How can organizations detect, delay and confuse attackers who have already penetrated their network? This is the challenge that the Decor project, led by Muris Sladić, a doctoral student at the Faculty of Electrical Engineering and Computer Science, and Dr. Sebastian Garcia from the Stratosphere Lab, a research group at the Artificial Intelligence Center at the Faculty of Electrical Engineering and Computer Science, responds to. Decor uses artificial intelligence and the principles of cyber deception defense to detect, confuse and contain attackers who have already penetrated the corporate network. This gives defenders a more timely overview of the attackers' activities and more time to react. The project won the Get Spin-off/Start-up Ready! program, which helps students and researchers turn research ideas into future startups and spin-offs.
The Get Spin-off/Start-up Ready! program, organized by the Faculty of Electrical Engineering and Computer Science, connects students, doctoral students and researchers with business mentors, investors and technology commercialization experts. 16 participants from various faculties of CTU advanced to the first year, with six students from the Faculty of Electrical Engineering of CTU.
The winning project Decor was created at the intersection of cutting-edge research in the field of cybersecurity and the practical needs of companies. It was developed by Muris Sladić, a doctoral student in the Department of Computer Science of the Faculty of Engineering “Current security tools are very good at defending against attacks from the outside. The problem arises when an attacker gets inside the network using stolen credentials. Our goal is to create an environment that looks like the real infrastructure of the company, but is actually a controlled trap that will detect and detain the attacker,” explains Muris Sladić.
When an intruder is trapped
The technology uses the principle of so-called cyber deception. Instead of simply detecting an attack, it creates believable fake services and systems that the attacker interacts with, thinking that he is in the real environment of the organization. This gives defenders valuable time to react.
“In traditional conflicts, deceiving the adversary has been part of defense for thousands of years. In cybersecurity, this approach is only just beginning to gain traction. Our goal is to help organizations take control of what the attacker sees and believes,” says Sebastian Garcia, head of Stratosphere Lab.
According to him, time can be the difference between a minor incident and millions in damage. “If we can keep an attacker busy for two or three hours in a controlled environment, it can be the difference between a successful defense and a large-scale data breach.”
Artificial intelligence plays a significant role in the entire solution. While AI helps defenders create convincing deceptive environments, it is increasingly being used by attackers themselves.
“Artificial intelligence today significantly increases the capabilities of both defenders and attackers. Attacks are faster and more sophisticated than before. This is precisely why we believe that AI must be part of the defense – human teams alone can no longer react quickly enough to everything that happens in networks,” adds Garcia.
From research to product
The Decor project is based on research that Muris Sladić has been doing since his diploma thesis and then during his doctoral studies. The first versions of the solution were created as individual AI honeypots – fake services designed to detect attackers. However, they have gradually grown into a comprehensive system that can be deployed in a corporate environment.
The team is currently finalizing a so-called minimum viable product (MVP) and is in talks with potential customers about pilot deployments. “The technology is already working and has been tested both in laboratory conditions and in a limited real-world environment. Now we are focusing on making it ready for deployment in companies and meeting high security and trust requirements,” says Sladić.
According to him, the biggest challenge today is gaining customer trust. The technology itself is already working, but companies need to be sure that the new security solution will not pose any additional risks. That is why the team designed the system in such a way that it does not require the installation of additional hardware or software agents inside the protected organization. The first pilot deployments and verifications in production environments could begin in the next few months, according to the team.
A program that opens the door to the world of startups
Participation in the Get Spin-off/Start-up Ready! program, which offers participants mentoring from experienced entrepreneurs, practical workshops and individual consultations, contributed significantly to the development of the project.
“As a computer scientist, I had limited experience with the business side of things. The program helped me understand how to think about customers, a business model or verifying market potential. The biggest benefit for me was working with business mentors who helped us look at a completely different perspective on the project," says Muris Sladić.
Dr. Sebastian Garcia also positively evaluates the program. "At CTU, you can see a real effort to help researchers and students establish startups and spin-offs. The program has managed to gather experienced mentors and experts who can help them navigate the world of business and commercialization of research."
Applications for the next round of the Get Spin-off/Start-up Ready! program are open until September 8, 2026. The program is intended for students, doctoral students, postdoctoral fellows and researchers who want to verify the commercial potential of their ideas and research results.
"If you feel that your research or project can have a real impact in practice, definitely try it. At worst, you will gain a new perspective on your work. At best, you may find that you have the foundation for a future startup," summarizes Muris Sladić's experience of participating in the program.