Service-Graph Reconfiguration Against Post-Access Reconnaissance, with Cryptographic Epoch Isolation and Mission-Domain State Continuity
Thor Thor. Independent Open-Source Researcher, THOR-SEC. ORCID: 0009-0001-6573-385X
This research was conducted independently on the author's own time and is not sponsored by, affiliated with, or representative of any employer.
Modern moving-target defenses alter addresses, ports, hosts, software variants, workflows, or computing environments to reduce the useful lifetime of attacker observations. This paper proposes Mission-Invariant Architecture Morphing (MIAM), a research architecture that moves the defensive transformation boundary into the application itself, targeting post-initial-access reconnaissance such as dependency mapping, lateral movement, and credential reuse. MIAM represents a workload as capability units assigned to runtime service graphs drawn from a certified grammar. For each candidate graph, machine-evaluable attack-prerequisite predicates estimate which previously learned conditions remain actionable, while a separate exposure term bounds new attack surface introduced by the candidate. A graph delta is combined with a capability-state map to derive a transition policy that permits only validated mission-domain state to cross the epoch boundary while blocking designated runtime and security state. A verified target graph is then instantiated under distinct epoch authority and cut over behind a stable logical interface. The paper develops an operational reconnaissance-transfer model, architecture-distance measures, a recurrence-aware retention model showing that a finite variant pool imposes a nonzero knowledge floor, a cryptographic epoch-isolation construction, a graph-delta-driven State Continuity Firewall, an enterprise implementation path, an ablation-based experimental protocol, and a reference claim set released as a defensive publication. The work is a design proposal produced through independent open-source cybersecurity research; it reports no empirical security advantage and makes no patentability determination.
The idea. The application's internal service partition changes across security epochs while the external interface and mission stay fixed.
The architecture. A separated control plane scores candidate graphs, verifies them against a mission contract, and cuts over under fresh epoch authority. Only validated mission-domain state crosses the State Continuity Firewall.
A key result. A finite pool of certified variants leaves a nonzero floor on retained attacker knowledge. Rotating faster does not remove it; pool size and diversity do.
This is a design proposal and formal model. It reports no empirical security results. All claimed benefits are hypotheses until a prototype is measured under the evaluation protocol in Section 15 of the paper.
| Path | Description |
|---|---|
paper/MIAM.pdf |
The paper |
paper/miam.tex |
LaTeX source (single file, figures in TikZ) |
paper/abstract.txt |
Plain-text abstract |
scripts/miam_checks.py |
Reproduces every number in Section 16 |
docs/figures/ |
Figures used in this README |
CHANGELOG.md |
Revision history |
pip install numpy
python3 scripts/miam_checks.py
The script validates the paper's arithmetic only. It does not measure security efficacy.
cd paper
pdflatex miam.tex
pdflatex miam.tex
Requires a standard TeX Live installation with TikZ and pgfplots.
Corrections, critiques, replications, and prototype implementations are welcome. Open an issue using the "Review finding" template, and cite the section, equation, figure, or claim number.
Thor, T. (2026). Mission-Invariant Architecture Morphing: Service-Graph Reconfiguration Against Post-Access Reconnaissance, with Cryptographic Epoch Isolation and Mission-Domain State Continuity (1.0.0). Zenodo. https://doi.org/10.5281/zenodo.23001045
Use the "Cite this repository" button on GitHub, or the metadata in CITATION.cff.
- Paper text and figures (
paper/): Creative Commons Attribution 4.0 International (CC BY 4.0). Reuse is permitted with attribution to the author. - Code (
scripts/): MIT License, seeLICENSE.
Appendix A of the paper is a reference claim set published as a defensive publication. Publication places the described mechanism in the public record as prior art. It does not grant any patent license, and it is not a patent application or legal opinion.


