Towards Centralized Orchestration of Cyber Protection Condition (CPCON)

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Timmons, Mark, Lukaszewski, Daniel, Xie, Geoffrey, Mayo, Thomas, McCanless, Donald
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866910951779860480
author Timmons, Mark
Lukaszewski, Daniel
Xie, Geoffrey
Mayo, Thomas
McCanless, Donald
author_facet Timmons, Mark
Lukaszewski, Daniel
Xie, Geoffrey
Mayo, Thomas
McCanless, Donald
contents The United States Cyber Command (USCYBERCOM) Cyber Protection Condition (CPCON) framework mandates graduated security postures across Department of Defense (DoD) networks, but current implementation remains largely manual, inconsistent, and error-prone. This paper presents a prototype system for centralized orchestration of CPCON directives, enabling automated policy enforcement and real-time threat response across heterogeneous network environments. Building on prior work in host-based intrusion response, our system leverages a policy-driven orchestrator to standardize security actions, isolate compromised subnets, and verify enforcement status. We validate the system through emulated attack scenarios, demonstrating improved speed, accuracy, and verifiability in CPCON transitions with human-in-the-loop oversight.
format Preprint
id arxiv_https___arxiv_org_abs_2505_12613
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards Centralized Orchestration of Cyber Protection Condition (CPCON)
Timmons, Mark
Lukaszewski, Daniel
Xie, Geoffrey
Mayo, Thomas
McCanless, Donald
Cryptography and Security
The United States Cyber Command (USCYBERCOM) Cyber Protection Condition (CPCON) framework mandates graduated security postures across Department of Defense (DoD) networks, but current implementation remains largely manual, inconsistent, and error-prone. This paper presents a prototype system for centralized orchestration of CPCON directives, enabling automated policy enforcement and real-time threat response across heterogeneous network environments. Building on prior work in host-based intrusion response, our system leverages a policy-driven orchestrator to standardize security actions, isolate compromised subnets, and verify enforcement status. We validate the system through emulated attack scenarios, demonstrating improved speed, accuracy, and verifiability in CPCON transitions with human-in-the-loop oversight.
title Towards Centralized Orchestration of Cyber Protection Condition (CPCON)
topic Cryptography and Security
url https://arxiv.org/abs/2505.12613