ARTFEED — Contemporary Art Intelligence

AI-Driven Models for Active Directory Security Hardening

other · 2026-07-27

This thesis addresses practical challenges in hardening Active Directory (AD) attack graphs. Existing models assume static graphs, but real-world AD environments are highly dynamic. Most solutions focus only on revoking vulnerabilities (edge removal), ignoring active defense mechanisms. Additionally, not all remediations are implementable, so a practical model must incorporate system admin feedback into prioritization. The study proposes new models to overcome these limitations.

Key facts

  • Active Directory is a directory service for managing security permissions in Windows domain networks.
  • AD is a primary target for adversaries.
  • Existing attack graph hardening solutions assume static graphs.
  • Most solutions are limited to edge removal.
  • System admin feedback is needed for prioritization.
  • The thesis proposes models addressing dynamic environments, active defense, and feedback integration.

Entities

Institutions

  • Microsoft

Sources