Paper published in a book (Scientific congresses, symposiums and conference proceedings)
Next Steps in Cyber Blue Team Automation - Leveraging the Power of LLMs
Dijk, Allard; Meier, Roland; Melella, Cosimo et al.
2025In Kwan, Claire (Ed.) 2025 17th International Conference on Cyber Conflict: The Next Step, CyCon 2025
Peer reviewed
 

Files


Full Text
cycon25_1.pdf
Author postprint (648.89 kB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
artificial intelligence; automated cyber defense; dataset; large language models; Locked Shields; Automated cybe defense; Cyber defense exercise; Cyber-defense; Dataset; Fully automated; Language model; Large language model; Locked shield; Network traffic; Power; Computer Networks and Communications
Abstract :
[en] In 2021, driven by the ongoing advancements in artificial intelligence (AI) and automation, previous works [1], [2] introduced architectures for fully automated blue teams in cyber defense exercises such as Locked Shields (LS). Since then, technological and scientific progress has further accelerated. In particular, the rapid evolution of generative AI through large language models (LLMs) has significantly enhanced the capabilities of cybersecurity automation. This paper reviews how cyber blue team automation can benefit from these recent advances, with a focus on how generative AI and LLMs are reshaping automation strategies for defending complex cyber infrastructure. Using the LS exercise as a case study, we discuss how generative AI-based automation can address the growing complexity of cyber threats. Our paper presents promising directions on how generative AI can enhance fully automated blue teams, and it addresses a major research gap - the lack of high-quality datasets for training and evaluation in this field. To address this challenge, we introduce a novel dataset containing labeled network traffic and end-host logs, collected during the 'partners' run' preceding LS 2024. This dataset is derived from over 400 GB of captured network traffic and more than 6 million log entries. It captures real-world red team behavior and is made publicly available to foster research and AI development in the field of blue team automation. We conclude with future research challenges in automated cyber defense.
Disciplines :
Computer science
Author, co-author :
Dijk, Allard;  Netherlands Defence Academy, Den Helder, Netherlands
Meier, Roland;  Cyber-Defence Campus armasuisse, Thun, Switzerland
Melella, Cosimo;  NATO Cooperative Cyber Defence, Centre of Excellence, Tallinn, Estonia
Pihelgas, Mauno;  Tallinn University of Technology, Tallinn, Estonia
Vaarandi, Risto;  Tallinn University of Technology, Tallinn, Estonia
LENDERS, Vincent  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Systems and Network Security Group (SNS) ; Cyber-Defence Campus armasuisse, Thun, Switzerland
External co-authors :
yes
Language :
English
Title :
Next Steps in Cyber Blue Team Automation - Leveraging the Power of LLMs
Publication date :
May 2025
Event name :
2025 17th International Conference on Cyber Conflict: The Next Step (CyCon)
Event place :
Tallinn, Est
Event date :
27-05-2025 => 30-05-2025
Audience :
International
Main work title :
2025 17th International Conference on Cyber Conflict: The Next Step, CyCon 2025
Editor :
Kwan, Claire
Publisher :
NATO CCD COE Publications
ISBN/EAN :
9789916978986
Peer reviewed :
Peer reviewed
Available on ORBilu :
since 19 December 2025

Statistics


Number of views
20 (0 by Unilu)
Number of downloads
0 (0 by Unilu)

Scopus citations®
 
0
Scopus citations®
without self-citations
0
OpenCitations
 
0
OpenAlex citations
 
0

Bibliography


Similar publications



Contact ORBilu