Skip to content

[research] Translate Japanese delaying, endurance, interception, and deception doctrine into falsifiable cyber playbooks #65

Description

@01rabbit

Parent doctrine: #64
System program: #66
Series-wide evaluation: #67

Purpose

Create a disciplined research bridge between selected Japanese Army/Navy tactical principles and Azazel Active Cyber Defense without turning historical analogy into untestable branding.

The output of this issue is not executable doctrine and not a claim that historical tactics were universally effective. Each candidate principle must be translated into a measurable cyber hypothesis, tested against modern defensive constraints, and paired with explicit failure/anti-pattern conditions.

Candidate doctrine families

Delaying / endurance

Research question: can bounded friction, diversion, and observation measurably reduce adversary progression while increasing defender time/evidence without unacceptable production impact?

Cyber translation candidates:

  • controlled delay / rate shaping;
  • deliberately yielding non-critical Presented Terrain;
  • preserving response options instead of immediately exposing every control;
  • phased containment after evidence gain.

Defense in depth / depth adaptation

Research question: can the shape of defensive depth change as evidence changes, rather than remaining static layers?

Cyber translation candidates:

  • progressive exposure reduction;
  • identity/network/workload controls activated by stage;
  • bounded Presented Terrain at selected depth;
  • production-preserving fallback positions.

Progressive attrition / interception

Research question: can defender-controlled effects reduce attacker options, viable paths, credentials, or useful information over time before final containment?

Do not equate this with destructive action. Attrition is limited to defender-controlled attack paths/options inside the authorized environment.

Decoy / diversion / deception

Research question: can expendable synthetic surfaces redirect effort and generate discriminating evidence while maintaining strict production isolation?

Cyber assets may include synthetic identities, credentials, services, data, paths, or network presentation, subject to explicit safety/provenance rules.

Use Presented Terrain for what the defender exposes. Do not call it Perceived Terrain, because attacker perception/belief is uncertain and belongs to the separate Adversary Belief model.

Historical failure anti-patterns that MUST be encoded

The research must also model doctrine failure, including:

  • rigid assumption that the adversary will follow the expected route/plan;
  • fixation on one decisive engagement point;
  • ignoring logistics/resource constraints;
  • irreversible sacrifice when reversible delay/containment would preserve options;
  • optimizing delay/dwell time while exposure risk rises;
  • doctrine that persists after evidence disproves its assumptions;
  • misleading success metrics that reward activity rather than defender outcome.

Translation template

Every historical principle must be documented in a common form:

Doctrine source / historical context
  -> abstract tactical principle
  -> proposed cyber mechanism
  -> expected defender advantage
  -> measurable variables
  -> safety / business constraints
  -> falsification condition
  -> historical anti-pattern / failure mode
  -> modern prior art comparison
  -> owning Azazel product(s)
  -> system-wide experiment candidate

Series mapping

A historical idea is not automatically an Edge feature.

Depending on the hypothesis, implementation/research may belong to:

Evidence discipline

Prefer primary/authoritative historical material and peer-reviewed/current security research for the cyber side. Secondary accounts may provide context but cannot be the sole support for a technical doctrine claim.

Record sources and distinguish:

  • historical fact;
  • interpretation;
  • cyber analogy;
  • experimentally supported finding;
  • untested research hypothesis.

Required initial studies

  1. Delaying Action -> Time/Evidence/Initiative measurement study.
  2. Defense in Depth -> Adaptive Depth architecture study.
  3. Progressive Attrition/Interception -> attacker-option reduction study.
  4. Decoy/Diversion -> Presented Terrain shaping study.
  5. Failure-case study: when immediate blocking is superior to delay/deception.
  6. Failure-case study: when a fixed doctrine becomes exploitable by an adaptive attacker.
  7. Distributed study: whether constrained Gadget observations materially improve the system evidence loop.
  8. Memory study: whether Knowledge Outcome Memory improves decisions beyond raw history/RAG.

Safety boundary

  • authorized defender-controlled environments only;
  • no hack-back;
  • no attacker-system compromise;
  • no uncontrolled data/credential exposure;
  • no deliberate production degradation solely to increase engagement;
  • operator/mission availability preempts research value;
  • no historical analogy may broaden modern authority boundaries.

Acceptance criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions