Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Other literature type . 2026
License: CC BY
Data sources: ZENODO
https://doi.org/10.2139/ssrn.6...
Article . 2026 . Peer-reviewed
Data sources: Crossref
ZENODO
Other literature type . 2026
License: CC BY
Data sources: Datacite
ZENODO
Other literature type . 2026
License: CC BY
Data sources: Datacite
versions View all 3 versions
addClaim

On Earned Autonomy: Delegating Network-Lethal Authority to Machines

Authors: Morley, Simon;

On Earned Autonomy: Delegating Network-Lethal Authority to Machines

Abstract

<div> Biological immune systems do not ask permission to act. They earn the right through evolutionary rehearsal. </div> <div> <span>Autonomous defensive capabilities exist. Endpoint detection and response (EDR) and extended detection and response (XDR) platforms classify threats using machine learning. Security Orchestration, Automation, and Response (SOAR) systems execute automated playbooks. Cloud security services block known-malicious traffic without human intervention. For threats that match predefined categories, machines already act at machine speed.</span> </div> <div> <span>The problem is what happens when they don't match.</span> </div> <div> <span>Current autonomous defence operates under two regimes: vendor-asserted trust, where operators accept accuracy claims without environment-specific evidence; or pre-authorised response, where humans approve action classes in advance. Both work for known threats. Neither addresses the legitimacy of autonomous action against novel, time-critical attacks, zero-days, behavioural anomalies, abuse patterns that fall outside existing signatures and playbooks.</span> </div> <div> <span>This paper introduces earned autonomy: a governance framework for delegating defensive authority to machines. Like identity and access management, authority must be demonstrated before granted, scoped, and continuously validated, but applied to machine judgment rather than user access. We present IBSR (Inline Block Simulation Report) and Guard as a reference implementation: IBSR learns behavioural patterns and produces judgment through rehearsal on live traffic, Guard executes blocking at kernel level, and the separation ensures autonomous action is never taken without prior evidence of competence.</span> </div> <div> <span>The gap is not capability, it is legitimacy. Digital infrastructure requires an equivalent governance mechanism: not assumed trust, but demonstrated competence.</span> </div>

Keywords

machine learning, earned autonomy, governance, intrusion detection, network security, autonomous defense, eBPF, XDP

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green