Cybersecurity AI in OT: Insights from an AI Top-10 Ranker in the Dragos OT CTF 2025

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mayoral-Vilches, Víctor, Navarrete-Lozano, Luis Javier, Balassone, Francesco, Sanz-Gómez, María, Chávez, Cristóbal Ricardo Veas, de Torres, Maite del Mundo
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915604209860608
author Mayoral-Vilches, Víctor
Navarrete-Lozano, Luis Javier
Balassone, Francesco
Sanz-Gómez, María
Chávez, Cristóbal Ricardo Veas
de Torres, Maite del Mundo
author_facet Mayoral-Vilches, Víctor
Navarrete-Lozano, Luis Javier
Balassone, Francesco
Sanz-Gómez, María
Chávez, Cristóbal Ricardo Veas
de Torres, Maite del Mundo
contents Operational Technology (OT) cybersecurity increasingly relies on rapid response across malware analysis, network forensics, and reverse engineering disciplines. We examine the performance of Cybersecurity AI (CAI), powered by the \texttt{alias1} model, during the Dragos OT CTF 2025 -- a 48-hour industrial control system (ICS) competition with more than 1,000 teams. Using CAI telemetry and official leaderboard data, we quantify CAI's trajectory relative to the leading human-operated teams. CAI reached Rank~1 between competition hours 7.0 and 8.0, crossed 10,000 points at 5.42~hours (1,846~pts/h), and completed 32 of the competition's 34 challenges before automated operations were paused at hour~24 with a final score of 18,900 points (6th place). The top-3 human teams solved 33 of 34 challenges, collectively leaving only the 600-point ``Kiddy Tags -- 1'' unsolved; they were also the only teams to clear the 1,000-point ``Moot Force'' binary. The top-5 human teams averaged 1,347~pts/h to the same milestone, marking a 37\% velocity advantage for CAI. We analyse time-resolved scoring, category coverage, and solve cadence. The evidence indicates that a mission-configured AI agent can match or exceed expert human crews in early-phase OT incident response while remaining subject to practical limits in sustained, multi-day operations.
format Preprint
id arxiv_https___arxiv_org_abs_2511_05119
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Cybersecurity AI in OT: Insights from an AI Top-10 Ranker in the Dragos OT CTF 2025
Mayoral-Vilches, Víctor
Navarrete-Lozano, Luis Javier
Balassone, Francesco
Sanz-Gómez, María
Chávez, Cristóbal Ricardo Veas
de Torres, Maite del Mundo
Cryptography and Security
Operational Technology (OT) cybersecurity increasingly relies on rapid response across malware analysis, network forensics, and reverse engineering disciplines. We examine the performance of Cybersecurity AI (CAI), powered by the \texttt{alias1} model, during the Dragos OT CTF 2025 -- a 48-hour industrial control system (ICS) competition with more than 1,000 teams. Using CAI telemetry and official leaderboard data, we quantify CAI's trajectory relative to the leading human-operated teams. CAI reached Rank~1 between competition hours 7.0 and 8.0, crossed 10,000 points at 5.42~hours (1,846~pts/h), and completed 32 of the competition's 34 challenges before automated operations were paused at hour~24 with a final score of 18,900 points (6th place). The top-3 human teams solved 33 of 34 challenges, collectively leaving only the 600-point ``Kiddy Tags -- 1'' unsolved; they were also the only teams to clear the 1,000-point ``Moot Force'' binary. The top-5 human teams averaged 1,347~pts/h to the same milestone, marking a 37\% velocity advantage for CAI. We analyse time-resolved scoring, category coverage, and solve cadence. The evidence indicates that a mission-configured AI agent can match or exceed expert human crews in early-phase OT incident response while remaining subject to practical limits in sustained, multi-day operations.
title Cybersecurity AI in OT: Insights from an AI Top-10 Ranker in the Dragos OT CTF 2025
topic Cryptography and Security
url https://arxiv.org/abs/2511.05119