Parent doctrine: #64
System program: #66
Series-wide evaluation: #67
Purpose
Create a disciplined research bridge between selected Japanese Army/Navy tactical principles and Azazel Active Cyber Defense without turning historical analogy into untestable branding.
The output of this issue is not executable doctrine and not a claim that historical tactics were universally effective. Each candidate principle must be translated into a measurable cyber hypothesis, tested against modern defensive constraints, and paired with explicit failure/anti-pattern conditions.
Candidate doctrine families
Delaying / endurance
Research question: can bounded friction, diversion, and observation measurably reduce adversary progression while increasing defender time/evidence without unacceptable production impact?
Cyber translation candidates:
- controlled delay / rate shaping;
- deliberately yielding non-critical Presented Terrain;
- preserving response options instead of immediately exposing every control;
- phased containment after evidence gain.
Defense in depth / depth adaptation
Research question: can the shape of defensive depth change as evidence changes, rather than remaining static layers?
Cyber translation candidates:
- progressive exposure reduction;
- identity/network/workload controls activated by stage;
- bounded Presented Terrain at selected depth;
- production-preserving fallback positions.
Progressive attrition / interception
Research question: can defender-controlled effects reduce attacker options, viable paths, credentials, or useful information over time before final containment?
Do not equate this with destructive action. Attrition is limited to defender-controlled attack paths/options inside the authorized environment.
Decoy / diversion / deception
Research question: can expendable synthetic surfaces redirect effort and generate discriminating evidence while maintaining strict production isolation?
Cyber assets may include synthetic identities, credentials, services, data, paths, or network presentation, subject to explicit safety/provenance rules.
Use Presented Terrain for what the defender exposes. Do not call it Perceived Terrain, because attacker perception/belief is uncertain and belongs to the separate Adversary Belief model.
Historical failure anti-patterns that MUST be encoded
The research must also model doctrine failure, including:
- rigid assumption that the adversary will follow the expected route/plan;
- fixation on one decisive engagement point;
- ignoring logistics/resource constraints;
- irreversible sacrifice when reversible delay/containment would preserve options;
- optimizing delay/dwell time while exposure risk rises;
- doctrine that persists after evidence disproves its assumptions;
- misleading success metrics that reward activity rather than defender outcome.
Translation template
Every historical principle must be documented in a common form:
Doctrine source / historical context
-> abstract tactical principle
-> proposed cyber mechanism
-> expected defender advantage
-> measurable variables
-> safety / business constraints
-> falsification condition
-> historical anti-pattern / failure mode
-> modern prior art comparison
-> owning Azazel product(s)
-> system-wide experiment candidate
Series mapping
A historical idea is not automatically an Edge feature.
Depending on the hypothesis, implementation/research may belong to:
Evidence discipline
Prefer primary/authoritative historical material and peer-reviewed/current security research for the cyber side. Secondary accounts may provide context but cannot be the sole support for a technical doctrine claim.
Record sources and distinguish:
- historical fact;
- interpretation;
- cyber analogy;
- experimentally supported finding;
- untested research hypothesis.
Required initial studies
Delaying Action -> Time/Evidence/Initiative measurement study.
Defense in Depth -> Adaptive Depth architecture study.
Progressive Attrition/Interception -> attacker-option reduction study.
Decoy/Diversion -> Presented Terrain shaping study.
- Failure-case study: when immediate blocking is superior to delay/deception.
- Failure-case study: when a fixed doctrine becomes exploitable by an adaptive attacker.
- Distributed study: whether constrained Gadget observations materially improve the system evidence loop.
- Memory study: whether Knowledge Outcome Memory improves decisions beyond raw history/RAG.
Safety boundary
- authorized defender-controlled environments only;
- no hack-back;
- no attacker-system compromise;
- no uncontrolled data/credential exposure;
- no deliberate production degradation solely to increase engagement;
- operator/mission availability preempts research value;
- no historical analogy may broaden modern authority boundaries.
Acceptance criteria
Parent doctrine: #64
System program: #66
Series-wide evaluation: #67
Purpose
Create a disciplined research bridge between selected Japanese Army/Navy tactical principles and Azazel Active Cyber Defense without turning historical analogy into untestable branding.
The output of this issue is not executable doctrine and not a claim that historical tactics were universally effective. Each candidate principle must be translated into a measurable cyber hypothesis, tested against modern defensive constraints, and paired with explicit failure/anti-pattern conditions.
Candidate doctrine families
Delaying / endurance
Research question: can bounded friction, diversion, and observation measurably reduce adversary progression while increasing defender time/evidence without unacceptable production impact?
Cyber translation candidates:
Defense in depth / depth adaptation
Research question: can the shape of defensive depth change as evidence changes, rather than remaining static layers?
Cyber translation candidates:
Progressive attrition / interception
Research question: can defender-controlled effects reduce attacker options, viable paths, credentials, or useful information over time before final containment?
Do not equate this with destructive action. Attrition is limited to defender-controlled attack paths/options inside the authorized environment.
Decoy / diversion / deception
Research question: can expendable synthetic surfaces redirect effort and generate discriminating evidence while maintaining strict production isolation?
Cyber assets may include synthetic identities, credentials, services, data, paths, or network presentation, subject to explicit safety/provenance rules.
Use Presented Terrain for what the defender exposes. Do not call it
Perceived Terrain, because attacker perception/belief is uncertain and belongs to the separate Adversary Belief model.Historical failure anti-patterns that MUST be encoded
The research must also model doctrine failure, including:
Translation template
Every historical principle must be documented in a common form:
Series mapping
A historical idea is not automatically an Edge feature.
Depending on the hypothesis, implementation/research may belong to:
Evidence discipline
Prefer primary/authoritative historical material and peer-reviewed/current security research for the cyber side. Secondary accounts may provide context but cannot be the sole support for a technical doctrine claim.
Record sources and distinguish:
Required initial studies
Delaying Action -> Time/Evidence/Initiativemeasurement study.Defense in Depth -> Adaptive Deptharchitecture study.Progressive Attrition/Interception -> attacker-option reductionstudy.Decoy/Diversion -> Presented Terrain shapingstudy.Safety boundary
Acceptance criteria
do not implement.