Autonomous Cyber Defence in Complex Software Ecosystems: A Graph-Based and AI-Driven Approach to Zero-Day Threat
Abstract
As the digital realm continues to expand, the complexity of modern software ecosystems has increased the frequency and severity of zero-day attacks, rendering traditional cyber defence mechanisms insufficient.
Purpose: This paper presents an autonomous cyber defence architecture that utilises a graph-based modelling and artificial intelligence (AI) to proactively detect and mitigate zero-day threats in complex environments.
Methodology: The system dynamically generates dependency graphs to identify critical nodes and aberrant connections, which are then used to locate behavioural anomalies via Graph Neural Networks (GNNs). In addition, Reinforcement learning agents further enhance the ability to evaluate threats in real time and take mitigation actions without relying on a predetermined signature.
Findings: Results of experimentation illustrate that the system's detection and performance capabilities were robust and efficient, achieving a detection rate of 96.8%, precision of 94.3%, recall of 92.7, and an F1 score of 93.5, along with a 3.1% false positive rate. The completion of threat response processes averaged 1.8 seconds, yielding a containment rate of 91.4% and an impact mitigation rate of 87.2%. Additionally, the system exhibited scalability to 10,000 software nodes.
Practical Implications: The results presented herein provide evidence for the feasibility of the framework to be implemented in a modern enterprise and cloud-native systems. Since the proposed system is able to adapt autonomously to ever changing threats in real time, it paves the way for intelligent, scalable, and zero-trust cyber defence architectures for the next-generation software ecosystem
Keywords: Autonomous Cyber Defence, Zero-Day Threat Detection, Graph Neural Networks, Reinforcement Learning, Anomaly Detection, Complex Software Ecosystems, Dynamic Dependency Graph, AI-Driven Security, Threat Mitigation, Behavioural Analysis
References
- Axelsson, S. (2000). Intrusion detection systems: A survey and taxonomy. Technical Report No. 99-15, Department of Computer Engineering, Chalmers University of Technology. https://www.cerias.purdue.edu/apps/reports_and_papers/view/4293/
- Bagga, T., Gupta, P. K., Ola, M. O., & Gilani, P. (2025). NEP 2020 in practice: Perspectives on implementation challenges. Prabandhan: Indian Journal of Management, 18(12), 8–14. https://doi.org/10.17010/pijom/2025/v18i12/175030
- Bilge, L., & Dumitras, T. (2012). Before we knew it: An empirical study of zero-day attacks in the real world. In Proceedings of the 2012 ACM Conference on Computer and Communications Security, 833–844. https://doi.org/10.1145/2382196.2382284
- Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cyber security intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. https://doi.org/10.1109/COMST.2015.2494502
- Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3), Article 15. https://doi.org/10.1145/1541880.1541882
- Garcia-Teodoro, P., Diaz-Verdejo, J., Macia-Fernandez, G., & Vazquez, E. (2009). Anomaly-based network intrusion detection: Techniques, systems and challenges. Computers & Security, 28(1–2), 18–28. https://doi.org/10.1016/j.cose.2008.08.003
- Kim, G., Lee, S., & Kim, S. (2014). A novel hybrid intrusion detection method integrating anomaly detection with misuse detection. Expert Systems with Applications, 41(4), 1690–1700. https://doi.org/10.1016/j.eswa.2013.08.066
- Liu, H., Lang, B., Liu, M., & Yan, H. (2019). CNN and RNN based payload classification methods for attack detection. Knowledge-Based Systems, 163, 332–341. https://doi.org/10.1016/j.knosys.2018.09.023
- Mnih, V., Kavukcuoglu, K., Silver, D., Rusu, A. A., Veness, J., Bellemare, M. G., Graves, A., Riedmiller, M., Fidjeland, A. K., Ostrovski, G., Petersen, S., Beattie, C., Sadik, A., Antonoglou, I., King, H., Kumaran, D., Wiersstra, D., Legg, S., & Hassabis, D. (2015). Human-level control through deep reinforcement learning. Nature, 518(7540), 529–533. https://doi.org/10.1038/nature14236
- MITRE. (2021). CALDERA: Automated adversary emulation platform. https://github.com/mitre/caldera
- Microsoft. (2021). CyberBattleSim: A cybersecurity research toolkit for training reinforcement learning agents. https://github.com/microsoft/CyberBattleSim
- OpenAI. (2020). OpenAI Gym: A toolkit for developing and comparing reinforcement learning algorithms. https://gym.openai.com/
- Ranshous, S., Shen, S., Koutra, D., Harenberg, S., Faloutsos, C., & Samatova, N. F. (2015). Anomaly detection in dynamic networks: A survey. Wiley Interdisciplinary Reviews: Computational Statistics, 7(3), 223–247. https://doi.org/10.1002/wics.1347
- Shafiq, M. Z., Khayam, S. A., & Farooq, M. (2008). Embedded malware detection using Markov n-grams. In Detection of Intrusions and Malware, and Vulnerability Assessment, 88–107. https://doi.org/10.1007/978-3-540-70542-0_6
- Sommer, R., & Paxson, V. (2010). Outside the closed world: On using machine learning for network intrusion detection. In 2010 IEEE Symposium on Security and Privacy, 305–316. https://doi.org/10.1109/SP.2010.25
- Wu, Z., Pan, S., Chen, F., Long, G., Zhang, C., & Yu, P. S. (2021). A comprehensive survey on graph neural networks. IEEE Transactions on Neural Networks and Learning Systems, 32(1), 4–24. https://doi.org/10.1109/TNNLS.2020.2978386
- Xu, K., Zhang, Z., & Bhattacharyya, S. (2005). Profiling Internet backbone traffic: Behaviour models and applications. ACM SIGCOMM Computer Communication Review, 38(4), 169–180. https://doi.org/10.1145/1402946.1402983
- Zhang, J., & Paxson, V. (2000). Detecting stepping stones. In Proceedings of the 9th USENIX Security Symposium. https://www.usenix.org/events/sec2000/full_papers/zhangstepping/zhangstepping.pdf
- Zhou, J., Cui, G., Zhang, Z., et al. (2020). Graph neural networks: A review of methods and applications. AI Open, 1, 57–81. https://doi.org/10.1016/j.aiopen.2021.01.001
