用博弈论+大模型动态优化漏洞修复策略,提升防御适应性。
CyGATE: Game-Theoretic Cyber Attack-Defense Engine for Patch Strategy Optimization
- 将攻防过程建模为部分可观测随机博弈,结合信念状态应对不确定性。
- 通过实时威胁情报动态调整补丁优先级,显著提升高危漏洞响应效率。
- 支持多角色协同场景,适合复杂企业环境的智能安全决策。
现代网络攻击跨越多个阶段,防御者需在不确定环境下动态制定缓解策略。现有博弈论方法常依赖静态假设,且缺乏与实时威胁情报的整合,适应性受限。本文提出CyGATE,一种基于大语言模型(LLMs)与检索增强生成(RAG)的博弈论框架,用于优化攻防策略。在双代理场景中,将网络对抗建模为跨攻击链阶段的部分可观测随机博弈(POSG),双方均使用信念状态处理不确定性:攻击者动态调整战术,防御者依据风险演化与对手行为重新排序补丁。该框架具备灵活扩展性,可支持多代理场景,如协同攻击、协作防御或包含多方利益相关者的复杂企业环境。在动态补丁调度场景中验证表明,CyGATE能有效识别高风险漏洞,通过动态威胁集成实现自适应响应,以战略前瞻预判攻击者行为,并优化资源利用效率。
原文摘要 · Abstract (English)
Modern cyber attacks unfold through multiple stages, requiring defenders to dynamically prioritize mitigations under uncertainty. While game-theoretic models capture attacker-defender interactions, existing approaches often rely on static assumptions and lack integration with real-time threat intelligence, limiting their adaptability. This paper presents CyGATE, a game-theoretic framework modeling attacker-defender interactions, using large language models (LLMs) with retrieval-augmented generation (RAG) to enhance tactic selection and patch prioritization. Applied to a two-agent scenario, CyGATE frames cyber conflicts as a partially observable stochastic game (POSG) across Cyber Kill Chain stages. Both agents use belief states to navigate uncertainty, with the attacker adapting tactics and the defender re-prioritizing patches based on evolving risks and observed adversary behavior. The framework's flexible architecture enables extension to multi-agent scenarios involving coordinated attackers, collaborative defenders, or complex enterprise environments with multiple stakeholders. Evaluated in a dynamic patch scheduling scenario, CyGATE effectively prioritizes high-risk vulnerabilities, enhancing adaptability through dynamic threat integration, strategic foresight by anticipating attacker moves under uncertainty, and efficiency by optimizing resource use.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。