arXiv:2506.22706cs.CRcs.AI2025-06被引 2

让防御系统学会在变化网络中通用应对各类攻击。

General Autonomous Cybersecurity Defense: Learning Robust Policies for Dynamic Topologies and Diverse Attackers

  • 设计可适应动态网络拓扑的通用防御策略
  • 在多种变化环境中实现稳定防御性能
  • 适合需要跨场景部署的自动化安全系统

面对不断演化的网络威胁,如恶意软件、勒索软件和钓鱼攻击,自主网络安全防御(ACD)系统已成为实时检测与响应的关键,支持可选的人工干预。然而,现有ACD系统依赖于网络动态平稳的假设,在真实场景中,网络拓扑可能因攻击者或防御者行为、系统故障或时间演化而改变,导致当前防御代理自适应能力失效。此外,许多代理在静态环境中训练,对特定拓扑过拟合,难以泛化到分布外的网络结构。本文通过探索在动态网络环境中学习可泛化策略的方法,提出通用自主网络安全防御(GACD),以解决上述挑战。

原文摘要 · Abstract (English)

In the face of evolving cyber threats such as malware, ransomware and phishing, autonomous cybersecurity defense (ACD) systems have become essential for real-time threat detection and response with optional human intervention. However, existing ACD systems rely on limiting assumptions, particularly the stationarity of the underlying network dynamics. In real-world scenarios, network topologies can change due to actions taken by attackers or defenders, system failures, or time evolution of networks, leading to failures in the adaptive capabilities of current defense agents. Moreover, many agents are trained on static environments, resulting in overfitting to specific topologies, which hampers their ability to generalize to out-of-distribution network topologies. This work addresses these challenges by exploring methods for developing agents to learn generalizable policies across dynamic network environments -- general ACD (GACD).

自主防御动态网络泛化能力

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。