学习OT系统的入侵响应策略
Learning Intrusion Response Strategies for OT Systems
浏览论文内容
中文总结 AI 辅助
本文提出基于POMDP的OT入侵响应形式化模型,结合部分可观测性,采用PPO学习方法,在仿真OT系统上验证了对多种MITRE攻击的有效性。
中文摘要 AI 辅助
针对运营技术(OT)系统的网络攻击对关键社会服务构成日益严重的威胁,这些系统用于监控和控制工业过程。因此,开发自动化入侵响应策略至关重要。本文提出了一种基于POMDP框架的OT入侵响应用例的形式化模型,该模型包含基于流量测量的部分可观测性的现实模型。该方法使我们能够开发基于PPO的可处理的、基于学习的自动化入侵响应求解方法。我们在一个仿真的OT系统上评估了所获得的响应策略,发现它们对研究用例中的多种MITRE攻击类型有效。
英文摘要
Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response strategies is highly important. In this paper, we present a formal model of an OT intrusion response use case using the POMDP framework. It includes a realistic model of partial observability that is based on traffic measurements. This approach allows us to develop tractable, learning-based solution methods for automated intrusion response, which are based on PPO. We evaluate the obtained response strategies on an emulated OT system and find that they are effective against several types of MITRE attacks for the studied use case.
发表机构
- KTH Royal Institute of Technology(KTH皇家理工学院)
机构由 AI 辅助整理,请以论文原文为准。