Ai helps prioritize cyberattack risks in industrial networks

AI-Based Vulnerability Assessment Capability and Cyber Attack Graph Analysis

Cryptography and Security

Summary

Cyberattacks on important infrastructure are getting trickier, and traditional defenses like firewalls often can't keep up. The authors studied two advanced AI methods that analyze how attacks might happen across networked systems and which parts are most vulnerable. Both methods agreed on the weak spots and attack paths found in a real-world 2015 cyberattack on Ukraine’s power grid, confirming their usefulness. This combined approach helps defenders decide which systems to protect first, efficiently managing resources and improving security.

What this means in practice

  • For enterprise cybersecurity teams: Use combined AI-driven methods to identify and prioritize network vulnerabilities for focused defensive actions in large operational technology environments.
  • For industrial control system operators: Pinpoint critical ICS devices that enable attack spread to prioritize hardening efforts and reduce system-wide risk in manufacturing and utilities.

Authors

Joni Herttuainen, Kirsi Hellsten, Vesa Kuikka, Ambrose Kam, Arlanda Johnson, David Welsh, Kimmo K. Kaski

Abstract

Cyber threats targeting mission-critical infrastructure are becoming more sophisticated while the barrier to launching attacks continues to fall. Traditional point solutions like antivirus and firewalls are reactive and fail to address the combinatorial complexity of modern attack surfaces. This paper presents an investigation combining two complementary methodologies: Lockheed Martin's Vortex/Crow framework, which applies multi-agent reinforcement learning (MARL) over industry-standard cyber knowledge graph to identify and prioritize attack vectors and TTPs (tactics, techniques, and procedures); and Aalto's probabilistic attack graph model that combines network topology and its vulnerabilities to compute system-level risk metrics. The 2015 Ukraine Power Grid cyberattack serves as a well-documented validation scenario. Applied independently to the same operational technology (OT) network topology, both methodologies converge on the same attack vectors and exploit sequences as those documented in the incident record, thus providing mutual cross-validation. Attack graph analyses using node-level elimination experiments identify industrial control systems (ICS) as the most critical enablers of attack propagation, representing high-priority targets for defensive hardening. Comparison of CVSS (v2.0) and IronMiner vulnerability scoring yields in general consistent results, with IronMiner providing more actionable differentiation at network periphery nodes. The layered methodology of baseline assessment and node-level elimination proves to be scalable to large enterprise networks, thus offering defenders a structured, AI-enabled path to prioritize mitigation under realistic time and resource constraints.