arXiv:2409.18197cs.AIcs.CR2024-09被引 53

用强化学习训练自主防御代理,有效抵御两类高级持续性威胁攻击。

Autonomous Network Defence using Reinforcement Learning

  • 设计基于强化学习的自主防御代理,模拟真实网络环境
  • 在13台主机3个子网环境下,成功抵御两类持续攻击
  • 适用于需要自动化响应的网络安全场景,尤其适合复杂网络

在网络攻防对抗中,防守方需防范所有恶意攻击,而攻击方只需一次成功即可获胜。为扭转这一劣势,本文研究了在真实网络防御场景中自主智能体的有效性。首先明确问题背景,介绍强化学习基础,并提出新型代理设计。通过包含13台主机、3个子网的网络仿真环境,训练了一个新型强化学习代理。结果表明,该代理能可靠防御两类先进持续性威胁(APT)红队攻击:一类具备完整网络拓扑知识,另一类需通过探索发现资源,更具通用性。

原文摘要 · Abstract (English)

In the network security arms race, the defender is significantly disadvantaged as they need to successfully detect and counter every malicious attack. In contrast, the attacker needs to succeed only once. To level the playing field, we investigate the effectiveness of autonomous agents in a realistic network defence scenario. We first outline the problem, provide the background on reinforcement learning and detail our proposed agent design. Using a network environment simulation, with 13 hosts spanning 3 subnets, we train a novel reinforcement learning agent and show that it can reliably defend continual attacks by two advanced persistent threat (APT) red agents: one with complete knowledge of the network layout and another which must discover resources through exploration but is more general.

强化学习网络安全自主防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。