{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:10:03Z","timestamp":1783613403232,"version":"3.55.0"},"reference-count":22,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,12,15]],"date-time":"2025-12-15T00:00:00Z","timestamp":1765756800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,12,15]],"date-time":"2025-12-15T00:00:00Z","timestamp":1765756800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"NTNU Norwegian University of Science and Technology"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2026,2]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In this paper, we worked in collaboration with the ASCERT (AI-based scenario management for cyber-range training) project and its generative AI prototype that generates dynamic and interactive cyber-range exercise scenarios. We evaluate the model by focusing on two objectives: (i) its ability to replicate real-world cyber attacks, and (ii) its consistency across multiple simulations that uses same inputs. To assess realism, we examine how well the model reproduces three well-documented cyber incidents namely Colonial Pipeline, Equifax, and SolarWinds, when it is provided with relevant source material for training. We then analyze repeatability by comparing outputs across fixed-input simulation runs. As the evaluation results indicate, overall the model generated varied and context-appropriate scenarios. Moreover, it introduced an interactivity feature that allows users to choose responses and observe consequences in real time. However, the consistency in repeated runs was limited: simulations are not reliably repeatable, although what was interesting is that the variability reflects the unpredictability of real attacks. These findings suggest that, while ASCERT already supports scenario variety and meaningful user interaction, it requires targeted refinements to improve stability and repeatability. With such improvements, the ASCERT model has strong potential to contribute to scalable and adaptive cybersecurity education and training.<\/jats:p>","DOI":"10.1007\/s10207-025-01179-w","type":"journal-article","created":{"date-parts":[[2025,12,15]],"date-time":"2025-12-15T16:35:09Z","timestamp":1765816509000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Evaluating ASCERT: generative AI for cyber-range scenario generation"],"prefix":"10.1007","volume":"25","author":[{"given":"M.","family":"Palumickas","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"M. Mudassar","family":"Yamin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"B.","family":"Katt","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chhagan","family":"Lal","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,12,15]]},"reference":[{"key":"1179_CR1","doi-asserted-by":"publisher","first-page":"8639","DOI":"10.1007\/s10586-024-04507-2","volume":"27","author":"L Nemec Zlatolas","year":"2024","unstructured":"Nemec Zlatolas, L., Welzer, T., Lhotska, L.: Data breaches in healthcare: security mechanisms for attack mitigation. Springer, Cluster Comput. 27, 8639\u20138654 (2024)","journal-title":"Springer, Cluster Comput."},{"key":"1179_CR2","unstructured":"(2024)"},{"key":"1179_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101636","volume":"88","author":"MM Yamin","year":"2020","unstructured":"Yamin, M.M., Katt, B., Gkioulos, V.: Cyber ranges and security testbeds: Scenarios, functions, tools and architecture. Comput. Sec. 88, 101636 (2020)","journal-title":"Comput. Sec."},{"key":"1179_CR4","volume":"88","author":"V Kampourakis","year":"2025","unstructured":"Kampourakis, V., Gkioulos, V., Katsikas, S.: A step-by-step definition of a reference architecture for cyber ranges. J. Info. Sec. Appl. 88, 103917 (2025)","journal-title":"J. Info. Sec. Appl."},{"key":"1179_CR5","unstructured":"Stolpe, A.: Ai-drevet cybersikkerhetstrening, Available at: https:\/\/nr.no\/prosjekter\/ai-drevet-ovelsesplanlegging-for-cybersikkerhetstrening\/(2025)"},{"key":"1179_CR6","doi-asserted-by":"crossref","unstructured":"A.\u00a0Zacharis, C.\u00a0Patsakis, Aicef: an ai-assisted cyber exercise content generation framework using named entity recognition, International Journal of Information Security (2023)","DOI":"10.1007\/s10207-023-00693-z"},{"key":"1179_CR7","doi-asserted-by":"crossref","unstructured":"Costa, G., Russo, E., Armando, A.: Automating the generation of cyber range virtual scenarios with vsdl, Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (2023)","DOI":"10.58346\/JOWUA.2022.I4.004"},{"key":"1179_CR8","unstructured":"Gavaudan, L., Legras, S., Ventos, V.: Cyber range automation, a bedrock for ai applications, in: Proceedings of the 28th C &ESAR, (2021)"},{"key":"1179_CR9","doi-asserted-by":"crossref","unstructured":"Yamin, M.M., Hashmi, E., Ullah, M., Katt, B.: Applications of llms for generating cyber security exercise scenarios, in: Proc. 2023 2nd Intl. Conf. Appl. Artif. Intell. Comput. (ICAAIC), IEEE, (2023)","DOI":"10.21203\/rs.3.rs-3970015\/v1"},{"key":"1179_CR10","doi-asserted-by":"crossref","unstructured":"Hannay, J.E., Stolpe, A., Yamin, M.M.: Toward ai-based scenario management for cyber range training, in: HCI International 2021 - Late Breaking Papers: Multimodality, eXtended Reality, and Artificial Intelligence, (2021)","DOI":"10.1007\/978-3-030-90963-5_32"},{"key":"1179_CR11","unstructured":"Wu, X., Qiu, Q., Li, J., Zhao, Y.: Intell-dragonfly: A cybersecurity attack surface generation engine based on artificial; intelligence-generated content technology, arXiv (2023)"},{"key":"1179_CR12","unstructured":"Midtb\u00f8, S.M.: ChatRange: Designing Cyber Security Exercise Scenarios using Autonomous AI Agents and Artificial Intelligence, Master\u2019s thesis, Norwegian University of Science and Technology, (2024)"},{"key":"1179_CR13","doi-asserted-by":"publisher","unstructured":"Beerman, J., Berent, D., Falter, Z., Bhunia, S.: A review of colonial pipeline ransomware attack, in: 2023 IEEE\/ACM 23rd Intl. Symp. Cluster, Cloud and Internet Comput. Workshops (CCGridW) , 8\u201315 (2023). https:\/\/doi.org\/10.1109\/CCGridW59191.2023.00017","DOI":"10.1109\/CCGridW59191.2023.00017"},{"key":"1179_CR14","unstructured":"Ozarslan, S.: Tactics, techniques, and procedures (ttps) used in the solarwinds breach, Picus Security (2020)"},{"key":"1179_CR15","unstructured":"Commission, F.T.: Available at: https:\/\/www.ftc.gov\/equifax-data-breach(2017)"},{"key":"1179_CR16","doi-asserted-by":"crossref","unstructured":"Beerman, J., Berent, D., Falter, Z., Bhunia, S.: A review of colonial pipeline ransomware attack, in: 2023 IEEE\/ACM 23rd intl. symp. cluster, cloud and internet comput. workshops (CCGridW). IEEE 2023, 8\u201315 (2023)","DOI":"10.1109\/CCGridW59191.2023.00017"},{"key":"1179_CR17","unstructured":"Wang, P., Johnson, C.: Cybersecurity incident handling: a case study of the equifax data breach., Issues in Information Systems 19 (2018)"},{"key":"1179_CR18","doi-asserted-by":"crossref","unstructured":"Alkhadra, R., Abuzaid, J., AlShammari, M., Mohammad, N.: Solar winds hack: In-depth analysis and countermeasures, in: 2021 12th Intl. Conf. Comput. Commn. Networking Tech. (ICCCNT), IEEE, pp. 1\u20137 (2021)","DOI":"10.1109\/ICCCNT51525.2021.9579611"},{"issue":"67","key":"1179_CR19","first-page":"1","volume":"14","author":"FY Loumachi","year":"2025","unstructured":"Loumachi, F.Y., Ghanem, M.C., Ferrag, M.A.: Advancing cyber incident timeline analysis through retrieval-augmented generation and large language models. Comput. 14(67), 1\u201342 (2025)","journal-title":"Comput."},{"key":"1179_CR20","doi-asserted-by":"publisher","first-page":"81","DOI":"10.70470\/SHIFRA\/2025\/005","volume":"2025","author":"A Ali","year":"2025","unstructured":"Ali, A., Ghanem, M.C.: Beyond detection: large language models and next-generation cybersecurity. SHIFRA 2025, 81\u201397 (2025)","journal-title":"SHIFRA"},{"key":"1179_CR21","doi-asserted-by":"crossref","unstructured":"Gupta, M., Akiri, C., Aryal, K., Parker, E., Praharaj, L.: From chatgpt to threatgpt: Impact of generative ai in cybersecurity and privacy, arXiv (2023)","DOI":"10.1109\/ACCESS.2023.3300381"},{"key":"1179_CR22","unstructured":"Forum, E.C.: Dual-use technology \u2013 cross-sector cooperation in the cybersecurity sector, 2024. Available at: https:\/\/cybersecforum.eu\/wp-content\/uploads\/2024\/12\/Dual-use-technology--cross-sector-cooperation-in-the-cyber-security-sector.pdf"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01179-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-025-01179-w","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-025-01179-w.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T16:08:06Z","timestamp":1769875686000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-025-01179-w"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,15]]},"references-count":22,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,2]]}},"alternative-id":["1179"],"URL":"https:\/\/doi.org\/10.1007\/s10207-025-01179-w","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-7806552\/v1","asserted-by":"object"}]},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,15]]},"assertion":[{"value":"8 October 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"8"}}