Signature Management using Operational Knowledge and Environments (SMOKE)
Abstract
The Signature Management using Operational Knowledge and Environments (SMOKE) program is developing signature management technologies that generate evasive cyber infrastructure which minimizes signatures as a source of attribution. SMOKE technologies incorporate counter-attribution techniques into the design process; quantitatively measure attribution risk in real-time; and maintain evasiveness after infrastructure changes. SMOKE data-driven tools will automate the planning and execution of threat emulated cyber infrastructure needed for network security assessments by red teams. SMOKE data-driven tools will automate the discovery of cyber threat infrastructure signatures. If successful, SMOKE prototypes will enable red teams to plan, build, and deploy cyber infrastructure that is informed by machine-readable signatures of sophisticated cyber threats.
Document Details
- Document Type
- Accomplishment
- Publication Date
- Oct 01, 2025
- Source ID
- 56864724265b803753f9ebd3220c00ee