REVIEW 4 major objections 5 minor 88 references
Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment
T0 review · 4 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read Passive hack-back—beacons, honeytokens, and decoy payloads—can attribute attackers covertly and lawfully in denied environments.
desk verdict A useful taxonomy of passive hack-back techniques undermined by an unargued legal claim that the whole 'lawful pathway' conclusion rests on. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying mechanism is the passive trigger point: a deceptive artifact placed inside stolen or leaked data that fires only when the attacker interacts with it in a foreign environment. The paper formalizes this through seven pre-assumptions and maps each to the vectors it enables, so the taxonomy is organized around what the defender can assume rather than around attacker infrastructure. Environment fingerprinting and time delays act as safety interlocks so the trigger does not fire on the defender's own network, and a return channel—DNS, HTTP(S), API calls, or externally logged fake credentials—carries telemetry back. AI and LLM components extend the same machinery by generating context-aware payloads at runtime, and post-quantum cryptography is proposed to protect the return channel and the integrity of collected evidence.
What would settle it
Run the paper's own prototype vectors against a disciplined adversary playbook: a network-isolated virtual machine with no egress except a monitored proxy, metadata scrubbing before any file is opened, and a policy of never using unknown credentials. If, over many trials, the DOCX beacon, APK asset, and honey SSH key yield zero callbacks and zero logins, the central claim is falsified. A field-scale version would plant a realistic batch of beaconed files in a controlled leak and measure callback rates from known threat-actor groups.
Extended reading notes
Core claim
The paper's central claim is that a coherent family of passive hack-back vectors can achieve covert cyber attribution in denied environments, where the defender knows nothing about the attacker's IP, route, or infrastructure and is barred from initiating contact. The proposed mechanism is to embed triggers in the assets the attacker is assumed to have exfiltrated—documents, credentials, source code, mobile packages—so that the attacker's own act of opening, building, or using those assets fires a callback to defender-controlled infrastructure. The paper catalogs the vector classes, maps each to an explicit pre-assumption about attacker behavior, and reports prototype evaluations in simulated attacker environments, with high beacon callback success and low detection. On the legal side, it argues that because no unauthorized access or disruption occurs, these techniques fit within the constraints that make active hack-back unlawful. It further contends that LLM-generated payloads, autonomous forensic agents, and adversarial machine learning can make the triggers adaptive, while quantum technologies are a future threat to telemetry cryptography and a future tool for covert communication.
Load-bearing premise
The load-bearing premise is that the attacker will actually open, run, or otherwise use the stolen data in a way that fires the embedded trigger and sends telemetry back; if the attacker analyzes the files in an isolated, instrumented environment or never touches the decoy credentials, the entire passive attribution chain stays silent.
Editorial extensions
If this is right
- If the central claim holds, defenders in legally restricted settings gain an attribution channel that does not require knowing the attacker's infrastructure or touching it directly.
- Document, credential, and mobile-package lures become general-purpose sensors: every callback is a signal that can be correlated across incidents to profile an adversary's tooling, locale, and workflows.
- Environment-specific triggers and manual arming make it possible to deploy these lures at scale without high rates of self-triggering inside the defender's own estate.
- AI-generated payloads imply that attribution fidelity need not be fixed at design time: the payload can adapt to the attacker's observed environment before reporting back.
- Hybrid frameworks become feasible: passive attribution can feed confidence thresholds that authorize delayed, conditional, legally vetted active responses.
Reading between the lines
- The same baiting logic should transfer to insider-threat and supply-chain scenarios, where the 'attacker' is a trusted user or downstream vendor and the trigger point is the same: interaction with a decoy asset.
- A sophisticated adversary who routinely inspects exfiltrated files in network-isolated sandboxes, strips metadata, and avoids using unknown credentials would starve every vector in the taxonomy; the framework therefore predicts an observable arms race in which attribution success tracks attacker OPSEC discipline.
- One testable extension is a controlled-leak experiment: release a batch of beaconed files and honey credentials through a realistic compromise, then measure callback rate and time-to-first-trigger across different threat-actor profiles.
- The legal framing implicitly assumes that passive collection from a foreign system does not itself cross a sovereignty line; if courts or states treat covert beacons as unauthorized access, the 'lawful' part of the claim would need re-examination.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This perspective paper argues that "passive hack-back"---using tracking beacons, honeytokens, environment-specific payloads, and AI-enhanced agents---offers a lawful and effective route to cyber attribution in denied environments. It defines seven pre-assumptions, maps them to a taxonomy of passive vectors (Section 4), describes prototype DOCX, APK, and credential-file payloads (Section 5.1), discusses legal, ethical, and operational constraints (Section 6), and explores AI and quantum enhancements (Sections 7--8). The central claim, stated in the Conclusion (Section 10), is that passive mechanisms "offer a stealthy and lawful pathway to attribution and intelligence gathering, without the risks typically associated with active countermeasures."
Significance. If the lawfulness and effectiveness claims were established, this would be a useful organizing framework for defenders operating under strict rules of engagement. The paper's strengths are its explicit pre-assumption mapping (Tables 1--2), a clear taxonomy of vectors, and honest limitations sections (e.g., Section 8.4 for quantum and Section 7.6 for AI governance). However, the contribution is a perspective, not a validated technical result, and its significance is currently bounded by two gaps: the legal basis for embedded beacons that execute on the attacker's machine is asserted rather than argued, and the effectiveness evaluation in Section 5.3 is qualitative with no reported measurements.
major comments (4)
- [Section 6.1 and Section 5.1] The claim that the described vectors are lawful rests on an unsupported and internally inconsistent premise. Section 6.1 asserts that honeytokens and embedded beacons "are typically considered lawful if they do not involve unauthorized access or system disruption," but Section 5.1 describes a DOCX with a hidden remote-image callback and an APK that "silently initiates a DNS request when the app is installed or run," and Section 7.1 contemplates agents "deployed within the attacker's infrastructure." Causing code to execute on the attacker's device after the attacker opens or installs the artifact is not the same as passive observation; the paper never explains why the attacker's act of opening or installing constitutes authorization for the embedded payload to carry out network callbacks or reconnaissance. Because the Conclusion's "lawful pathway" depends on this point, the legal half of the central claim is not established. The paper should either restrict the lawfulness claim to genuinely passive mechanisms (e.g., honeytoken credentials that trigger only when the attacker uses them against defender-controlled services) or provide a jurisdiction-specific analysis of why beacon execution on a third-party system is not unauthorized access.
- [Section 5.3 and Section 10] The effectiveness half of the central claim is not supported by the reported evaluation. Section 5.3 defines three metrics--callback success rate, attribution fidelity, and stealth level--but then states only that "experimental results showed that all three prototype vectors achieved high callback success rates" and that attribution fidelity "yielded useful telemetry in the majority of cases." No actual rates, sample sizes, detection counts, or confidence intervals are provided, and no comparison to a baseline is given. Since the Conclusion claims these mechanisms "offer a stealthy and lawful pathway to attribution," the evaluation should either report the measured values or be explicitly labeled as a qualitative feasibility demonstration rather than an evaluation.
- [Section 1.1.1 and Section 10] The Conclusion overstates the robustness of the approach relative to the paper's own Pre-Assumption 3 ("The Attacker Will Interact with the Data in a Vulnerable or Traceable Way"). If the attacker analyzes exfiltrated data in an air-gapped or instrumented environment, scrubs metadata, or never opens the decoy assets, the beacons and honeytokens never fire and no attribution is produced. Table 1 itself rates several conditional assumptions as only Medium or Low usefulness. The unqualified language in the Conclusion should be revised to state explicitly that the claimed pathway is conditional on the attacker's interaction with the stolen data, which is a behavioral premise outside the defender's control.
- [Section 7.1 and Section 2] The description of autonomous agents contradicts the paper's own threat model and pre-assumptions. Section 7.1 says AI-powered agents "can be covertly embedded into exfiltrated data or decoy software. Once deployed within the attacker's infrastructure," while Section 2 states that defensive actions avoid "direct contact with attacker infrastructure" and Pre-Assumption 4 says "Defender Cannot Initiate Contact." The paper does not explain the mechanism by which an agent embedded in a stolen file transitions from being a triggered payload to being "deployed within the attacker's infrastructure" without active propagation or unauthorized access. This tension affects the coherence of the proposed AI-enhanced vectors and should be resolved by either clarifying the deployment mechanism or removing the claim that such agents remain within passive constraints.
minor comments (5)
- [Section 4.2] The sentence "The concept of honeytokens, decoy data that triggers alerts upon unauthorized access, originates [36]" is grammatically incomplete; it should read "originates with [36]" or be rephrased.
- [Section 5.1] Describing an APK that "silently initiates a DNS request when the app is installed or run" as a passive vector requires justification; initiating network traffic on the attacker's device blurs the boundary between passive and active behavior, and this terminology should be revisited.
- [References] Several references appear only loosely related to the claims they support, for example [51] (a Bayesian optimization paper) and [42] (a general beacon-technology book); the authors should re-check that each citation directly supports the surrounding statement.
- [Section 6.1] The legal discussion relies on a single journal article (reference [54]) for the assertion that beacons and honeytokens are "typically considered lawful"; citing specific statutes, case law, or attorney-general guidance would strengthen this section.
- [Table 3] The row "Attribution Depth" conflates technical capability with operational value; the claim that AI-assisted methods enable "sociolinguistic inference" is presented without evidence or discussion of possible misattribution, despite the caveats in Section 7.6.
Circularity Check
No circularity: the paper is a qualitative framework with explicit assumptions; the central legality claim rests on external legal authorities, not on the paper's own outputs.
full rationale
Passive Hack-Back Strategies is a perspective and taxonomy paper: it contains no fitted parameters, no equations, no predictive model, and no uniqueness theorem. The pre-assumptions in Section 1.1.1 are explicitly stated behavioral and operational conditions, such as "The Attacker Will Interact with the Data in a Vulnerable or Traceable Way," and the described vectors are consequences of those assumptions rather than circular redeductions. The central claim that passive mechanisms offer a "stealthy and lawful pathway" is supported in Section 6.1 by external legal authorities, including the Tallinn Manual [7], the DoD Law of War Manual [52], and Walker-Munro et al. [54]; whether that support is adequate is a legal-substantiation or correctness concern, not a circularity concern. The only self-citation, Ref [77] by Weinberg and Faccia, appears in Section 8.1 and Future Work as background on post-quantum cryptography and does not carry the attribution or lawfulness argument. The prototype evaluation in Section 5.3 reports high callback success and minimal detection but provides no raw data; this is an evidence-quality and reproducibility concern, not an instance of fitting a parameter and renaming it a prediction. Therefore, no load-bearing step reduces to its own inputs, and no circularity is present.
Assumptions & free parameters
assumptions (6)
- domain assumption The attacker has exfiltrated data that includes defender-controlled assets.
- domain assumption The attacker will interact with the exfiltrated data in a traceable way (open documents, run apps, use credentials).
- domain assumption The defender cannot initiate contact with attacker infrastructure due to legal and operational constraints.
- domain assumption A return channel exists for telemetry (DNS, HTTP, or credential logs).
- domain assumption The attacker is not immediately aware of the deception embedded in the stolen data.
- domain assumption Passive beacons and honeytokens are lawful under relevant jurisdictions.
Cite this review
Pith. "Pith review of Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment." pith.science (2026). https://pith.science/paper/B53Y7E3W
@misc{pith2026250816637,
author = {Pith},
title = {Pith review of: Passive Hack-Back Strategies for Cyber Attribution: Covert Vectors in Denied Environment},
year = {2026},
howpublished = {\url{https://pith.science/paper/B53Y7E3W}},
note = {Machine review of arXiv:2508.16637}
}
read the original abstract
Attributing cyberattacks remains a central challenge in modern cybersecurity, particularly within denied environments where defenders have limited visibility into attacker infrastructure and are restricted by legal or operational rules of engagement. This perspective examines the strategic value of passive hack-back techniques that enable covert attribution and intelligence collection without initiating direct offensive actions. Key vectors include tracking beacons, honeytokens, environment-specific payloads, and supply-chain-based traps embedded within exfiltrated or leaked assets. These approaches rely on the assumption that attackers will interact with compromised data in traceable ways, allowing defenders to gather signals without violating engagement policies. The paper also explores the role of Artificial Intelligence (AI) in enhancing passive hack-back operations. Topics include the deployment of autonomous agents for forensic reconnaissance, the use of Large Language Models (LLMs) to generate dynamic payloads, and Adversarial Machine Learning (AML) techniques for evasion and counter-deception. A dedicated section discusses the implications of quantum technologies in this context, both as future threats to cryptographic telemetry and as potential tools for stealthy communication and post-quantum resilience. Finally, the paper advocates for hybrid defensive frameworks that combine passive attribution with delayed or conditional active responses, while maintaining compliance with legal, ethical, and operational constraints.
Reference graph
Works this paper leans on
-
[77]
Quantum Algorithms: A New Frontier in Financial Crime Prevention
A. I. Weinberg and A. Faccia, “Quantum algorithms: A new frontier in financial crime prevention,” arXiv preprint arXiv:2403.18322 , 2024
work page Pith review arXiv 2024
-
[1]
Varsalone and C
J. Varsalone and C. Haller, The Hack is Back: Techniques to Beat Hackers at Their Own Games . CRC Press, 2024
2024
-
[2]
The ethics of hacking back,
C. T. Holzer and J. E. Lerums, “The ethics of hacking back,” in 2016 IEEE Symposium on Technologies for Homeland Security (HST) . IEEE, 2016, pp. 1–6
2016
-
[3]
Framework and principles for active cyber defense,
D. E. Denning, “Framework and principles for active cyber defense,” Com- puters & Security , vol. 40, pp. 108–113, 2014. 21
2014
-
[4]
Brown and S
R. Brown and S. J. Roberts, Intelligence-Driven Incident Response . ” O’Reilly Media, Inc.”, 2023
2023
-
[5]
An enhanced cyber attack attribution frame- work,
N. Pitropakis, E. Panaousis, A. Giannakoulias, G. Kalpakis, R. D. Ro- driguez, and P. Sarigiannidis, “An enhanced cyber attack attribution frame- work,” in International Conference on Trust and Privacy in Digital Busi- ness. Springer, 2018, pp. 213–228
2018
-
[6]
Attributing cyber attacks,
T. Rid and B. Buchanan, “Attributing cyber attacks,” Journal of strategic studies, vol. 38, no. 1-2, pp. 4–37, 2015
2015
-
[7]
M. N. Schmitt, Tallinn manual 2.0 on the international law applicable to cyber operations. Cambridge University Press, 2017
2017
Show all 88 references
-
[8]
The dod law of war manual and its critics: some obser- vations,
C. J. Dunlap Jr, “The dod law of war manual and its critics: some obser- vations,” International Law Studies , vol. 92, p. 85, 2016
2016
-
[9]
Honeywords: Making password-cracking de- tectable,
A. Juels and R. L. Rivest, “Honeywords: Making password-cracking de- tectable,” in Proceedings of the 2013 ACM SIGSAC conference on Com- puter & communications security , 2013, pp. 145–160
2013
-
[10]
Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions,
T. Zhukabayeva, L. Zholshiyeva, N. Karabayev, S. Khan, and N. Alnazzawi, “Cybersecurity solutions for industrial internet of things–edge computing integration: Challenges, threats, and future directions,” Sensors, vol. 25, no. 1, p. 213, 2025
2025
-
[11]
Weaving tangled webs: offense, defense, and deception in cyberspace,
E. Gartzke and J. R. Lindsay, “Weaving tangled webs: offense, defense, and deception in cyberspace,” Security Studies, vol. 24, no. 2, pp. 316–348, 2015
2015
-
[12]
Goldsmith, The United States’ Defend Forward Cyber Strategy: A Com- prehensive Legal Assessment
J. Goldsmith, The United States’ Defend Forward Cyber Strategy: A Com- prehensive Legal Assessment. Oxford University Press, 2022
2022
-
[13]
A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions,
E. M. Rudd, A. Rozsa, M. G¨ unther, and T. E. Boult, “A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions,” IEEE Communications Surveys & Tutorials, vol. 19, no. 2, pp. 1145–1172, 2016
2016
-
[14]
Z. Tari, N. Sohrabi, Y. Samadi, and J. Suaboot, Data Exfiltration threats and prevention techniques: Machine Learning and memory-based data se- curity. John Wiley & Sons, 2023
2023
-
[15]
Beyond the leak: Analyzing the real-world exploitation of stolen credentials using honeypots,
M. Rabzelj and U. Sedlar, “Beyond the leak: Analyzing the real-world exploitation of stolen credentials using honeypots,” Sensors, vol. 25, no. 12, p. 3676, 2025
2025
-
[16]
Safer and optimised vulner- ability scanning for operational technology through integrated and auto- mated passive monitoring and active scanning,
T. W. Edgar, S. Niddodi, T. R. Rice, W. J. Hofer, G. E. Seppala, K. M. Arthur-Durett, M. Engels, and D. O. Manz, “Safer and optimised vulner- ability scanning for operational technology through integrated and auto- mated passive monitoring and active scanning,” Journal of Info...
2019
-
[17]
Device fingerprinting for cyber-physical systems: A survey,
V. Kumar and K. Paul, “Device fingerprinting for cyber-physical systems: A survey,” ACM Computing Surveys , vol. 55, no. 14s, pp. 1–41, 2023
2023
-
[18]
Hutchens, The language of deception: weaponizing next Generation AI
J. Hutchens, The language of deception: weaponizing next Generation AI . John Wiley & Sons, 2023
2023
-
[19]
Synoptic analysis techniques for intrusion detection in wireless networks,
D. T. Hlavacek, “Synoptic analysis techniques for intrusion detection in wireless networks,” Ph.D. dissertation, Iowa State University, 2015
2015
-
[20]
Research and application of indoor positioning method based on fixed infrared beacon,
W. Yao and L. Ma, “Research and application of indoor positioning method based on fixed infrared beacon,” in 2018 37th Chinese Control Conference (CCC). IEEE, 2018, pp. 5375–5379
2018
-
[21]
Baiting inside attackers using decoy documents,
B. M. Bowen, S. Hershkop, A. D. Keromytis, and S. J. Stolfo, “Baiting inside attackers using decoy documents,” in International Conference on Security and Privacy in Communication Systems . Springer, 2009, pp. 51–70
2009
-
[22]
Mitre engage: A framework and community for cy- ber deception,
B. Eidson, “Mitre engage: A framework and community for cy- ber deception,” Feb. 2022, accessed: 2025-08-05. [Online]. Avail- able: https://www.mitre.org/news-insights/impact-story/mitre-engage- framework-and-community-cyber-deception
2022
-
[23]
Diogenes and E
Y. Diogenes and E. Ozkaya, Cybersecurity–Attack and Defense Strategies: Improve your security posture to mitigate risks and prevent attackers from infiltrating your system . Packt Publishing Ltd, 2022
2022
-
[24]
Hacking the hackers: Offensive security strategies in modern cyber defense,
Z. Huma, “Hacking the hackers: Offensive security strategies in modern cyber defense,” Journal of Data and Digital Innovation (JDDI) , vol. 2, no. 2, pp. 126–132, 2025
2025
-
[25]
A critique of active defense or ‘hack back’,
A. Caldwell and K. Curran, “A critique of active defense or ‘hack back’,” International Journal for Information Security Research, vol. 10, no. 1, pp. 957–961, 2020
2020
-
[26]
Exploring the use of ethical hacking techniques in strength- ening organizational cybersecurity defenses,
A. Smith, “Exploring the use of ethical hacking techniques in strength- ening organizational cybersecurity defenses,” Global Research Perspectives on Cybersecurity Governance, Policy, and Management , vol. 8, no. 12, pp. 1–11, 2024
2024
-
[27]
Advancing cybersecurity with honey- pots and deception strategies,
Z. Mori´ c, V. Daki´ c, and D. Regvart, “Advancing cybersecurity with honey- pots and deception strategies,” in Informatics, vol. 12, no. 1. MDPI AG, 2025, p. 14
2025
-
[28]
Optimizing internet of things honeypots with ma- chine learning: A review,
S. Lanz, S. L.-R. Pignol, P. Schmitt, H. Wang, M. Papaioannou, G. Choud- hary, and N. Dragoni, “Optimizing internet of things honeypots with ma- chine learning: A review,” Applied Sciences, vol. 15, no. 10, p. 5251, 2025
2025
-
[29]
A comprehensive survey of advanced persistent threat attribution: Taxonomy, methods, challenges and open research problems,
N. Rani, B. Saha, and S. K. Shukla, “A comprehensive survey of advanced persistent threat attribution: Taxonomy, methods, challenges and open research problems,” arXiv preprint arXiv:2409.11415 , 2024. 23
2024 arXiv
-
[30]
Cyber threat intelligence sharing: Survey and research directions,
T. D. Wagner, K. Mahbub, E. Palomar, and A. E. Abdallah, “Cyber threat intelligence sharing: Survey and research directions,” Computers & Secu- rity, vol. 87, p. 101589, 2019
2019
-
[31]
An anomaly detection model for multivariate time series with anomaly perception,
D. Wei, W. Sun, X. Zou, D. Ma, H. Xu, P. Chen, C. Yang, M. Chen, and H. Li, “An anomaly detection model for multivariate time series with anomaly perception,” PeerJ Computer Science, vol. 10, p. e2172, 2024
2024
-
[32]
Criminalizing hacking, not dating: Reconstructing the cfaa in- tent requirement,
D. Thaw, “Criminalizing hacking, not dating: Reconstructing the cfaa in- tent requirement,” J. Crim. L. & Criminology , vol. 103, p. 907, 2013
2013
-
[33]
Cyber intelligence,
F. Lemieux, “Cyber intelligence,” in Intelligence and State Surveillance in Modern Societies: An International Perspective . Emerald Publishing Limited, 2024, pp. 171–184
2024
-
[34]
Miller and T
S. Miller and T. Bossomaier, Cybersecurity, ethics, and collective responsi- bility. Oxford University Press, 2024
2024
-
[35]
Honeytokens: The other honeypot,
L. Spitzner, “Honeytokens: The other honeypot,” 2003
2003
-
[36]
Data-level cyber deception in cloud of things: Prospects, issues, and challenges,
N. Prabhaker, G. S. Bopche, and M. Arock, “Data-level cyber deception in cloud of things: Prospects, issues, and challenges,” in Cloud of Things . Chapman and Hall/CRC, 2024, pp. 173–191
2024
-
[37]
Intrusion detection system using honey token based encrypted pointers to mitigate cyber threats for critical infras- tructure networks,
M. K. Asif and Y. S. Al-Harthi, “Intrusion detection system using honey token based encrypted pointers to mitigate cyber threats for critical infras- tructure networks,” in 2014 IEEE International Conference on Systems, Man, and Cybernetics (SMC) . IEEE, 2014, pp. 1266–1270
2014
-
[38]
A survey of parser differential anti-patterns,
S. Ali and S. W. Smith, “A survey of parser differential anti-patterns,” in 2023 IEEE Security and Privacy Workshops (SPW) . IEEE, 2023, pp. 105–116
2023
-
[39]
Time traps in supply chains: Is optimal still good enough?
F. Dunke, I. Heckmann, S. Nickel, and F. Saldanha-da Gama, “Time traps in supply chains: Is optimal still good enough?” European Journal of Operational Research, vol. 264, no. 3, pp. 813–829, 2018
2018
-
[40]
Steganography: Unveil- ing techniques and research agenda,
A. Kumar, S. Tandon, S. Deorari, and R. Kumar, “Steganography: Unveil- ing techniques and research agenda,” 2024
2024
-
[41]
M. A. Shhadih, Cyber Deception Techniques and an Adversary Engage- ment Platform for Cybersecurity Enhancement . The George Washington University, 2023
2023
-
[42]
Statler, A
S. Statler, A. Audenaert, J. Coombs, T. Gordon, P. Hendrix, K. Kolodziej, P. Leddy, B. Parker, M. Proietti, and R. Rotolo, Beacon technologies. Springer, 2016. 24
2016
-
[43]
Secure cloud-based mobile apps: attack taxonomy, re- quirements, mechanisms, tests and automation,
F. T. Chimuco, J. B. Sequeiros, C. G. Lopes, T. M. Sim˜ oes, M. M. Freire, and P. R. Inacio, “Secure cloud-based mobile apps: attack taxonomy, re- quirements, mechanisms, tests and automation,” International Journal of Information Security, vol. 22, no. 4, pp. 833–867, 2023
2023
-
[44]
Malware dy- namic analysis evasion techniques: A survey,
A. Afianian, S. Niksefat, B. Sadeghiyan, and D. Baptiste, “Malware dy- namic analysis evasion techniques: A survey,” ACM Computing Surveys (CSUR), vol. 52, no. 6, pp. 1–28, 2019
2019
-
[45]
Johansen, Digital forensics and incident response: incident response techniques and procedures to respond to modern cyber threats
G. Johansen, Digital forensics and incident response: incident response techniques and procedures to respond to modern cyber threats. Packt Pub- lishing Ltd, 2020
2020
-
[46]
Integrated moving target defense and control reconfiguration for securing cyber-physical systems,
B. Potteiger, Z. Zhang, and X. Koutsoukos, “Integrated moving target defense and control reconfiguration for securing cyber-physical systems,” Microprocessors and microsystems, vol. 73, p. 102954, 2020
2020
-
[47]
Automated windows behavioral tracing for malware analysis,
S. Rana, N. Kumar, A. Handa, and S. K. Shukla, “Automated windows behavioral tracing for malware analysis,”Security and Privacy, vol. 5, no. 6, p. e253, 2022
2022
-
[48]
Comprehensive research on mobile application security as- sessment,
M. Nagarajan, R. L. N. Dinesh, R. Selvan, M. Nagamaiah, and K. V. P. Anjaneyulu, “Comprehensive research on mobile application security as- sessment,” in 2025 International Conference on Computational Robotics, Testing and Engineering Evaluation (ICCRTEE) . IEEE, 2025, pp. 1–6
2025
-
[49]
Mobile application security using static and dynamic analysis,
H. Shahriar, C. Zhang, M. A. Talukder, and S. Islam, “Mobile application security using static and dynamic analysis,” inMachine intelligence and big data analytics for cybersecurity applications . Springer, 2020, pp. 443–459
2020
-
[50]
Boyraz, Endpoint Detection and Response Essentials: Explore the land- scape of hacking, defense, and deployment in EDR
G. Boyraz, Endpoint Detection and Response Essentials: Explore the land- scape of hacking, defense, and deployment in EDR . Packt Publishing Ltd, 2024
2024
-
[51]
Beacon: A bayesian optimization strategy for novelty search in expensive black-box systems,
W.-T. Tang, A. Chakrabarty, and J. A. Paulson, “Beacon: A bayesian optimization strategy for novelty search in expensive black-box systems,” arXiv preprint arXiv:2406.03616 , 2024
2024 arXiv
-
[52]
Department of defense law of war manual,
S. E. Preston and R. S. Taylor, “Department of defense law of war manual,” 2016
2016
-
[53]
Legal regulation of cyber warfare: reviewing the contribution of the tallinn manual to the advancement of international law,
M. Sang, “Legal regulation of cyber warfare: reviewing the contribution of the tallinn manual to the advancement of international law,” 2015
2015
-
[54]
The use and legality of honeypots, tracers and trackers in active cyber defence,
B. Walker-Munro, A. Cox, G. Haroway, J. Otway, D. Unwin, and S. D. Bachmann, “The use and legality of honeypots, tracers and trackers in active cyber defence,” The Commonwealth Cyber Journal, vol. 3, pp. 5–18, 2025. 25
2025
-
[55]
The vital role of international law in the framework for responsible state behaviour in cyberspace,
H. Moynihan, “The vital role of international law in the framework for responsible state behaviour in cyberspace,” Journal of Cyber Policy, vol. 6, no. 3, pp. 394–410, 2021
2021
-
[56]
Operations security (opsec) guide
W. S. M. RANGE, R. T. SITE, Y. P. GROUND, D. P. GROUND, A. T. CENTER, E. P. GROUND, A. F. F. T. CENTER, A. A. CENTER, and B. M. G. RANGE, “Operations security (opsec) guide.”
-
[57]
Implementing data exfiltration defense in situ: a sur- vey of countermeasures and human involvement,
M.-H. Chung, Y. Yang, L. Wang, G. Cento, K. Jerath, A. Raman, D. Lie, and M. H. Chignell, “Implementing data exfiltration defense in situ: a sur- vey of countermeasures and human involvement,” acm computing surveys , vol. 55, no. 14s, pp. 1–37, 2023
2023
-
[58]
The ai-based cyber threat landscape: A survey,
N. Kaloudi and J. Li, “The ai-based cyber threat landscape: A survey,” ACM Computing Surveys (CSUR) , vol. 53, no. 1, pp. 1–34, 2020
2020
-
[59]
Ai-assisted computer network operations testbed for nature-inspired cyber security based adaptive defense simulation and analysis,
S. K. Shandilya, S. Upadhyay, A. Kumar, and A. K. Nagar, “Ai-assisted computer network operations testbed for nature-inspired cyber security based adaptive defense simulation and analysis,” Future Generation Com- puter Systems, vol. 127, pp. 297–308, 2022
2022
-
[60]
Llms killed the script kiddie: How agents supported by large language models change the landscape of network threat testing,
S. Moskal, S. Laney, E. Hemberg, and U.-M. O’Reilly, “Llms killed the script kiddie: How agents supported by large language models change the landscape of network threat testing,” arXiv preprint arXiv:2310.06936, 2023
2023 arXiv
-
[61]
Artificial intelligence and game theory models for defending critical networks with cyber deception,
S. Fugate and K. Ferguson-Walter, “Artificial intelligence and game theory models for defending critical networks with cyber deception,” AI Magazine, vol. 40, no. 1, pp. 49–62, 2019
2019
-
[62]
Leveraging computational intelligence techniques for defensive deception: a review, recent advances, open problems and future directions,
P. V. Mohan, S. Dixit, A. Gyaneshwar, U. Chadha, K. Srinivasan, and J. T. Seo, “Leveraging computational intelligence techniques for defensive deception: a review, recent advances, open problems and future directions,” Sensors, vol. 22, no. 6, p. 2194, 2022
2022
-
[63]
Steganography an art of hiding data,
S. Channalli and A. Jadhav, “Steganography an art of hiding data,” arXiv preprint arXiv:0912.2319, 2009
2009 arXiv
-
[64]
Language-based control and mitigation of timing channels,
D. Zhang, A. Askarov, and A. C. Myers, “Language-based control and mitigation of timing channels,” in Proceedings of the 33rd ACM SIGPLAN conference on Programming Language Design and Implementation , 2012, pp. 99–110
2012
-
[65]
Mimichunter: A general passive network protocol mimicry detection framework,
Z. Cao, G. Xiong, and L. Guo, “Mimichunter: A general passive network protocol mimicry detection framework,” in 2015 IEEE Trust- com/BigDataSE/ISPA, vol. 1. IEEE, 2015, pp. 271–278
2015
-
[66]
A systematic review of ad- versarial machine learning attacks, defensive controls, and technologies,
J. Malik, R. Muthalagu, and P. M. Pawar, “A systematic review of ad- versarial machine learning attacks, defensive controls, and technologies,” IEEE Access, vol. 12, pp. 99 382–99 421, 2024. 26
2024
-
[67]
Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense,
A. Alotaibi and M. A. Rassam, “Adversarial machine learning attacks against intrusion detection systems: A survey on strategies and defense,” Future Internet, vol. 15, no. 2, p. 62, 2023
2023
-
[68]
Evading a machine learning-based intrusion detection system through adversarial perturbations,
T. Fladby, H. Haugerud, S. Nichele, K. Begnum, and A. Yazidi, “Evading a machine learning-based intrusion detection system through adversarial perturbations,” in Proceedings of the International Conference on Research in Adaptive and Convergent Systems , 2020, pp. 161–166
2020
-
[69]
Owning mistakes sincerely: Strategies for mitigating ai errors,
A. Mahmood, J. W. Fung, I. Won, and C.-M. Huang, “Owning mistakes sincerely: Strategies for mitigating ai errors,” in Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems , 2022, pp. 1–11
2022
-
[70]
Legal compliance in corporate governance frameworks: Best practices for ensuring transparency, accountability, and risk mitigation,
K. Akinsola, “Legal compliance in corporate governance frameworks: Best practices for ensuring transparency, accountability, and risk mitigation,” Accountability, and Risk Mitigation (January 31, 2025) , 2025
2025
-
[71]
Ethics of ai and cybersecurity when sovereignty is at stake,
P. Timmers, “Ethics of ai and cybersecurity when sovereignty is at stake,” Minds and Machines , vol. 29, no. 4, pp. 635–645, 2019
2019
-
[72]
National power after ai,
M. Daniels and B. Chang, “National power after ai,” Center for Security and Emerging Technology, pp. 1–30, 2021
2021
-
[73]
A review of quantum cybersecurity: threats, risks and opportunities,
M. J. H. Faruk, S. Tahora, M. Tasnim, H. Shahriar, and N. Sakib, “A review of quantum cybersecurity: threats, risks and opportunities,” in 2022 1st International Conference on AI in Cybersecurity (ICAIC) . IEEE, 2022, pp. 1–8
2022
-
[74]
Algorithms for quantum computation: discrete logarithms and factoring,
P. W. Shor, “Algorithms for quantum computation: discrete logarithms and factoring,” in Proceedings 35th annual symposium on foundations of computer science. Ieee, 1994, pp. 124–134
1994
-
[75]
Introduction to post-quantum cryptography,
D. J. Bernstein et al., “Introduction to post-quantum cryptography,” Post- quantum cryptography, vol. 1, pp. 1–10, 2009
2009
-
[76]
Status report on the second round of the nist post-quantum cryptography standardization process,
G. Alagic, J. Alperin-Sheriff, D. Apon, D. Cooper, Q. Dang, J. Kelsey, Y.- K. Liu, C. Miller, D. Moody, R. Peralta et al., “Status report on the second round of the nist post-quantum cryptography standardization process,” US Department of Commerce, NIST , vol. 2, p. 69, 2020
2020
-
[78]
Management of the chain of custody of digital evidence using blockchain and self-sovereign identities: A systematic literature review,
L. Loffi, G. L. Camillo, C. A. De Souza, C. M. Westphall, and C. B. Westphall, “Management of the chain of custody of digital evidence using blockchain and self-sovereign identities: A systematic literature review,” IEEE Access, 2025
2025
-
[79]
Structural code graphing for automated ransomware detection using novel quantum graph-spectral fingerprinting,
E. Watts, A. Worthington, E. Sheffield, and C. Featherstone, “Structural code graphing for automated ransomware detection using novel quantum graph-spectral fingerprinting,” 2024. 27
2024
-
[80]
A fast quantum mechanical algorithm for database search,
L. K. Grover, “A fast quantum mechanical algorithm for database search,” in Proceedings of the twenty-eighth annual ACM symposium on Theory of computing, 1996, pp. 212–219
1996
-
[81]
Quantum machine learning,
J. Biamonte, P. Wittek, N. Pancotti, P. Rebentrost, N. Wiebe, and S. Lloyd, “Quantum machine learning,” Nature, vol. 549, no. 7671, pp. 195–202, 2017
2017
-
[82]
An introduction to practical quan- tum key distribution,
O. Amer, V. Garg, and W. O. Krawec, “An introduction to practical quan- tum key distribution,” IEEE Aerospace and Electronic Systems Magazine , vol. 36, no. 3, pp. 30–55, 2021
2021
-
[83]
Satellite-to-ground quantum key distri- bution,
S.-K. Liao, W.-Q. Cai, W.-Y. Liu, L. Zhang, Y. Li, J.-G. Ren, J. Yin, Q. Shen, Y. Cao, Z.-P. Li et al. , “Satellite-to-ground quantum key distri- bution,” Nature, vol. 549, no. 7670, pp. 43–47, 2017
2017
-
[84]
Designing a quantum network protocol,
W. Kozlowski, A. Dahlberg, and S. Wehner, “Designing a quantum network protocol,” in Proceedings of the 16th international conference on emerging networking experiments and technologies , 2020, pp. 1–16
2020
-
[85]
(2025, Jun.) Quantum data centre of the future
NCC Group. (2025, Jun.) Quantum data centre of the future. Accessed: 2025-08-06. [Online]. Available: https://www.nccgroup.com/research- blog/quantum-data-centre-of-the-future/
2025
-
[86]
Act as a honeytoken generator! an investigation into honeytoken generation with large language models,
D. Reti, N. Becker, T. Angeli, A. Chattopadhyay, D. Schneider, S. Vollmer, and H. D. Schotten, “Act as a honeytoken generator! an investigation into honeytoken generation with large language models,” in Proceedings of the 11th ACM Workshop on Adaptive and Autonomous Cyber Defe...
2024
-
[87]
Honey encryption: Security beyond the brute- force bound,
A. Juels and T. Ristenpart, “Honey encryption: Security beyond the brute- force bound,” in Annual international conference on the theory and appli- cations of cryptographic techniques. Springer, 2014, pp. 293–310
2014
-
[88]
The malicious use of arti- ficial intelligence: Forecasting, prevention, and mitigation,
M. Brundage, S. Avin, J. Clark, H. Toner, P. Eckersley, B. Garfinkel, A. Dafoe, P. Scharre, T. Zeitzoff, B. Filar et al., “The malicious use of arti- ficial intelligence: Forecasting, prevention, and mitigation,” arXiv preprint arXiv:1802.07228, 2018. 28
2018 arXiv
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.