用排队论建模漏洞动态,实现自适应防御并大幅减少活跃漏洞。
A Queueing-Theoretic Framework for Dynamic Attack Surfaces: Data-Integrated Risk Analysis and Adaptive Defense

- 将漏洞数量视为队列中的积压任务,模拟其随时间演变。
- 实证发现修补时间呈重尾分布,导致攻击面长期依赖性。
- 基于强化学习的自适应防御策略,可降低90%以上活跃漏洞。
我们构建了一个基于排队论的框架,用于建模网络攻击面的时间演化过程,其中活跃漏洞数被表示为队列中的积压量。漏洞在被发现或创建时进入系统,修复或被成功利用后离开。基于该模型,我们研究自动化对攻防动态的影响,引入人工智能放大因子来缩放漏洞出现、利用和修复速率。分析表明,即使自动化对称,也会提升成功利用的速率。通过开源软件供应链的真实漏洞数据验证模型,结果与现实攻击面动态高度吻合。实证显示修补时间具有重尾特性,我们证明这会引发漏洞积压的长程依赖,有助于解释持续存在的网络风险。利用该排队抽象,我们提出系统性风险缓解方法,将动态防御问题建模为带有资源预算和切换成本约束的受限马尔可夫决策过程,并开发出具有理论近优后悔界的强化学习算法。数值实验验证了该方法的有效性,表明所提出的自适应强化学习防御策略能显著降低成功利用次数并缓解重尾队列事件。在ARVO数据集上的追踪实验显示,相比现有实践,该策略在不增加总体维护预算的前提下,将软件供应链中平均活跃漏洞数降低超过90%。我们的结果使防御者能够量化长程依赖攻击动态下的累积暴露风险,并设计具有可证明效率的自适应防御策略。
原文摘要 · Abstract (English)
We develop a queueing-theoretic framework to model the temporal evolution of cyber-attack surfaces, where the number of active vulnerabilities is represented as the backlog of a queue. Vulnerabilities arrive as they are discovered or created, and leave the system when they are patched or successfully exploited. Building on this model, we study how automation affects attack and defense dynamics by introducing an AI amplification factor that scales arrival, exploit, and patching rates. Our analysis shows that even symmetric automation can increase the rate of successful exploits. We validate the model using vulnerability data collected from an open source software supply chain and show that it closely matches real-world attack surface dynamics. Empirical results reveal heavy-tailed patching times, which we prove induce long-range dependence in vulnerability backlog and help explain persistent cyber risk. Utilizing our queueing abstraction for the attack surface, we develop a systematic approach for cyber risk mitigation. We formulate the dynamic defense problem as a constrained Markov decision process with resource-budget and switching-cost constraints, and develop a reinforcement learning (RL) algorithm that achieves provably near-optimal regret. Numerical experiments validate the approach and demonstrate that our adaptive RL-based defense policies significantly reduce successful exploits and mitigate heavy-tail queue events. Using trace-driven experiments on the ARVO dataset, we show that the proposed RL-based defense policy reduces the average number of active vulnerabilities in a software supply chain by over 90% compared to existing defense practices, without increasing the overall maintenance budget. Our results allow defenders to quantify cumulative exposure risk under long-range dependent attack dynamics and to design adaptive defense strategies with provable efficiency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。