AI 中文总结
针对企业网络受APT攻击及现有漏洞管理评估缺陷,提出VulnGym模拟工具,通过模拟基于真实APT配置文件训练的攻击者与执行可配置补丁策略的防御者对抗,依多因素定制漏洞管理,经实验验证其有效性。
AI 中文摘要
企业网络不断受到高级持续性威胁(APT)的攻击,随着披露漏洞增多,资源受限组织需确定打补丁优先级。现有标准单独评估漏洞,无法考量补丁策略应对随时间推进的对手的表现。以往工具模拟攻击活动存在缺陷。为此提出VulnGym,它能在含真实通用漏洞披露(CVE)的网络上,模拟基于真实APT配置文件训练的强化学习攻击者,对抗执行可配置补丁策略的防御者。二者基于共享网络行动,攻击者进展受防御者打补丁活动影响。实验表明漏洞管理须依组织环境、对手行为、网络拓扑和资产关键性定制。
英文摘要
Enterprise networks are continuously targeted by Advanced Persistent Threats (APTs), attack campaigns exploiting software vulnerabilities to compromise critical assets over time. As disclosed vulnerabilities grow, resource-constrained organizations must prioritize which ones to patch. Existing prioritization standards score vulnerabilities individually and cannot capture how a patching policy performs against an adversary that progresses through the network over time. Previous tools have simulated attack campaigns through Reinforcement Learning (RL), but either omit vulnerability management, leaving the attacker unopposed, or rely on synthetic networks disconnected from real threat data, and so cannot assess how a policy would fare against a realistic adversary. To fill this gap, we propose VulnGym, a simulation tool to evaluate vulnerability management policies. VulnGym simulates an RL-trained attacker, calibrated on real APT profiles, against a defender executing a configurable patching policy over a network with real Common Vulnerabilities and Exposures (CVEs). Both agents act on a shared, evolving network representation, so the attacker's progress is directly shaped by the defender's patching activity, allowing a given policy to be stress-tested against a realistic attack campaign. Experiments based on real-world vulnerabilities and two APTs show that vulnerability management must be tailored to organizational context, adversarial behavior, network topology, and asset criticality.