Cyber Resilience of IIoT Network Assets Using Multi-agent AI Against Advanced Persistent Threat
摘要
The Advanced Persistent Threat (APT) targets conventional business networks like industrial control system (ICS), cyber-physical system (CPS), Biometric and Industrial Internet of Things (IIoT) systems, etc. Especially, IIoT networks are incredibly complex, and an assault on one may cause a catastrophic calamity. The use of the voting algorithm to choose the final categorization improves upon the original result. It is common practice in many corporate settings to prioritize detection over false alarms when securing networked assets. The simulators Decentralized Multi-agent Security System (DMASS) and Generalized Anomaly Detection (GAD) algorithms were applied to detect and classify APT-vulnerable IoT nodes in the benchmarked dataset like UNSW-NB15, UNBISCX. The cross-method facilitates, system profiles to evaluate more accurately, the similarities among group of agents. The DMASS improved detection rates between by 80 and 85% in false alarm-heavy conditions and the generalized anomaly detection technique detected 85% of network threats. Agent choice and threshold cutoff to prevent brute force analysis boosted DMASS efficiency by 50%. The outcome demonstrates that the same conclusion regarding the security breach could have been reached with less computational effort.