DEF CON 33 -  Decision Making in Adversarial Automation  - Bobby Kuzma, Michael Odell

DEF CON 33 - Decision Making in Adversarial Automation - Bobby Kuzma, Michael Odell

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 26:52

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Revised Summary

This presentation by Bobby and Michael Odell (Moch) explores decision-making frameworks in adversarial contexts, beginning with relatable analogies like comparing deterministic blackjack players (who follow rules consistently) versus random players. The speakers introduce the concept of "stochastic parrots" (systems that merely regurgitate training data) versus "deterministic predators" (systems following predictable processes), establishing a foundation for understanding automated decision-making in adversarial environments like cybersecurity [0:00-3:30].

Key Takeaways:

Adversarial OODA loops create time disadvantages: In cybersecurity, attackers and defenders operate in continuous "Observe, Orient, Decide, Act" cycles. When an attacker acts, they disrupt the defender's decision loop. The presenters illustrate this by noting that Security Operations Centers often have alert latencies of five minutes or more, while attackers can move rapidly through networks, potentially compromising multiple systems before defenders can respond [4:20-7:00].

Decision frameworks depend on environment knowledge: Markov Decision Processes (MDPs) model environments with complete knowledge (like white box assessments), while Partially Observable MDPs (POMDPs) address scenarios with incomplete information (like black box assessments). The speakers use the analogy of Atari games for MDPs (where the screen state, available actions, and scoring system are completely known) versus real-world networks where unknown factors must be considered [7:00-10:30].

Multiple decision-making approaches with different trade-offs: The presentation compares various models including:

  • Stochastic methods (random action selection)
  • Deterministic approaches (always choosing the maximum quality action)
  • Policy gradients (continuous decision surfaces)
  • Boltzmann exploration (quality-weighted probabilistic selection)
  • Decision trees (algorithmic check

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So, um, thank first off, thank you for coming. I know almost everyone wants to be either napping in a coma or in some kind of stuper around here at this point. So, I do appreciate that. Um, we are going to be talking about uh decision-m and adversarial automation. Um, I do have to give you a quick warning. Um, this does contain math. Um, I understand that some people have a very fraught relationship with math. And to quote my mother-in-law, math isn't supposed to have symbols or letters. So, we'll we'll try to keep that to the minimum. Um, I'm Bobby. I'm a dad, husband, nerd. I chase rockets when I'm not breaking things. Uh, Michael Odell or I go by Moch sometimes. I'm just a nerd that happens to work with him that he thought I'd be good for this talk. So, it's pleasure to meet you. He he …