{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/151545"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/151545","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Inference of Cyber Threats, Vulnerabilities, and Mitigations to Enhance Cybersecurity Simulations","abstract":"Machine Learning techniques can provide insight in a variety of inference tasks involving not only text data but also source code. We apply these techniques to BRON, a graph database linking cybersecurity threats, vulnerability sources, and mitigation techniques, in order to extract a wider variety of relationships, and more effectively analyze them. We find that prompt engineering in large language models improves performance in edge classification within BRON. We in addition explore these inferences in practice, by modeling the interaction between cybersecurity attackers and defenders on a given network in a zero-sum game. We apply coevolution in a novel multi-step feedback framework to improve performance in modelling attacks, and find that allowing attackers to dynamically select their attack strategies improves their payoff.","abstract_html":"Machine Learning techniques can provide insight in a variety of inference tasks involving not only text data but also source code. We apply these techniques to BRON, a graph database linking cybersecurity threats, vulnerability sources, and mitigation techniques, in order to extract a wider variety of relationships, and more effectively analyze them. We find that prompt engineering in large language models improves performance in edge classification within BRON. We in addition explore these inferences in practice, by modeling the interaction between cybersecurity attackers and defenders on a given network in a zero-sum game. We apply coevolution in a novel multi-step feedback framework to improve performance in modelling attacks, and find that allowing attackers to dynamically select their attack strategies improves their payoff.","abstract_has_math":false,"creators":["Liu, Kyle"],"institution":"Massachusetts Institute of Technology","degree_name":"Master","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","school":null,"contributors":[],"advisors":["Hemberg, Erik","O’Reilly, Una-May"],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-06","date_published":"2023-06","updated_at":"2026-07-22T22:21:30Z","subjects":[],"languages":[],"rights":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"],"rights_urls":["https://rightsstatements.org/page/InC-EDU/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/151545","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Hemberg, Erik","O’Reilly, Una-May"]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"]},{"key":"dc:creator","label":"Author","values":["Liu, Kyle"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2023-07-31T19:47:35Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2023-07-31T19:47:35Z"]},{"key":"dc:date.issued","label":"Date","values":["2023-06"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master","Master of Engineering in Electrical Engineering and Computer Science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"]},{"key":"dc:rights.uri","label":"Rights URI","values":["https://rightsstatements.org/page/InC-EDU/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/151545"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Machine Learning techniques can provide insight in a variety of inference tasks involving not only text data but also source code. We apply these techniques to BRON, a graph database linking cybersecurity threats, vulnerability sources, and mitigation techniques, in order to extract a wider variety of relationships, and more effectively analyze them. We find that prompt engineering in large language models improves performance in edge classification within BRON. We in addition explore these inferences in practice, by modeling the interaction between cybersecurity attackers and defenders on a given network in a zero-sum game. We apply coevolution in a novel multi-step feedback framework to improve performance in modelling attacks, and find that allowing attackers to dynamically select their attack strategies improves their payoff."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M.Eng."]},{"key":"dc:title","label":"Title","values":["Inference of Cyber Threats, Vulnerabilities, and Mitigations to Enhance Cybersecurity Simulations"]}]}],"canonical_facts":{"dc:contributor.advisor":["Hemberg, Erik","O’Reilly, Una-May"],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"],"dc:creator":["Liu, Kyle"],"dc:date.accessioned":["2023-07-31T19:47:35Z"],"dc:date.available":["2023-07-31T19:47:35Z"],"dc:date.issued":["2023-06"],"dc:description.abstract":["Machine Learning techniques can provide insight in a variety of inference tasks involving not only text data but also source code. We apply these techniques to BRON, a graph database linking cybersecurity threats, vulnerability sources, and mitigation techniques, in order to extract a wider variety of relationships, and more effectively analyze them. We find that prompt engineering in large language models improves performance in edge classification within BRON. We in addition explore these inferences in practice, by modeling the interaction between cybersecurity attackers and defenders on a given network in a zero-sum game. We apply coevolution in a novel multi-step feedback framework to improve performance in modelling attacks, and find that allowing attackers to dynamically select their attack strategies improves their payoff."],"dc:description.degree":["M.Eng."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/151545"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["In Copyright - Educational Use Permitted","Copyright retained by author(s)"],"dc:rights.uri":["https://rightsstatements.org/page/InC-EDU/1.0/"],"dc:title":["Inference of Cyber Threats, Vulnerabilities, and Mitigations to Enhance Cybersecurity Simulations"],"dc:type":["Thesis"],"thesis:degree_name":["Master","Master of Engineering in Electrical Engineering and Computer Science"]},"updated_at":"2026-07-22T22:21:30Z"}