TACAM Algorithmic Random Walks & Sector-CPE Knowledge Graph Synthesis
J. McKenney
This paper is a standalone treatise in the WG-07 Threat Modeling and TACAM Matrix working group rather than an entry in a numbered series. Its own References section cites a confirmed working-group sibling, the TACAM Matrix spectral decomposition treatise, whose adversary threat quotients this engine's knowledge-graph traversal is built to simulate against.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Most risk models for industrial facilities assume losses follow a bell curve, with extreme events rare. Cyberattacks on physical infrastructure do not behave that way: a few extreme, low-probability events drive most of the damage, and a bell-curve model badly understates the worst case, leaving operators and insurers with false confidence.
This paper describes a simulation engine that walks step by step across a knowledge graph of a facility's systems and vulnerabilities, the way an attacker would, to find the paths that end in the most severe consequences. A real facility's graph is too large to search exhaustively, so the engine narrows its search using weights built from live vulnerability and defense data, and deliberately runs a fraction of its runs in an exaggerated, higher-temperature mode meant to surface rare, severe paths a normal search would miss.
It then converts the simulated losses into the extreme-value statistics used in insurance and risk finance, producing a short set of summary numbers that show a risk committee how far conventional insurance limits fall short of the facility's true exposure to a severe event.
Abstract#
Traditional threat modeling and industrial risk assessment rest on Gaussian assumptions and static tree structures. Authored by J. McKenney (Tetrel Security and Eigenia Research) for Working Group WG-07, this treatise sets out the mathematics and algorithms of the Seldon Monte Carlo engine. On interconnected critical infrastructure, Gaussian models fail: empirical cyber-physical losses show heavy fat tails driven by extreme, low-probability, high-consequence events, and normal distributions understate catastrophic tail risk by 200 to 500 percent. A production facility graph exceeds 3.2 million nodes and 85 million edges, where unconstrained pathfinding causes combinatorial explosion. We resolve this with an Importance-Weighted Breadth-First Search that extracts subgraphs bounded by degree, EPSS trajectories, and spectral eigenvector boosts. We formulate the 14-dimension adjacency edge weighting function governing probabilistic traversal, incorporating CISA Known Exploited Vulnerabilities, zone-aware IEC 62443 Security Level Target defense modifiers, and temporal vulnerability momentum. To surface Black Swan pathways, the engine applies thermodynamic shocks that quadruple the Boltzmann temperature (T_bs equals 4T), with vector-space semantic teleportation across air-gapped zones using 4096-dimensional embeddings. Breach losses are modeled through power-law mathematics, using the Hill Estimator for live Pareto tail-index calculation, where OT incidents sit near a tail index of 1.35, an infinite-variance regime. Three Taleb metrics follow: the Gaussian-to-Pareto Ratio, the Surprise Zone, and the Antifragility Score.
1. The Epistemological Failure of Gaussian Risk in Operational Technology#
Risk management in critical infrastructure has long suffered from the uncritical adoption of Gaussian statistics. In classical financial engineering, standard portfolio theory assumes asset variations follow thin-tailed normal distributions where probabilities decay exponentially as . In physical facilities, this assumption leads operators to calculate the Value at Risk () by multiplying standard deviations from the mean:
where is historical mean incident loss, is standard deviation, and is the standard normal deviate (e.g., ).
In operational technology, however, physical systems operate within the domain of Extremistan: an environment dominated by power-law dynamics where single extreme events render historical averages meaningless. A single cyber-physical intrusion into a safety instrumented system or a 110 kV substation switchgear can trigger tens of millions of dollars in equipment destruction, environmental remediation, and catastrophic plant downtime.
When an operational technology asset owner calculates risk using Gaussian equations, the model inherently predicts that a 6-sigma event is essentially impossible (occurring once in 1.38 million years). Yet, in real-world critical infrastructure, systemic multi-stage attacks occur repeatedly due to common-mode failures, shared vendor dependencies, and protocol vulnerabilities. To discover these critical failure modes before adversaries execute them, we reject thin-tailed assumptions and formulate a physics-grounded random walk engine.
2. Computational Tractability: Importance-Weighted Subgraph Extraction#
A complete cyber-physical digital twin of a hyperscale facility incorporates mechanical process piping, electrical single-line schematics, IT/OT network topology, logical access permissions, and Common Platform Enumerations (CPEs). In production environments, this graph encompasses over 3.2 million nodes and 85 million edges.
Running unconstrained graph traversals or Monte Carlo pathfinding across 85 million edges in real-time is computationally intractable, precipitating combinatorial query explosions that exhaust memory and lock graph database engines. Seldon resolves this through Importance-Weighted Subgraph Extraction.
The Subgraph Selection Algorithm#
- Seed Anchoring: The simulation selects an entry point representing a specific adversary access vector (e.g., an unauthenticated remote maintenance VPN, a compromised building management workstation, or a vendor contractor laptop).
- Constrained Breadth-First Search (BFS): Seldon executes a directed BFS to a maximum depth of hops. Edges are restricted strictly to cyber-physical attack relations:
- Importance Scoring: To prioritize node retention within an in-memory execution budget of nodes, each discovered node is evaluated via an Importance Score :
where is the degree centrality of the node, is the empirical Exploit Prediction Scoring System probability cached from live threat intelligence feeds, and is a spectral eigenvector boost assigned to top-decile topological graph pivot points:
where is the leading eigenvector of the normalized graph adjacency matrix (). The top 20 highest-degree nodes are guaranteed inclusion to preserve critical facility network choke points.
3. The 14-Dimension Adjacency Edge Weighting Engine#
Once the extracted simulation workspace is loaded into high-performance in-memory memory structures, Seldon computes a dynamic traversal weight for every directed edge .
The weight represents the instantaneous transition probability that an adversary occupying node successfully penetrates node within a discrete operational epoch. The edge weight is formulated as:
where is the baseline structural relation weight, and represents ten dynamic environmental and threat intelligence modifiers:
Mathematical Formulation of Key Modifiers#
- Exploit Prediction Trajectory (): Scaling transition likelihood from 0.5 (zero exploit likelihood) to 2.0 (confirmed high likelihood).
- Active In-The-Wild Exploitation ():
- Zone-Aware Security Level Defense Suppression (): Per IEC 62443-3-3, target security levels reduce attacker traversal probability through defensive depth: For an unhardened perimeter (), (zero resistance). In a fully hardened control cell (), , heavily penalizing edge traversal likelihood.
- Spectral Pivot Point Multiplier (): High eigenvector centrality nodes act as structural bridges between otherwise segregated operational zones:
4. Thermodynamic Graph Traversal: Boltzmann Softmax & Temperature Shock#
Standard simulations execute between 10,000 and 50,000 iterations. During nominal iterations, threat actors behave quasi-rationally, following optimal paths toward high-value assets. Seldon implements this through a Boltzmann (Softmax) Distribution:
where is the set of outgoing edges from current node , and is the thermodynamic temperature parameter controlling simulation randomness.
The Black Swan Shock Protocol#
This protocol is stated in full here.
Nominal walks illuminate standard attack paths that network engineers already anticipate. However, catastrophic infrastructure breaches routinely occur via obscure, low-probability vectors that human defenders dismiss as negligible.
To reveal these vulnerability chains, Seldon reserves 10 percent to 15 percent of all Monte Carlo iterations as explicit Black Swan Shock Walks:
- Quadrupled Temperature Parameter: The thermodynamic temperature is multiplied fourfold: As , the term , causing . The Boltzmann distribution flattens toward a uniform distribution: This thermodynamic shock mathematically forces the simulated adversary to ignore obvious routes and traverse highly improbable, unmitigated paths, testing non-linear vulnerability compositions.
- Vector-Space Semantic Teleportation: Real-world cyber-physical attacks frequently bypass network perimeters via non-topological mechanisms: vendor remote access sessions, rogue maintenance USBs, or dual-homed engineering laptops. To model this without inventing fictional physical wires, Seldon injects Semantic Teleportation:
- At each step of a Black Swan walk, the walker evaluates a teleportation probability .
- When triggered, instead of traversing physical edges in , the walker queries PostgreSQL (
pgvector) using cosine similarity across 4096-dimensional text-embedding vectors:
where is the high-dimensional embedding capturing operational context, firmware codebase ancestry, and vendor supply-chain metadata. This allows the walker to teleport across logical air gaps into semantically linked control logic.
5. Extremistan Actuarial Sampling: Hill Estimator & Pareto Inversion#
When an adversarial walk successfully penetrates a designated physical Crown Jewel (e.g., a Safety Instrumented System, a 33 kV substation breaker, or a Coolant Distribution Unit PLC), assigning a static average financial loss hides the true catastrophic tail risk. Seldon integrates power-law fat-tail mathematics.
The Hill Estimator for Tail Index #
Historical cyber-physical loss datasets are analyzed using the Hill Estimator to establish the empirical Pareto tail index :
where represents order statistics of historical incident loss data, is the lower threshold for power-law behavior, and is the number of extreme upper-tail observations.
Empirical loss analysis across industrial infrastructure demonstrates that OT cyber incidents reside in the regime , proving conclusively that critical infrastructure operates in an infinite variance regime.
Inverse Transform Sampling#
Upon target compromise, the sampled financial consequence is drawn directly from the continuous Pareto distribution via Inverse Transform Sampling:
where is a pseudorandom deviate. This formulation ensures that simulations capture extreme economic shocks: where a single breach cascades into tens of millions of dollars in continuous business interruption, turbine rotor replacement, and regulatory fines.
6. Taleb Convergence Metrics & Capital Underwriting#
Following the completion of 50,000 iterations, Seldon compiles a suite of Taleb Metrics to govern capital allocation, insurance treaty attachment, and engineering hardening:
1. The Gaussian-to-Pareto (GvP) Ratio#
The GvP Ratio compares true tail risk against conventional corporate risk assumptions:
where is the Conditional Value at Risk (Expected Shortfall) at the 99th percentile:
A is an explicit warning to corporate risk committees and reinsurance syndicates that conventional property and casualty cyber limits are fundamentally inadequate.
2. The Surprise Zone ()#
The Surprise Zone measures the unhedged dollar gap between the threshold value at risk and the expected loss once that threshold is breached:
In thin-tailed Gaussian models, is negligible. In power-law OT environments, represents the catastrophic shortfall that bankrupts self-insured captives and exhausts standard commercial treaty limits.
3. Antifragility Score ()#
Each network zone and component is assigned an empirical Antifragility Score based on its non-linear response to systemic stress:
- : Fragile. The component suffers catastrophic, non-linear degradation under cyber stress (e.g., an unauthenticated PLC controlling high-pressure valves).
- : Robust. The component maintains steady-state operation but absorbs stress without adaptive improvement.
- : Antifragile. The component is architected with hardwired fail-safes and dynamic isolation conduits that benefit from localized failures by isolating compromised segments and preserving core plant stability.
7. Empirical Visualization: The Red Squadron Pheromone Trail#
To translate abstract topological probabilities into actionable operational intelligence for plant operators, the random walk trajectories are visualized directly within the Cyber Digital Twin interface.
As the 19 distinct Threat Actor Agents traverse the graph, they leave simulated digital pheromone trails along edges:
where is the pheromone decay constant, and is the pheromone deposited by agent upon traversing edge :
where is the total path length and is an impact scaling factor.
Edges that repeatedly act as structural bottlenecks for multiple threat actor profiles accumulate dense pheromone concentrations. In the WebGL / Babylon.js digital twin canvas, these critical conduits illuminate in vibrant orange and red. This provides control room operators with instantaneous visual confirmation of critical chokepoints, eliminating the need to parse raw graph database tables.
8. Conclusion#
By synthesizing graph theory, non-equilibrium statistical physics, and power-law actuarial mathematics, the Seldon Monte Carlo engine replaces qualitative security assumptions with rigorous mathematical reality.
Applying importance-weighted BFS allows real-time execution against multi-million-node models; 14-dimension adjacency weighting binds simulations to empirical threat data; thermodynamic shocks and semantic vector jumps expose concealed Black Swan pathways; and Pareto fat-tail metrics provide defensible financial grounding for capital allocation under Lloyd's Y5381. Through this architecture, critical infrastructure operators transition from fragile, reactive defense to provable, antifragile resilience.
9. References#
- Taleb, N. N. (2007). The Black Swan: The Impact of the Highly Improbable. New York: Random House.
- Taleb, N. N. (2012). Antifragile: Things That Gain from Disorder. New York: Random House.
- Hill, B. M. (1975). A Simple General Approach to Inference About the Tail of a Distribution. The Annals of Statistics, 3(5), 1163-1174.
- Clauset, A., Shalizi, C. R., & Newman, M. E. (2009). Power-law distributions in empirical data. SIAM Review, 51(4), 661-703.
- International Electrotechnical Commission. (2019). IEC 62443-3-3: Industrial communication networks, Network and system security, Part 3-3: System security requirements and security levels. Geneva: IEC.
- Cybersecurity and Infrastructure Security Agency. (2026). Known Exploited Vulnerabilities Catalog (CISA KEV). Washington, D.C.: CISA.
- First.org. (2025). Exploit Prediction Scoring System (EPSS) Version 3.
- McKenney, J. (2026). The TACAM Matrix: Spectral Decomposition and Adversary Threat Quotients in Industrial Control Systems. Eigenia Research Working Group 07 Treatise WG-07-TM-TACAM.
- Newman, M. E. (2018). Networks: An Introduction. Oxford: Oxford University Press.