Researchers at Colorado State University have developed iEXAM, an AI-powered tool that helps cybersecurity professionals understand and strengthen network defenses. The system explains how hackers could break into a network and suggests practical ways to stop them. iEXAM helps users test different “what-if” scenarios to see how changes might make a network safer. It also gives clear explanations of why specific defenses work, making it easier for system administrators to act. The result is a more secure, better understood, and more resilient network.
Cyber attacks are increasing in frequency and sophistication, yet many tools fall short in helping administrators understand vulnerabilities or test different defense options. Traditional attack graph tools often make unrealistic assumptions and do not factor in network connectivity or real-time updates. They also lack the ability to reason with incomplete information or provide understandable explanations for system administrators. The monotonicity assumption (which assumes attackers never move backwards), common in previous work, also limits the modeling of complex attacker behaviors like revisiting nodes or launching attacks from specific hosts, which can lead to an incomplete understanding of potential threats.
iEXAM (Instructable and EXplainable AI for Cybersecurity Analysis and Management) is a novel software framework that integrates AI planning with cybersecurity modeling. It introduces a next-generation attack graph that accounts for both network vulnerabilities and connectivity, overcoming limitations of traditional models like monotonicity.
The iEXAM tool translates network configurations and vulnerability data into formal models using the Planning Domain Definition Language (PDDL). These models enable automated identification of attack paths and generate defensive strategies that make attacks either impossible (impenetrability) or significantly harder (increased attack cost). Notably, iEXAM can identify multiple diverse strategies so administrators can choose the most feasible for their systems. It also supports what-if analysis and provides human-readable explanations, helping users understand and refine their cyber defenses interactively.
In empirical testing, iEXAM handled complex networks efficiently, producing optimal defensive plans even as the number of nodes and vulnerabilities increased. For example, in a simulated network of 30 nodes, the tool consistently generated solutions with significantly lower computational time when guided by its custom heuristic algorithm (Table 1).
Available for Exclusive Licensing
TRL: 4
US Provisional Patent
Indrajit Ray
Sarath Sreedharan
Indrakshi Ray
Rakesh Podder
Shadaab Kawnain Bashir
Turgay Caglar
Aly Hoeher
Aly.Hoeher@colostate.edu
970-491-7100