arXiv:2503.02780cs.CRcs.LG2025-03被引 2

提出可量化网络韧性模型,助力防御系统在攻击中快速恢复。

Quantitative Resilience Modeling for Autonomous Cyber Defense

  • 构建多目标韧性评估框架,融合资源关键性与操作优先级
  • 在CybORG环境验证,证明主动加固与快速恢复最有效
  • 支持跨时间与拓扑的韧性聚合,适合安全运维人员使用

网络韧性指系统在遭受攻击后以最小影响恢复运行的能力。现有方法缺乏适用于多样网络结构与攻击模式的统一韧性定义。本文提出一种可量化的韧性建模方法,综合考虑多种防御目标、关键资源对日常运营的重要性,并为安全人员提供可解释的韧性评估。我们在CybORG强化学习框架中评估该方法,分析韧性、成本与目标优先级之间的权衡。进一步提出跨时间变化攻击模式和多网络拓扑的韧性指标聚合方法,全面刻画系统韧性。基于该度量设计的强化学习自主防御代理,相较多个启发式基线表现更优,表明主动网络加固与受损主机的及时恢复是高效防御的关键。

原文摘要 · Abstract (English)

Cyber resilience is the ability of a system to recover from an attack with minimal impact on system operations. However, characterizing a network's resilience under a cyber attack is challenging, as there are no formal definitions of resilience applicable to diverse network topologies and attack patterns. In this work, we propose a quantifiable formulation of resilience that considers multiple defender operational goals, the criticality of various network resources for daily operations, and provides interpretability to security operators about their system's resilience under attack. We evaluate our approach within the CybORG environment, a reinforcement learning (RL) framework for autonomous cyber defense, analyzing trade-offs between resilience, costs, and prioritization of operational goals. Furthermore, we introduce methods to aggregate resilience metrics across time-variable attack patterns and multiple network topologies, comprehensively characterizing system resilience. Using insights gained from our resilience metrics, we design RL autonomous defensive agents and compare them against several heuristic baselines, showing that proactive network hardening techniques and prompt recovery of compromised machines are critical for effective cyber defenses.

网络安全韧性建模强化学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。