<p>Current network pentest simulations lack dynamic defense mechanisms, limiting realism and effectiveness. To address this, we propose a novel adversarial environment extending the NASim framework by integrating a probabilistic defender capable of fixing vulnerabilities. Through rigorous mathematical analysis, we establish that vulnerability discovery and patching probabilities inherently follow the <i>Beta distribution</i>, whose bounded characteristics align precisely with the vulnerability lifecycle. This forms the foundation for our probability-based adjustable defense strategy. We implement the SecuMark framework to enable realistic bidirectional attacker-defender interactions within NASim. Experiments across diverse network topologies evaluate RL algorithms under varying defense intensities. Key findings indicate that defender intervention significantly reduces pentest success rates, exemplified by reductions of 30–50% under high defense levels. DQN and standard Q-Learning maintain relatively high success rates under low-to-moderate defenses, while Q-Learning augmented with experience replay demonstrates superior adaptability under intense defensive pressure. Furthermore, the specific parameters (<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10207_2025_1089_Article_IEq1.gif" Format="GIF" Height="10" Rendition="HTML" Resolution="72" Type="Linedraw" Width="14" /> </InlineMediaObject> <EquationSource Format="TEX">\(\alpha \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>α</mi> </math></EquationSource> </InlineEquation>, <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10207_2025_1089_Article_IEq2.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\(\beta \)</EquationSource> <EquationSource Format="MATHML"><math> <mi>β</mi> </math></EquationSource> </InlineEquation>) of the Beta distribution critically influence the performance volatility of RL algorithms. SecuMark enhances simulation authenticity, provides a robust testbed for adversarial strategy optimization.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Construction of network pentest-defense adversarial environment based on NASim

  • Yuanzhi Huo,
  • Sicong You,
  • Mengjie Jin

摘要

Current network pentest simulations lack dynamic defense mechanisms, limiting realism and effectiveness. To address this, we propose a novel adversarial environment extending the NASim framework by integrating a probabilistic defender capable of fixing vulnerabilities. Through rigorous mathematical analysis, we establish that vulnerability discovery and patching probabilities inherently follow the Beta distribution, whose bounded characteristics align precisely with the vulnerability lifecycle. This forms the foundation for our probability-based adjustable defense strategy. We implement the SecuMark framework to enable realistic bidirectional attacker-defender interactions within NASim. Experiments across diverse network topologies evaluate RL algorithms under varying defense intensities. Key findings indicate that defender intervention significantly reduces pentest success rates, exemplified by reductions of 30–50% under high defense levels. DQN and standard Q-Learning maintain relatively high success rates under low-to-moderate defenses, while Q-Learning augmented with experience replay demonstrates superior adaptability under intense defensive pressure. Furthermore, the specific parameters ( \(\alpha \) α , \(\beta \) β ) of the Beta distribution critically influence the performance volatility of RL algorithms. SecuMark enhances simulation authenticity, provides a robust testbed for adversarial strategy optimization.