Welcome to Ruthvik Nath Bandari's portfolio

All projects
Cybersecurity · AI/ML

CTPPO

Cyber Threat Propagation Path Optimizer · AAI 6610 course project, solo

My contribution

CTPPO is my solo project. I designed and built the attack-graph model, the exact search, the exploit-likelihood grounding, the evaluation harness and the local-first API and interface.

  • Python
  • NAMOA*
  • FastAPI
  • DistilBERT
  • React
Horizontal chart: a CVSS-ranked fix recovers 24.0% of the best possible single-fix reachability reduction (95% CI 19.5 to 28.8), the Pareto-critical fix recovers 84.1% (95% CI 80.0 to 87.9), on 293 of 300 synthetic networks.

Share of the best possible single fix's attacker-reachability reduction recovered by each method, from one experiment: 300 seeded synthetic networks, each method recommends one fix. Scored on 293 of the 300 networks (the oracle-fraction denominator). Dots are means; whiskers are bootstrap 95% confidence intervals. The networks deliberately include high-CVSS dead ends off the attack path, the case CVSS ranking gets wrong, so this shows the mechanism and is not real-world threat reduction.

Problem

Vulnerability scanners hand over a flat list ranked by CVSS severity. Severity describes one CVE in isolation. It says nothing about whether that CVE sits on a path an attacker can actually walk to something that matters. I wanted to test whether choosing a fix by attack path beats choosing it by score.

Approach

The network becomes an attack graph. Each edge cost is grounded in EPSS, CISA KEV and CVSS data. An exact multi-objective search (NAMOA*) returns the complete Pareto front over success probability, attacker effort and business impact, and the fix that lies on the most Pareto-optimal paths is recommended. The search output was checked against brute force on 80 of 80 random graphs.

How it was built

I modelled a network as an attack graph and grounded edge costs in cached EPSS, CISA KEV and CVSS data. On that graph I implemented an exact multi-objective search (NAMOA*) over success probability, attacker effort and business impact, then recommended the fix on the most Pareto-optimal paths. Early on, parallel edges were silently dropped, so I wrote a brute-force oracle and matched it on 80 of 80 random graphs before republishing results. I scored the method against an oracle on 293 of 300 seeded synthetic networks (the oracle-fraction denominator) and wrapped it in a FastAPI service and React interface. Limits: synthetic networks; lateral-movement costs are heuristic.

Evidence and limitations

The core test used 300 seeded synthetic networks. Each method recommended one fix, and I scored it against an oracle that tries every single fix. Scored on 293 of the 300 networks (the oracle-fraction denominator), the Pareto fix recovered 84.1% of the oracle's reduction (95% CI 80.0 to 87.9) and the CVSS-ranked fix 24.0% (95% CI 19.5 to 28.8).

Limits: these networks are synthetic and were seeded with off-path high-CVSS dead ends, the exact case CVSS gets wrong. A later neutral-generator check kept the advantage, but this remains evidence about the mechanism, not measured threat reduction on a real network. Lateral-movement edge costs are heuristic priors.