Pith. sign in

REVIEW 4 major objections 5 minor 88 references

Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment

T0 review · 4 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read Passive hack-back—beacons, honeytokens, and decoy payloads—can attribute attackers covertly and lawfully in denied environments.

desk verdict A useful taxonomy of passive hack-back techniques undermined by an unargued legal claim that the whole 'lawful pathway' conclusion rests on. read the letter →

arxiv 2508.16637 v1 pith:B53Y7E3W submitted 2025-08-17 cs.CR

classification cs.CR
keywords passivehack-backcyberattributionhoneytokenstrackingbeaconsdeniedenvironmentsadversarialmachinelearningLLM-generatedpayloadsdeception
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish that defenders do not need to strike back to attribute a cyberattack: by planting passive triggers inside the data an attacker is likely to steal, a defender can collect location, identity, and environment signals from the attacker's own systems without initiating any offensive action. The payoff would be a lawful, non-escalatory attribution capability for exactly the denied or contested environments where active hack-back is prohibited or too dangerous. The paper builds this case through a taxonomy of vectors—tracking beacons, honeytokens and canary credentials, environment-fingerprinted payloads, parser bombs, build-time traps, and steganographic watermarks—and through prototype deployments of a beaconed document, a beaconed Android package, and a honey SSH credential. It then argues that AI-generated adaptive payloads and post-quantum hardening can extend the same passive logic. The paper's central claim is that passive hack-back is a realistic and legally defensible intelligence-gathering strategy rather than a theoretical curiosity.

What carries the argument

The carrying mechanism is the passive trigger point: a deceptive artifact placed inside stolen or leaked data that fires only when the attacker interacts with it in a foreign environment. The paper formalizes this through seven pre-assumptions and maps each to the vectors it enables, so the taxonomy is organized around what the defender can assume rather than around attacker infrastructure. Environment fingerprinting and time delays act as safety interlocks so the trigger does not fire on the defender's own network, and a return channel—DNS, HTTP(S), API calls, or externally logged fake credentials—carries telemetry back. AI and LLM components extend the same machinery by generating context-aware payloads at runtime, and post-quantum cryptography is proposed to protect the return channel and the integrity of collected evidence.

What would settle it

Run the paper's own prototype vectors against a disciplined adversary playbook: a network-isolated virtual machine with no egress except a monitored proxy, metadata scrubbing before any file is opened, and a policy of never using unknown credentials. If, over many trials, the DOCX beacon, APK asset, and honey SSH key yield zero callbacks and zero logins, the central claim is falsified. A field-scale version would plant a realistic batch of beaconed files in a controlled leak and measure callback rates from known threat-actor groups.

Watch

Extended reading notes

Core claim

The paper's central claim is that a coherent family of passive hack-back vectors can achieve covert cyber attribution in denied environments, where the defender knows nothing about the attacker's IP, route, or infrastructure and is barred from initiating contact. The proposed mechanism is to embed triggers in the assets the attacker is assumed to have exfiltrated—documents, credentials, source code, mobile packages—so that the attacker's own act of opening, building, or using those assets fires a callback to defender-controlled infrastructure. The paper catalogs the vector classes, maps each to an explicit pre-assumption about attacker behavior, and reports prototype evaluations in simulated attacker environments, with high beacon callback success and low detection. On the legal side, it argues that because no unauthorized access or disruption occurs, these techniques fit within the constraints that make active hack-back unlawful. It further contends that LLM-generated payloads, autonomous forensic agents, and adversarial machine learning can make the triggers adaptive, while quantum technologies are a future threat to telemetry cryptography and a future tool for covert communication.

Load-bearing premise

The load-bearing premise is that the attacker will actually open, run, or otherwise use the stolen data in a way that fires the embedded trigger and sends telemetry back; if the attacker analyzes the files in an isolated, instrumented environment or never touches the decoy credentials, the entire passive attribution chain stays silent.

Editorial extensions

If this is right

  • If the central claim holds, defenders in legally restricted settings gain an attribution channel that does not require knowing the attacker's infrastructure or touching it directly.
  • Document, credential, and mobile-package lures become general-purpose sensors: every callback is a signal that can be correlated across incidents to profile an adversary's tooling, locale, and workflows.
  • Environment-specific triggers and manual arming make it possible to deploy these lures at scale without high rates of self-triggering inside the defender's own estate.
  • AI-generated payloads imply that attribution fidelity need not be fixed at design time: the payload can adapt to the attacker's observed environment before reporting back.
  • Hybrid frameworks become feasible: passive attribution can feed confidence thresholds that authorize delayed, conditional, legally vetted active responses.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same baiting logic should transfer to insider-threat and supply-chain scenarios, where the 'attacker' is a trusted user or downstream vendor and the trigger point is the same: interaction with a decoy asset.
  • A sophisticated adversary who routinely inspects exfiltrated files in network-isolated sandboxes, strips metadata, and avoids using unknown credentials would starve every vector in the taxonomy; the framework therefore predicts an observable arms race in which attribution success tracks attacker OPSEC discipline.
  • One testable extension is a controlled-leak experiment: release a batch of beaconed files and honey credentials through a realistic compromise, then measure callback rate and time-to-first-trigger across different threat-actor profiles.
  • The legal framing implicitly assumes that passive collection from a foreign system does not itself cross a sovereignty line; if courts or states treat covert beacons as unauthorized access, the 'lawful' part of the claim would need re-examination.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. This perspective paper argues that "passive hack-back"---using tracking beacons, honeytokens, environment-specific payloads, and AI-enhanced agents---offers a lawful and effective route to cyber attribution in denied environments. It defines seven pre-assumptions, maps them to a taxonomy of passive vectors (Section 4), describes prototype DOCX, APK, and credential-file payloads (Section 5.1), discusses legal, ethical, and operational constraints (Section 6), and explores AI and quantum enhancements (Sections 7--8). The central claim, stated in the Conclusion (Section 10), is that passive mechanisms "offer a stealthy and lawful pathway to attribution and intelligence gathering, without the risks typically associated with active countermeasures."

Significance. If the lawfulness and effectiveness claims were established, this would be a useful organizing framework for defenders operating under strict rules of engagement. The paper's strengths are its explicit pre-assumption mapping (Tables 1--2), a clear taxonomy of vectors, and honest limitations sections (e.g., Section 8.4 for quantum and Section 7.6 for AI governance). However, the contribution is a perspective, not a validated technical result, and its significance is currently bounded by two gaps: the legal basis for embedded beacons that execute on the attacker's machine is asserted rather than argued, and the effectiveness evaluation in Section 5.3 is qualitative with no reported measurements.

major comments (4)
  1. [Section 6.1 and Section 5.1] The claim that the described vectors are lawful rests on an unsupported and internally inconsistent premise. Section 6.1 asserts that honeytokens and embedded beacons "are typically considered lawful if they do not involve unauthorized access or system disruption," but Section 5.1 describes a DOCX with a hidden remote-image callback and an APK that "silently initiates a DNS request when the app is installed or run," and Section 7.1 contemplates agents "deployed within the attacker's infrastructure." Causing code to execute on the attacker's device after the attacker opens or installs the artifact is not the same as passive observation; the paper never explains why the attacker's act of opening or installing constitutes authorization for the embedded payload to carry out network callbacks or reconnaissance. Because the Conclusion's "lawful pathway" depends on this point, the legal half of the central claim is not established. The paper should either restrict the lawfulness claim to genuinely passive mechanisms (e.g., honeytoken credentials that trigger only when the attacker uses them against defender-controlled services) or provide a jurisdiction-specific analysis of why beacon execution on a third-party system is not unauthorized access.
  2. [Section 5.3 and Section 10] The effectiveness half of the central claim is not supported by the reported evaluation. Section 5.3 defines three metrics--callback success rate, attribution fidelity, and stealth level--but then states only that "experimental results showed that all three prototype vectors achieved high callback success rates" and that attribution fidelity "yielded useful telemetry in the majority of cases." No actual rates, sample sizes, detection counts, or confidence intervals are provided, and no comparison to a baseline is given. Since the Conclusion claims these mechanisms "offer a stealthy and lawful pathway to attribution," the evaluation should either report the measured values or be explicitly labeled as a qualitative feasibility demonstration rather than an evaluation.
  3. [Section 1.1.1 and Section 10] The Conclusion overstates the robustness of the approach relative to the paper's own Pre-Assumption 3 ("The Attacker Will Interact with the Data in a Vulnerable or Traceable Way"). If the attacker analyzes exfiltrated data in an air-gapped or instrumented environment, scrubs metadata, or never opens the decoy assets, the beacons and honeytokens never fire and no attribution is produced. Table 1 itself rates several conditional assumptions as only Medium or Low usefulness. The unqualified language in the Conclusion should be revised to state explicitly that the claimed pathway is conditional on the attacker's interaction with the stolen data, which is a behavioral premise outside the defender's control.
  4. [Section 7.1 and Section 2] The description of autonomous agents contradicts the paper's own threat model and pre-assumptions. Section 7.1 says AI-powered agents "can be covertly embedded into exfiltrated data or decoy software. Once deployed within the attacker's infrastructure," while Section 2 states that defensive actions avoid "direct contact with attacker infrastructure" and Pre-Assumption 4 says "Defender Cannot Initiate Contact." The paper does not explain the mechanism by which an agent embedded in a stolen file transitions from being a triggered payload to being "deployed within the attacker's infrastructure" without active propagation or unauthorized access. This tension affects the coherence of the proposed AI-enhanced vectors and should be resolved by either clarifying the deployment mechanism or removing the claim that such agents remain within passive constraints.
minor comments (5)
  1. [Section 4.2] The sentence "The concept of honeytokens, decoy data that triggers alerts upon unauthorized access, originates [36]" is grammatically incomplete; it should read "originates with [36]" or be rephrased.
  2. [Section 5.1] Describing an APK that "silently initiates a DNS request when the app is installed or run" as a passive vector requires justification; initiating network traffic on the attacker's device blurs the boundary between passive and active behavior, and this terminology should be revisited.
  3. [References] Several references appear only loosely related to the claims they support, for example [51] (a Bayesian optimization paper) and [42] (a general beacon-technology book); the authors should re-check that each citation directly supports the surrounding statement.
  4. [Section 6.1] The legal discussion relies on a single journal article (reference [54]) for the assertion that beacons and honeytokens are "typically considered lawful"; citing specific statutes, case law, or attorney-general guidance would strengthen this section.
  5. [Table 3] The row "Attribution Depth" conflates technical capability with operational value; the claim that AI-assisted methods enable "sociolinguistic inference" is presented without evidence or discussion of possible misattribution, despite the caveats in Section 7.6.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper is a qualitative framework with explicit assumptions; the central legality claim rests on external legal authorities, not on the paper's own outputs.

full rationale

Passive Hack-Back Strategies is a perspective and taxonomy paper: it contains no fitted parameters, no equations, no predictive model, and no uniqueness theorem. The pre-assumptions in Section 1.1.1 are explicitly stated behavioral and operational conditions, such as "The Attacker Will Interact with the Data in a Vulnerable or Traceable Way," and the described vectors are consequences of those assumptions rather than circular redeductions. The central claim that passive mechanisms offer a "stealthy and lawful pathway" is supported in Section 6.1 by external legal authorities, including the Tallinn Manual [7], the DoD Law of War Manual [52], and Walker-Munro et al. [54]; whether that support is adequate is a legal-substantiation or correctness concern, not a circularity concern. The only self-citation, Ref [77] by Weinberg and Faccia, appears in Section 8.1 and Future Work as background on post-quantum cryptography and does not carry the attribution or lawfulness argument. The prototype evaluation in Section 5.3 reports high callback success and minimal detection but provides no raw data; this is an evidence-quality and reproducibility concern, not an instance of fitting a parameter and renaming it a prediction. Therefore, no load-bearing step reduces to its own inputs, and no circularity is present.

Assumptions & free parameters 0 free parameters · 6 assumptions · 0 invented entities

The framework is built on operational pre-assumptions stated in Section 1.1.1. None are derived or empirically established; they are conditions under which the proposed vectors are claimed to work.

assumptions (6)
  • domain assumption The attacker has exfiltrated data that includes defender-controlled assets.
    Section 1.1.1, pre-assumption 2: the entire vector set is embedded in assets that must first be stolen.
  • domain assumption The attacker will interact with the exfiltrated data in a traceable way (open documents, run apps, use credentials).
    Section 1.1.1, pre-assumption 3; this is the weakest behavioral premise.
  • domain assumption The defender cannot initiate contact with attacker infrastructure due to legal and operational constraints.
    Section 1.1.1, pre-assumption 4 and Section 2 threat model.
  • domain assumption A return channel exists for telemetry (DNS, HTTP, or credential logs).
    Section 1.1.1, pre-assumption 7; without a return path there is no attribution signal.
  • domain assumption The attacker is not immediately aware of the deception embedded in the stolen data.
    Section 1.1.1, pre-assumption 6; payload stealth is required for the vectors to fire.
  • domain assumption Passive beacons and honeytokens are lawful under relevant jurisdictions.
    Section 6.1 asserts legality, but this is jurisdiction-dependent and not established for all cases.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment." pith.science (2026). https://pith.science/paper/B53Y7E3W

@misc{pith2026250816637,
  author       = {Pith},
  title        = {Pith review of: Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/B53Y7E3W}},
  note         = {Machine review of arXiv:2508.16637}
}
read the original abstract

Attributing cyberattacks remains a central challenge in modern cybersecurity, particularly within denied environments where defenders have limited visibility into attacker infrastructure and are restricted by legal or operational rules of engagement. This perspective examines the strategic value of passive hack-back techniques that enable covert attribution and intelligence collection without initiating direct offensive actions. Key vectors include tracking beacons, honeytokens, environment-specific payloads, and supply-chain-based traps embedded within exfiltrated or leaked assets. These approaches rely on the assumption that attackers will interact with compromised data in traceable ways, allowing defenders to gather signals without violating engagement policies. The paper also explores the role of Artificial Intelligence (AI) in enhancing passive hack-back operations. Topics include the deployment of autonomous agents for forensic reconnaissance, the use of Large Language Models (LLMs) to generate dynamic payloads, and Adversarial Machine Learning (AML) techniques for evasion and counter-deception. A dedicated section discusses the implications of quantum technologies in this context, both as future threats to cryptographic telemetry and as potential tools for stealthy communication and post-quantum resilience. Finally, the paper advocates for hybrid defensive frameworks that combine passive attribution with delayed or conditional active responses, while maintaining compliance with legal, ethical, and operational constraints.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

88 extracted references · 72 canonical work pages

  1. [77]

    Quantum Algorithms: A New Frontier in Financial Crime Prevention

    A. I. Weinberg and A. Faccia, “Quantum algorithms: A new frontier in financial crime prevention,” arXiv preprint arXiv:2403.18322 , 2024

  2. [1]

    Varsalone and C

    J. Varsalone and C. Haller, The Hack is Back: Techniques to Beat Hackers at Their Own Games . CRC Press, 2024

  3. [2]

    The ethics of hacking back,

    C. T. Holzer and J. E. Lerums, “The ethics of hacking back,” in 2016 IEEE Symposium on Technologies for Homeland Security (HST) . IEEE, 2016, pp. 1–6

  4. [3]

    Framework and principles for active cyber defense,

    D. E. Denning, “Framework and principles for active cyber defense,” Com- puters & Security , vol. 40, pp. 108–113, 2014. 21

  5. [4]

    Brown and S

    R. Brown and S. J. Roberts, Intelligence-Driven Incident Response . ” O’Reilly Media, Inc.”, 2023

  6. [5]

    An enhanced cyber attack attribution frame- work,

    N. Pitropakis, E. Panaousis, A. Giannakoulias, G. Kalpakis, R. D. Ro- driguez, and P. Sarigiannidis, “An enhanced cyber attack attribution frame- work,” in International Conference on Trust and Privacy in Digital Busi- ness. Springer, 2018, pp. 213–228

  7. [6]

    Attributing cyber attacks,

    T. Rid and B. Buchanan, “Attributing cyber attacks,” Journal of strategic studies, vol. 38, no. 1-2, pp. 4–37, 2015

  8. [7]

    M. N. Schmitt, Tallinn manual 2.0 on the international law applicable to cyber operations. Cambridge University Press, 2017

Show all 88 references
  1. [8]

    The dod law of war manual and its critics: some obser- vations,

    C. J. Dunlap Jr, “The dod law of war manual and its critics: some obser- vations,” International Law Studies , vol. 92, p. 85, 2016

  2. [9]

    Honeywords: Making password-cracking de- tectable,

    A. Juels and R. L. Rivest, “Honeywords: Making password-cracking de- tectable,” in Proceedings of the 2013 ACM SIGSAC conference on Com- puter & communications security , 2013, pp. 145–160

  3. [10]

    Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions,

    T. Zhukabayeva, L. Zholshiyeva, N. Karabayev, S. Khan, and N. Alnazzawi, “Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions,” Sensors, vol. 25, no. 1, p. 213, 2025

  4. [11]

    Weaving tangled webs: offense, defense, and deception in cyberspace,

    E. Gartzke and J. R. Lindsay, “Weaving tangled webs: offense, defense, and deception in cyberspace,” Security Studies, vol. 24, no. 2, pp. 316–348, 2015

  5. [12]

    Goldsmith, The United States’ Defend Forward Cyber Strategy: A Com- prehensive Legal Assessment

    J. Goldsmith, The United States’ Defend Forward Cyber Strategy: A Com- prehensive Legal Assessment. Oxford University Press, 2022

  6. [13]

    A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions,

    E. M. Rudd, A. Rozsa, M. G¨ unther, and T. E. Boult, “A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions,” IEEE Communications Surveys & Tutorials, vol. 19, no. 2, pp. 1145–1172, 2016

  7. [14]

    Z. Tari, N. Sohrabi, Y. Samadi, and J. Suaboot, Data Exfiltration threats and prevention techniques: Machine Learning and memory-based data se- curity. John Wiley & Sons, 2023

  8. [15]

    Beyond the leak: Analyzing the real-world exploitation of stolen credentials using honeypots,

    M. Rabzelj and U. Sedlar, “Beyond the leak: Analyzing the real-world exploitation of stolen credentials using honeypots,” Sensors, vol. 25, no. 12, p. 3676, 2025

  9. [16]

    Safer and optimised vulner- ability scanning for operational technology through integrated and auto- mated passive monitoring and active scanning,

    T. W. Edgar, S. Niddodi, T. R. Rice, W. J. Hofer, G. E. Seppala, K. M. Arthur-Durett, M. Engels, and D. O. Manz, “Safer and optimised vulner- ability scanning for operational technology through integrated and auto- mated passive monitoring and active scanning,” Journal of Info...

  10. [17]

    Device fingerprinting for cyber-physical systems: A survey,

    V. Kumar and K. Paul, “Device fingerprinting for cyber-physical systems: A survey,” ACM Computing Surveys , vol. 55, no. 14s, pp. 1–41, 2023

  11. [18]

    Hutchens, The language of deception: weaponizing next Generation AI

    J. Hutchens, The language of deception: weaponizing next Generation AI . John Wiley & Sons, 2023

  12. [19]

    Synoptic analysis techniques for intrusion detection in wireless networks,

    D. T. Hlavacek, “Synoptic analysis techniques for intrusion detection in wireless networks,” Ph.D. dissertation, Iowa State University, 2015

  13. [20]

    Research and application of indoor positioning method based on fixed infrared beacon,

    W. Yao and L. Ma, “Research and application of indoor positioning method based on fixed infrared beacon,” in 2018 37th Chinese Control Conference (CCC). IEEE, 2018, pp. 5375–5379

  14. [21]

    Baiting inside attackers using decoy documents,

    B. M. Bowen, S. Hershkop, A. D. Keromytis, and S. J. Stolfo, “Baiting inside attackers using decoy documents,” in International Conference on Security and Privacy in Communication Systems . Springer, 2009, pp. 51–70

  15. [22]

    Mitre engage: A framework and community for cy- ber deception,

    B. Eidson, “Mitre engage: A framework and community for cy- ber deception,” Feb. 2022, accessed: 2025-08-05. [Online]. Avail- able: https://www.mitre.org/news-insights/impact-story/mitre-engage- framework-and-community-cyber-deception

  16. [23]

    Diogenes and E

    Y. Diogenes and E. Ozkaya, Cybersecurity–Attack and Defense Strategies: Improve your security posture to mitigate risks and prevent attackers from infiltrating your system . Packt Publishing Ltd, 2022

  17. [24]

    Hacking the hackers: Offensive security strategies in modern cyber defense,

    Z. Huma, “Hacking the hackers: Offensive security strategies in modern cyber defense,” Journal of Data and Digital Innovation (JDDI) , vol. 2, no. 2, pp. 126–132, 2025

  18. [25]

    A critique of active defense or ‘hack back’,

    A. Caldwell and K. Curran, “A critique of active defense or ‘hack back’,” International Journal for Information Security Research, vol. 10, no. 1, pp. 957–961, 2020

  19. [26]

    Exploring the use of ethical hacking techniques in strength- ening organizational cybersecurity defenses,

    A. Smith, “Exploring the use of ethical hacking techniques in strength- ening organizational cybersecurity defenses,” Global Research Perspectives on Cybersecurity Governance, Policy, and Management , vol. 8, no. 12, pp. 1–11, 2024

  20. [27]

    Advancing cybersecurity with honey- pots and deception strategies,

    Z. Mori´ c, V. Daki´ c, and D. Regvart, “Advancing cybersecurity with honey- pots and deception strategies,” in Informatics, vol. 12, no. 1. MDPI AG, 2025, p. 14

  21. [28]

    Optimizing internet of things honeypots with ma- chine learning: A review,

    S. Lanz, S. L.-R. Pignol, P. Schmitt, H. Wang, M. Papaioannou, G. Choud- hary, and N. Dragoni, “Optimizing internet of things honeypots with ma- chine learning: A review,” Applied Sciences, vol. 15, no. 10, p. 5251, 2025

  22. [29]

    A comprehensive survey of advanced persistent threat attribution: Taxonomy, methods, challenges and open research problems,

    N. Rani, B. Saha, and S. K. Shukla, “A comprehensive survey of advanced persistent threat attribution: Taxonomy, methods, challenges and open research problems,” arXiv preprint arXiv:2409.11415 , 2024. 23

  23. [30]

    Cyber threat intelligence sharing: Survey and research directions,

    T. D. Wagner, K. Mahbub, E. Palomar, and A. E. Abdallah, “Cyber threat intelligence sharing: Survey and research directions,” Computers & Secu- rity, vol. 87, p. 101589, 2019

  24. [31]

    An anomaly detection model for multivariate time series with anomaly perception,

    D. Wei, W. Sun, X. Zou, D. Ma, H. Xu, P. Chen, C. Yang, M. Chen, and H. Li, “An anomaly detection model for multivariate time series with anomaly perception,” PeerJ Computer Science, vol. 10, p. e2172, 2024

  25. [32]

    Criminalizing hacking, not dating: Reconstructing the cfaa in- tent requirement,

    D. Thaw, “Criminalizing hacking, not dating: Reconstructing the cfaa in- tent requirement,” J. Crim. L. & Criminology , vol. 103, p. 907, 2013

  26. [33]

    Cyber intelligence,

    F. Lemieux, “Cyber intelligence,” in Intelligence and State Surveillance in Modern Societies: An International Perspective . Emerald Publishing Limited, 2024, pp. 171–184

  27. [34]

    Miller and T

    S. Miller and T. Bossomaier, Cybersecurity, ethics, and collective responsi- bility. Oxford University Press, 2024

  28. [35]

    Honeytokens: The other honeypot,

    L. Spitzner, “Honeytokens: The other honeypot,” 2003

  29. [36]

    Data-level cyber deception in cloud of things: Prospects, issues, and challenges,

    N. Prabhaker, G. S. Bopche, and M. Arock, “Data-level cyber deception in cloud of things: Prospects, issues, and challenges,” in Cloud of Things . Chapman and Hall/CRC, 2024, pp. 173–191

  30. [37]

    Intrusion detection system using honey token based encrypted pointers to mitigate cyber threats for critical infras- tructure networks,

    M. K. Asif and Y. S. Al-Harthi, “Intrusion detection system using honey token based encrypted pointers to mitigate cyber threats for critical infras- tructure networks,” in 2014 IEEE International Conference on Systems, Man, and Cybernetics (SMC) . IEEE, 2014, pp. 1266–1270

  31. [38]

    A survey of parser differential anti-patterns,

    S. Ali and S. W. Smith, “A survey of parser differential anti-patterns,” in 2023 IEEE Security and Privacy Workshops (SPW) . IEEE, 2023, pp. 105–116

  32. [39]

    Time traps in supply chains: Is optimal still good enough?

    F. Dunke, I. Heckmann, S. Nickel, and F. Saldanha-da Gama, “Time traps in supply chains: Is optimal still good enough?” European Journal of Operational Research, vol. 264, no. 3, pp. 813–829, 2018

  33. [40]

    Steganography: Unveil- ing techniques and research agenda,

    A. Kumar, S. Tandon, S. Deorari, and R. Kumar, “Steganography: Unveil- ing techniques and research agenda,” 2024

  34. [41]

    M. A. Shhadih, Cyber Deception Techniques and an Adversary Engage- ment Platform for Cybersecurity Enhancement . The George Washington University, 2023

  35. [42]

    Statler, A

    S. Statler, A. Audenaert, J. Coombs, T. Gordon, P. Hendrix, K. Kolodziej, P. Leddy, B. Parker, M. Proietti, and R. Rotolo, Beacon technologies. Springer, 2016. 24

  36. [43]

    Secure cloud-based mobile apps: attack taxonomy, re- quirements, mechanisms, tests and automation,

    F. T. Chimuco, J. B. Sequeiros, C. G. Lopes, T. M. Sim˜ oes, M. M. Freire, and P. R. Inacio, “Secure cloud-based mobile apps: attack taxonomy, re- quirements, mechanisms, tests and automation,” International Journal of Information Security, vol. 22, no. 4, pp. 833–867, 2023

  37. [44]

    Malware dy- namic analysis evasion techniques: A survey,

    A. Afianian, S. Niksefat, B. Sadeghiyan, and D. Baptiste, “Malware dy- namic analysis evasion techniques: A survey,” ACM Computing Surveys (CSUR), vol. 52, no. 6, pp. 1–28, 2019

  38. [45]

    Johansen, Digital forensics and incident response: incident response techniques and procedures to respond to modern cyber threats

    G. Johansen, Digital forensics and incident response: incident response techniques and procedures to respond to modern cyber threats. Packt Pub- lishing Ltd, 2020

  39. [46]

    Integrated moving target defense and control reconfiguration for securing cyber-physical systems,

    B. Potteiger, Z. Zhang, and X. Koutsoukos, “Integrated moving target defense and control reconfiguration for securing cyber-physical systems,” Microprocessors and microsystems, vol. 73, p. 102954, 2020

  40. [47]

    Automated windows behavioral tracing for malware analysis,

    S. Rana, N. Kumar, A. Handa, and S. K. Shukla, “Automated windows behavioral tracing for malware analysis,”Security and Privacy, vol. 5, no. 6, p. e253, 2022

  41. [48]

    Comprehensive research on mobile application security as- sessment,

    M. Nagarajan, R. L. N. Dinesh, R. Selvan, M. Nagamaiah, and K. V. P. Anjaneyulu, “Comprehensive research on mobile application security as- sessment,” in 2025 International Conference on Computational Robotics, Testing and Engineering Evaluation (ICCRTEE) . IEEE, 2025, pp. 1–6

  42. [49]

    Mobile application security using static and dynamic analysis,

    H. Shahriar, C. Zhang, M. A. Talukder, and S. Islam, “Mobile application security using static and dynamic analysis,” inMachine intelligence and big data analytics for cybersecurity applications . Springer, 2020, pp. 443–459

  43. [50]

    Boyraz, Endpoint Detection and Response Essentials: Explore the land- scape of hacking, defense, and deployment in EDR

    G. Boyraz, Endpoint Detection and Response Essentials: Explore the land- scape of hacking, defense, and deployment in EDR . Packt Publishing Ltd, 2024

  44. [51]

    Beacon: A bayesian optimization strategy for novelty search in expensive black-box systems,

    W.-T. Tang, A. Chakrabarty, and J. A. Paulson, “Beacon: A bayesian optimization strategy for novelty search in expensive black-box systems,” arXiv preprint arXiv:2406.03616 , 2024

  45. [52]

    Department of defense law of war manual,

    S. E. Preston and R. S. Taylor, “Department of defense law of war manual,” 2016

  46. [53]

    Legal regulation of cyber warfare: reviewing the contribution of the tallinn manual to the advancement of international law,

    M. Sang, “Legal regulation of cyber warfare: reviewing the contribution of the tallinn manual to the advancement of international law,” 2015

  47. [54]

    The use and legality of honeypots, tracers and trackers in active cyber defence,

    B. Walker-Munro, A. Cox, G. Haroway, J. Otway, D. Unwin, and S. D. Bachmann, “The use and legality of honeypots, tracers and trackers in active cyber defence,” The Commonwealth Cyber Journal, vol. 3, pp. 5–18, 2025. 25

  48. [55]

    The vital role of international law in the framework for responsible state behaviour in cyberspace,

    H. Moynihan, “The vital role of international law in the framework for responsible state behaviour in cyberspace,” Journal of Cyber Policy, vol. 6, no. 3, pp. 394–410, 2021

  49. [56]

    Operations security (opsec) guide

    W. S. M. RANGE, R. T. SITE, Y. P. GROUND, D. P. GROUND, A. T. CENTER, E. P. GROUND, A. F. F. T. CENTER, A. A. CENTER, and B. M. G. RANGE, “Operations security (opsec) guide.”

  50. [57]

    Implementing data exfiltration defense in situ: a sur- vey of countermeasures and human involvement,

    M.-H. Chung, Y. Yang, L. Wang, G. Cento, K. Jerath, A. Raman, D. Lie, and M. H. Chignell, “Implementing data exfiltration defense in situ: a sur- vey of countermeasures and human involvement,” acm computing surveys , vol. 55, no. 14s, pp. 1–37, 2023

  51. [58]

    The ai-based cyber threat landscape: A survey,

    N. Kaloudi and J. Li, “The ai-based cyber threat landscape: A survey,” ACM Computing Surveys (CSUR) , vol. 53, no. 1, pp. 1–34, 2020

  52. [59]

    Ai-assisted computer network operations testbed for nature-inspired cyber security based adaptive defense simulation and analysis,

    S. K. Shandilya, S. Upadhyay, A. Kumar, and A. K. Nagar, “Ai-assisted computer network operations testbed for nature-inspired cyber security based adaptive defense simulation and analysis,” Future Generation Com- puter Systems, vol. 127, pp. 297–308, 2022

  53. [60]

    Llms killed the script kiddie: How agents supported by large language models change the landscape of network threat testing,

    S. Moskal, S. Laney, E. Hemberg, and U.-M. O’Reilly, “Llms killed the script kiddie: How agents supported by large language models change the landscape of network threat testing,” arXiv preprint arXiv:2310.06936, 2023

  54. [61]

    Artificial intelligence and game theory models for defending critical networks with cyber deception,

    S. Fugate and K. Ferguson-Walter, “Artificial intelligence and game theory models for defending critical networks with cyber deception,” AI Magazine, vol. 40, no. 1, pp. 49–62, 2019

  55. [62]

    Leveraging computational intelligence techniques for defensive deception: a review, recent advances, open problems and future directions,

    P. V. Mohan, S. Dixit, A. Gyaneshwar, U. Chadha, K. Srinivasan, and J. T. Seo, “Leveraging computational intelligence techniques for defensive deception: a review, recent advances, open problems and future directions,” Sensors, vol. 22, no. 6, p. 2194, 2022

  56. [63]

    Steganography an art of hiding data,

    S. Channalli and A. Jadhav, “Steganography an art of hiding data,” arXiv preprint arXiv:0912.2319, 2009

  57. [64]

    Language-based control and mitigation of timing channels,

    D. Zhang, A. Askarov, and A. C. Myers, “Language-based control and mitigation of timing channels,” in Proceedings of the 33rd ACM SIGPLAN conference on Programming Language Design and Implementation , 2012, pp. 99–110

  58. [65]

    Mimichunter: A general passive network protocol mimicry detection framework,

    Z. Cao, G. Xiong, and L. Guo, “Mimichunter: A general passive network protocol mimicry detection framework,” in 2015 IEEE Trust- com/BigDataSE/ISPA, vol. 1. IEEE, 2015, pp. 271–278

  59. [66]

    A systematic review of ad- versarial machine learning attacks, defensive controls, and technologies,

    J. Malik, R. Muthalagu, and P. M. Pawar, “A systematic review of ad- versarial machine learning attacks, defensive controls, and technologies,” IEEE Access, vol. 12, pp. 99 382–99 421, 2024. 26

  60. [67]

    Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense,

    A. Alotaibi and M. A. Rassam, “Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense,” Future Internet, vol. 15, no. 2, p. 62, 2023

  61. [68]

    Evading a machine learning-based intrusion detection system through adversarial perturbations,

    T. Fladby, H. Haugerud, S. Nichele, K. Begnum, and A. Yazidi, “Evading a machine learning-based intrusion detection system through adversarial perturbations,” in Proceedings of the International Conference on Research in Adaptive and Convergent Systems , 2020, pp. 161–166

  62. [69]

    Owning mistakes sincerely: Strategies for mitigating ai errors,

    A. Mahmood, J. W. Fung, I. Won, and C.-M. Huang, “Owning mistakes sincerely: Strategies for mitigating ai errors,” in Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems , 2022, pp. 1–11

  63. [70]

    Legal compliance in corporate governance frameworks: Best practices for ensuring transparency, accountability, and risk mitigation,

    K. Akinsola, “Legal compliance in corporate governance frameworks: Best practices for ensuring transparency, accountability, and risk mitigation,” Accountability, and Risk Mitigation (January 31, 2025) , 2025

  64. [71]

    Ethics of ai and cybersecurity when sovereignty is at stake,

    P. Timmers, “Ethics of ai and cybersecurity when sovereignty is at stake,” Minds and Machines , vol. 29, no. 4, pp. 635–645, 2019

  65. [72]

    National power after ai,

    M. Daniels and B. Chang, “National power after ai,” Center for Security and Emerging Technology, pp. 1–30, 2021

  66. [73]

    A review of quantum cybersecurity: threats, risks and opportunities,

    M. J. H. Faruk, S. Tahora, M. Tasnim, H. Shahriar, and N. Sakib, “A review of quantum cybersecurity: threats, risks and opportunities,” in 2022 1st International Conference on AI in Cybersecurity (ICAIC) . IEEE, 2022, pp. 1–8

  67. [74]

    Algorithms for quantum computation: discrete logarithms and factoring,

    P. W. Shor, “Algorithms for quantum computation: discrete logarithms and factoring,” in Proceedings 35th annual symposium on foundations of computer science. Ieee, 1994, pp. 124–134

  68. [75]

    Introduction to post-quantum cryptography,

    D. J. Bernstein et al., “Introduction to post-quantum cryptography,” Post- quantum cryptography, vol. 1, pp. 1–10, 2009

  69. [76]

    Status report on the second round of the nist post-quantum cryptography standardization process,

    G. Alagic, J. Alperin-Sheriff, D. Apon, D. Cooper, Q. Dang, J. Kelsey, Y.- K. Liu, C. Miller, D. Moody, R. Peralta et al., “Status report on the second round of the nist post-quantum cryptography standardization process,” US Department of Commerce, NIST , vol. 2, p. 69, 2020

  70. [78]

    Management of the chain of custody of digital evidence using blockchain and self-sovereign identities: A systematic literature review,

    L. Loffi, G. L. Camillo, C. A. De Souza, C. M. Westphall, and C. B. Westphall, “Management of the chain of custody of digital evidence using blockchain and self-sovereign identities: A systematic literature review,” IEEE Access, 2025

  71. [79]

    Structural code graphing for automated ransomware detection using novel quantum graph-spectral fingerprinting,

    E. Watts, A. Worthington, E. Sheffield, and C. Featherstone, “Structural code graphing for automated ransomware detection using novel quantum graph-spectral fingerprinting,” 2024. 27

  72. [80]

    A fast quantum mechanical algorithm for database search,

    L. K. Grover, “A fast quantum mechanical algorithm for database search,” in Proceedings of the twenty-eighth annual ACM symposium on Theory of computing, 1996, pp. 212–219

  73. [81]

    Quantum machine learning,

    J. Biamonte, P. Wittek, N. Pancotti, P. Rebentrost, N. Wiebe, and S. Lloyd, “Quantum machine learning,” Nature, vol. 549, no. 7671, pp. 195–202, 2017

  74. [82]

    An introduction to practical quan- tum key distribution,

    O. Amer, V. Garg, and W. O. Krawec, “An introduction to practical quan- tum key distribution,” IEEE Aerospace and Electronic Systems Magazine , vol. 36, no. 3, pp. 30–55, 2021

  75. [83]

    Satellite-to-ground quantum key distri- bution,

    S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. Ren, J. Yin, Q. Shen, Y. Cao, Z.-P. Li et al. , “Satellite-to-ground quantum key distri- bution,” Nature, vol. 549, no. 7670, pp. 43–47, 2017

  76. [84]

    Designing a quantum network protocol,

    W. Kozlowski, A. Dahlberg, and S. Wehner, “Designing a quantum network protocol,” in Proceedings of the 16th international conference on emerging networking experiments and technologies , 2020, pp. 1–16

  77. [85]

    (2025, Jun.) Quantum data centre of the future

    NCC Group. (2025, Jun.) Quantum data centre of the future. Accessed: 2025-08-06. [Online]. Available: https://www.nccgroup.com/research- blog/quantum-data-centre-of-the-future/

  78. [86]

    Act as a honeytoken generator! an investigation into honeytoken generation with large language models,

    D. Reti, N. Becker, T. Angeli, A. Chattopadhyay, D. Schneider, S. Vollmer, and H. D. Schotten, “Act as a honeytoken generator! an investigation into honeytoken generation with large language models,” in Proceedings of the 11th ACM Workshop on Adaptive and Autonomous Cyber Defe...

  79. [87]

    Honey encryption: Security beyond the brute- force bound,

    A. Juels and T. Ristenpart, “Honey encryption: Security beyond the brute- force bound,” in Annual international conference on the theory and appli- cations of cryptographic techniques. Springer, 2014, pp. 293–310

  80. [88]

    The malicious use of arti- ficial intelligence: Forecasting, prevention, and mitigation,

    M. Brundage, S. Avin, J. Clark, H. Toner, P. Eckersley, B. Garfinkel, A. Dafoe, P. Scharre, T. Zeitzoff, B. Filar et al., “The malicious use of arti- ficial intelligence: Forecasting, prevention, and mitigation,” arXiv preprint arXiv:1802.07228, 2018. 28

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.