Leveraging Reinforcement Learning in Red Teaming for Advanced Ransomware Attack Simulations

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Cheng, Redino, Christopher, Clark, Ryan, Rahman, Abdul, Aguinaga, Sal, Murli, Sathvik, Nandakumar, Dhruv, Rao, Roland, Huang, Lanxiao, Radke, Daniel, Bowen, Edward
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929399478091776
author Wang, Cheng
Redino, Christopher
Clark, Ryan
Rahman, Abdul
Aguinaga, Sal
Murli, Sathvik
Nandakumar, Dhruv
Rao, Roland
Huang, Lanxiao
Radke, Daniel
Bowen, Edward
author_facet Wang, Cheng
Redino, Christopher
Clark, Ryan
Rahman, Abdul
Aguinaga, Sal
Murli, Sathvik
Nandakumar, Dhruv
Rao, Roland
Huang, Lanxiao
Radke, Daniel
Bowen, Edward
contents Ransomware presents a significant and increasing threat to individuals and organizations by encrypting their systems and not releasing them until a large fee has been extracted. To bolster preparedness against potential attacks, organizations commonly conduct red teaming exercises, which involve simulated attacks to assess existing security measures. This paper proposes a novel approach utilizing reinforcement learning (RL) to simulate ransomware attacks. By training an RL agent in a simulated environment mirroring real-world networks, effective attack strategies can be learned quickly, significantly streamlining traditional, manual penetration testing processes. The attack pathways revealed by the RL agent can provide valuable insights to the defense team, helping them identify network weak points and develop more resilient defensive measures. Experimental results on a 152-host example network confirm the effectiveness of the proposed approach, demonstrating the RL agent's capability to discover and orchestrate attacks on high-value targets while evading honeyfiles (decoy files strategically placed to detect unauthorized access).
format Preprint
id arxiv_https___arxiv_org_abs_2406_17576
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Leveraging Reinforcement Learning in Red Teaming for Advanced Ransomware Attack Simulations
Wang, Cheng
Redino, Christopher
Clark, Ryan
Rahman, Abdul
Aguinaga, Sal
Murli, Sathvik
Nandakumar, Dhruv
Rao, Roland
Huang, Lanxiao
Radke, Daniel
Bowen, Edward
Cryptography and Security
Artificial Intelligence
Machine Learning
Ransomware presents a significant and increasing threat to individuals and organizations by encrypting their systems and not releasing them until a large fee has been extracted. To bolster preparedness against potential attacks, organizations commonly conduct red teaming exercises, which involve simulated attacks to assess existing security measures. This paper proposes a novel approach utilizing reinforcement learning (RL) to simulate ransomware attacks. By training an RL agent in a simulated environment mirroring real-world networks, effective attack strategies can be learned quickly, significantly streamlining traditional, manual penetration testing processes. The attack pathways revealed by the RL agent can provide valuable insights to the defense team, helping them identify network weak points and develop more resilient defensive measures. Experimental results on a 152-host example network confirm the effectiveness of the proposed approach, demonstrating the RL agent's capability to discover and orchestrate attacks on high-value targets while evading honeyfiles (decoy files strategically placed to detect unauthorized access).
title Leveraging Reinforcement Learning in Red Teaming for Advanced Ransomware Attack Simulations
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2406.17576