabled large-scale, automated cyberattacks capable of targeting critical infrastructure with unprecedented speed. Since a perfect defense is often unattainable in complex networks, defenders must strategically force attackers into either objective failure or leaving a detectable footprint. This research addresses this defensive gap by applying Automated Planning to model a self-cleaning adversary within a state-based environment. Utilizing a Stackelberg planning framework, our methodology simulates a game-theoretic dynamic where a defender proactively modifies the environment and the attacker computes an optimal intrusion path in response. This adversarial interaction is evaluated across a simulated, segmented network, ultimately enabling the formal verification of security invariants and providing a framework to strengthen both network architecture and forensic audit trails.","abstract_html":"The rapid advancement of artificial intelligence has enabled large-scale, automated cyberattacks capable of targeting critical infrastructure with unprecedented speed. Since a perfect defense is often unattainable in complex networks, defenders must strategically force attackers into either objective failure or leaving a detectable footprint. This research addresses this defensive gap by applying Automated Planning to model a self-cleaning adversary within a state-based environment. Utilizing a Stackelberg planning framework, our methodology simulates a game-theoretic dynamic where a defender proactively modifies the environment and the attacker computes an optimal intrusion path in response. This adversarial interaction is evaluated across a simulated, segmented network, ultimately enabling the formal verification of security invariants and providing a framework to strengthen both network architecture and forensic audit trails.","abstract_has_math":false,"creators":["Curcio, Jason, author","Sreedharan, Sarath, advisor","Ray, Indrajit, committee member","Daily, Jeremy, committee member"],"institution":"Colorado State University. Libraries","degree_name":"Master of Science (M.S.)","degree_level":"Masters","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026","date_published":"2026","updated_at":"2026-07-27T19:13:00Z","subjects":["forensics","Stackelberg","planning","cybersecurity"],"languages":["eng","English"],"rights":["Copyright and other restrictions may apply. User is responsible for compliance with all applicable laws. For information about copyright law, please see https://libguides.colostate.edu/copyright."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://doi.org/10.25675/3.027160"],"render_values":[{"text":"https://doi.org/10.25675/3.027160","href":"https://doi.org/10.25675/3.027160","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/10217/244800","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Curcio, Jason, author","Sreedharan, Sarath, advisor","Ray, Indrajit, committee member","Daily, Jeremy, committee member"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-06-08T10:31:41Z"]},{"key":"dc:date.issued","label":"Date","values":["2026"]},{"key":"dc:publisher","label":"Institution","values":["Colorado State University. Libraries"]},{"key":"dc:type","label":"Dc Type","values":["Text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Masters"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (M.S.)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["Colorado State University"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["forensics","Stackelberg","planning","cybersecurity"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["English"]},{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright and other restrictions may apply. User is responsible for compliance with all applicable laws. For information about copyright law, please see https://libguides.colostate.edu/copyright."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["Curcio_colostate_0053N_19532.pdf"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10217/244800","https://doi.org/10.25675/3.027160"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The rapid advancement of artificial intelligence has enabled large-scale, automated cyberattacks capable of targeting critical infrastructure with unprecedented speed. Since a perfect defense is often unattainable in complex networks, defenders must strategically force attackers into either objective failure or leaving a detectable footprint. This research addresses this defensive gap by applying Automated Planning to model a self-cleaning adversary within a state-based environment. Utilizing a Stackelberg planning framework, our methodology simulates a game-theoretic dynamic where a defender proactively modifies the environment and the attacker computes an optimal intrusion path in response. This adversarial interaction is evaluated across a simulated, segmented network, ultimately enabling the formal verification of security invariants and providing a framework to strengthen both network architecture and forensic audit trails."]},{"key":"dc:format.medium","label":"Dc Format Medium","values":["born digital","masters theses"]},{"key":"dc:title","label":"Title","values":["Characterizing anti-forensic attackers in cybersecurity domains with Stackelberg planning"]}]}],"canonical_facts":{"dc:creator":["Curcio, Jason, author","Sreedharan, Sarath, advisor","Ray, Indrajit, committee member","Daily, Jeremy, committee member"],"dc:date.accessioned":["2026-06-08T10:31:41Z"],"dc:date.issued":["2026"],"dc:description.abstract":["The rapid advancement of artificial intelligence has enabled large-scale, automated cyberattacks capable of targeting critical infrastructure with unprecedented speed. Since a perfect defense is often unattainable in complex networks, defenders must strategically force attackers into either objective failure or leaving a detectable footprint. This research addresses this defensive gap by applying Automated Planning to model a self-cleaning adversary within a state-based environment. Utilizing a Stackelberg planning framework, our methodology simulates a game-theoretic dynamic where a defender proactively modifies the environment and the attacker computes an optimal intrusion path in response. This adversarial interaction is evaluated across a simulated, segmented network, ultimately enabling the formal verification of security invariants and providing a framework to strengthen both network architecture and forensic audit trails."],"dc:format.medium":["born digital","masters theses"],"dc:identifier":["Curcio_colostate_0053N_19532.pdf"],"dc:identifier.uri":["https://hdl.handle.net/10217/244800","https://doi.org/10.25675/3.027160"],"dc:language":["English"],"dc:language.iso":["eng"],"dc:publisher":["Colorado State University. Libraries"],"dc:rights":["Copyright and other restrictions may apply. User is responsible for compliance with all applicable laws. For information about copyright law, please see https://libguides.colostate.edu/copyright."],"dc:subject":["forensics","Stackelberg","planning","cybersecurity"],"dc:title":["Characterizing anti-forensic attackers in cybersecurity domains with Stackelberg planning"],"dc:type":["Text"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Masters"],"thesis:degree_name":["Master of Science (M.S.)"],"thesis:institution_name":["Colorado State University"]},"updated_at":"2026-07-27T19:13:00Z"}