arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.16541cs.CRcs.AI

自主网络事件响应智能体的网络靶场评估

A Cyber Range Evaluation of Autonomous Network Incident Response Agents

  • KTH Royal Institute of Technology(瑞典皇家理工学院)
  • Swedish Defence Research Agency FOI(瑞典国防研究局(FOI))

机构由 AI 辅助整理,请以论文原文为准。

Jakob Nyberg, Teodor Sommestad, Andrei Buhaiu, Joakim Loxdal, Pontus Johnson, Mathias Ekstedt

AI总结:

本研究在网络靶场中评估自主网络入侵响应智能体,发现强化学习智能体比启发式策略更高效,且性能受对手策略和模拟用户影响。

AI中文摘要:

我们在一个旨在用于人类操作员培训的网络靶场中测试了用于自动化网络入侵响应的智能体的性能。该靶场实现了一个具有可变网络拓扑的仿真网络环境、红队仿真以及模拟用户智能体。防御智能体的目标是防止红队智能体访问网络中的主机,同时最小化由防御措施引起的可用性成本。告警通过SIEM平台生成,并映射到智能体使用的数据建模语言。我们测试了启发式智能体和使用强化学习学习的策略的组合。学习到的策略通过模拟该网络的网络攻击仿真器进行优化,以最小化综合成本。我们发现,强化学习智能体在整体上比启发式策略更有效地防御系统,并且性能在很大程度上取决于对手的策略与模拟用户的组合。

英文摘要:

We test the performance of agents for automated network intrusion response in a cyber range intended for human operator training. The range implements an emulated networking environment with a variable network topology, red-team emulation and simulated user agents. The goal of the defensive agents is to prevent hosts in the network from being accessed by the red-team agent, while minimizing the availability costs induced from defensive measures. Alerts are generated using a SIEM platform and mapped to a data modeling language used by the agents. We test a combination of heuristic agents and policies learned using reinforcement learning. The learned policies are optimized to minimize the combined cost using a cyber attack simulator modeling the network. We found that the reinforcement learning agents were overall more efficient at defending the system than the heuristic policy, and that the performance depends highly on the policy of the adversary in combination with the simulated users.

↑