SEAS-8414 · George Washington University SEAS · Summer 2026

Cyber Analytics

SEAS-8414

From passive network discovery to autonomous remediation — a doctoral treatment of the complete operational security pipeline, built around the Breakwater framework.

The course surveys analytical tools for cybersecurity data and emphasizes how data analytics procedures support defensible cybersecurity policy decisions across discovery, diagnostics, vulnerability assessment, risk modeling, simulation, cryptographic readiness, federated intelligence, supply-chain integrity, deception, formal verification, and closed-loop remediation.

Saturdays 9AM–12PM ET · May 16 – Aug 15 Instructor: Ravi Mallarapu
12
Chapters
Network to Remediation
22
Pipeline Phases
Progressive Scan Pipeline
48
API Endpoints
Breakwater Framework
44
DB Models
Full Data Schema

Textbook Chapters

Twelve doctoral-level chapters covering the complete operational security pipeline. Each chapter includes figures, code examples, and lab exercises.

01 Phase 1

Network Discovery and Asset Inventory

ARP harvesting, mDNS/SSDP browsing, fping sweeps, and TCP connect probing to build a complete asset inventory.

02 Phase 2

Service Enrichment and Device Fingerprinting

nmap service detection, HTTP banner scraping, TLS certificate inspection, JARM fingerprinting, and ONVIF/RTSP probing.

03 Phase 3

Vulnerability Assessment

CPE construction, NVD API lookups, CVSS scoring, OpenVAS integration, and default credential testing.

04 Phase 4

Attack Graph Analytics and Risk Scoring

NetworkX-based attack graph construction, Breakwater Risk Score computation, MITRE ATT&CK mapping, and STIX export.

05 Phase 5

Prescriptive Analytics, Autonomous Penetration Testing

PPO reinforcement-learning agent, rule-based campaign orchestrator, and three safety modes for controlled exploitation.

06 Phase 6

Simulation Analytics: Digital Twin and Remediation Simulation

SDN-based digital twin creation, Docker environment mirroring, scenario engine, and remediation simulation.

07 Phase 7

Post-Quantum Cryptographic Readiness

Post-quantum algorithm assessment, harvest-now-decrypt-later risk scoring, and NIST PQC migration planning.

08 Phase 8

Federated Threat Intelligence Network

SCAFFOLD federated learning for threat intelligence sharing with differential privacy and Byzantine fault tolerance.

09 Phase 9

Supply Chain Integrity and Counterfeit Detection

SBOM generation and analysis, counterfeit component detection, and EU Cyber Resilience Act compliance.

10 Phase 10

Active Deception and Threat Hunting

Adaptive honeypots, RL Chameleon engine for dynamic decoy behavior, and MITRE TTP annotation of attacker telemetry.

11 Phase 11

Formal Protocol Verification

Applied pi calculus modeling, Dolev-Yao attacker model, and automated ProVerif-style verification of security protocols.

12 Phase 12

Autonomous Remediation and Safety Verification

Plan/approve/execute remediation pipeline, Vault credential rotation, micro-segmentation, and safety guarantees.