Lucía Alba Torres, Miguel Rebollo, Javier Palanca, Mario Aragonés Lozano
Modern cyber threats demand coordinated defensive strategies that extend beyond centralized security mechanisms. However, existing multi-agent platforms exhibit critical limitations in explicit communication and real-time coordination for cyberdefense operations. This work proposes a hierarchical multi-agent architecture for autonomous cyberdefense that addresses these limitations through structured inter-agent communication and distributed coordination. The architecture integrates a centralized monitor agent with specialized defensive swarms deployed across operational hosts. It is implemented using SPADE 4.1 (Smart Python Agent Development Environment) to enable XMPP-based (Extensible Messaging and Presence Protocol) communication with low-latency messaging and location transparency. Four specialized swarms—Network Defender, Host Defender, Anomaly Detection, and Forensic and Recovery—perform autonomous defensive tasks. A secure authentication mechanism ensures trusted communication between monitor and deployer agents. The system was evaluated in a controlled virtualized environment using the Network Defender Swarm as an illustrative case. The experimental results focus on internal coordination behavior, messaging efficiency, and end-to-end detection time across increasing levels of parallelism. A scan agent scalability analysis shows that moderate parallelism (2–16 agents) yields the lowest Total Detection Time (12.88 s across the full TCP port range), while excessive agent counts degrade performance. Results demonstrate how the proposed architecture supports low-latency communication, efficient coordination, and parallel task execution. Message latency benchmarks show improvements compared to classical agent frameworks such as JADE. These findings provide initial evidence that communication-centric multi-agent architectures can facilitate coordinated and adaptive cyberdefense operations, while serving as a platform for further experimental evaluation.