A Knowledge-Based Multi-Agent Framework for Security Control Recommendation
Carolina Fernández-Martínez, Shuaib Siddiqui, Vanesa Daza
cs.GT, cs.AI, cs.CR, cs.LG, cs.MA
Submitted: 2026-07-10
Comments: Elsevier Knowledge-Based Systems (KNOSYS), 2026
DOI: 10.1016/j.knosys.2026.116558
Code: https://github.com/usnistgov/oscal-content
License: http://creativecommons.org/licenses/by-nc-sa/4.0/
The gist: Hardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise.
Terminology
Abstract
Hardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise. In this regard, Decision Support Systems (DSS) with embedded expert knowledge can assist users by guiding them with security recommendations to meet their objectives. This work proposes a Security DSS that recommends security control sub-families given minimal user requirements indicating coverage of different security dimensions. It leverages a curated, unified dataset from both well-known Information Security (InfoSec) and academic sources. This DSS is defined as a non-zero-sum, simultaneous game that is grounded in a Multi-Agent Influence Diagram (MAID) model and explores the decision space over 7 security dimensions or agents, using no-regret online learning to ultimately find the security control sub-families that best fit the requirements while incurring minimal under- and over-provisioning of security resources. This work was validated in terms of performance and accuracy, among others, for varying dataset sizes. It shows exceptional satisfaction coverage results of 99% when using as little as 65% of the SW-implementable security controls, running in 1.2-35.7 seconds; and more moderate coverage results of 73%-77% when using 29% of the controls, resolving in 0.8-13.8 seconds.
Sources
- A Game-Theoretic Approach for Security Control Selection
- Understanding Agent Incentives using Causal Influence Diagrams. Part I: Single Action Settings
- Bayesian and Multi-Objective Decision Support for Incident Mitigation in Cyber-Physical Systems
- The Complexity of Correlated Equilibria in Generalized Games
Related papers
- Exact Regret Frontiers and Externality Scheduling in Centralized Serial-Dictatorship Bandits
- In-Context Credit Assignment via the Core
- Breaking 1/epsilon Barrier in Quantum Zero-Sum Games: Generalizing Metric Subregularity for Spectraplexes
- Enhancing Affine Maximizer Auctions with Correlation-Aware Payment
- LLM Bidders Preserve the Mechanism-Level Orderings of Human Bidders
- Towards Performatively Stable Equilibria in Decision-Dependent Games for Arbitrary Data Distribution Maps