Existing literature primarily focuses on static or semi-dynamic approaches for the placement of deception resources that do not fully exploit the network security state. To address these limitations, we introduce an adaptive reinforcement learning approach to enhance the selection of denial & deception strategies, employing honeypatches as a key deception method. Our approach entails modeling the network using an attack graph, capturing the attacker’s strategy, and the defender’s action space. Tailored to each attacker, our approach uses Q-learning to determine the optimal type and placement of denial & deception actions. We constructed an attack graph of real attack scenarios on a target network and used it to run our Q-learning simulation, providing a realistic environment for evaluation.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Adaptive Reinforcement Learning-Based Approach for Effective Cyber Denial and Deception Strategies Finding

  • Amal Sayari,
  • Slim Rekhis,
  • Yacine Djemaiel,
  • Ali Mabrouk

摘要

Existing literature primarily focuses on static or semi-dynamic approaches for the placement of deception resources that do not fully exploit the network security state. To address these limitations, we introduce an adaptive reinforcement learning approach to enhance the selection of denial & deception strategies, employing honeypatches as a key deception method. Our approach entails modeling the network using an attack graph, capturing the attacker’s strategy, and the defender’s action space. Tailored to each attacker, our approach uses Q-learning to determine the optimal type and placement of denial & deception actions. We constructed an attack graph of real attack scenarios on a target network and used it to run our Q-learning simulation, providing a realistic environment for evaluation.