Optimizing Cyber Defense in Dynamic Active Directories through Reinforcement Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Goel, Diksha, Moore, Kristen, Guo, Mingyu, Wang, Derui, Kim, Minjune, Camtepe, Seyit
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909232886972416
author Goel, Diksha
Moore, Kristen
Guo, Mingyu
Wang, Derui
Kim, Minjune
Camtepe, Seyit
author_facet Goel, Diksha
Moore, Kristen
Guo, Mingyu
Wang, Derui
Kim, Minjune
Camtepe, Seyit
contents This paper addresses a significant gap in Autonomous Cyber Operations (ACO) literature: the absence of effective edge-blocking ACO strategies in dynamic, real-world networks. It specifically targets the cybersecurity vulnerabilities of organizational Active Directory (AD) systems. Unlike the existing literature on edge-blocking defenses which considers AD systems as static entities, our study counters this by recognizing their dynamic nature and developing advanced edge-blocking defenses through a Stackelberg game model between attacker and defender. We devise a Reinforcement Learning (RL)-based attack strategy and an RL-assisted Evolutionary Diversity Optimization-based defense strategy, where the attacker and defender improve each other strategy via parallel gameplay. To address the computational challenges of training attacker-defender strategies on numerous dynamic AD graphs, we propose an RL Training Facilitator that prunes environments and neural networks to eliminate irrelevant elements, enabling efficient and scalable training for large graphs. We extensively train the attacker strategy, as a sophisticated attacker model is essential for a robust defense. Our empirical results successfully demonstrate that our proposed approach enhances defender's proficiency in hardening dynamic AD graphs while ensuring scalability for large-scale AD.
format Preprint
id arxiv_https___arxiv_org_abs_2406_19596
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Optimizing Cyber Defense in Dynamic Active Directories through Reinforcement Learning
Goel, Diksha
Moore, Kristen
Guo, Mingyu
Wang, Derui
Kim, Minjune
Camtepe, Seyit
Cryptography and Security
Artificial Intelligence
Machine Learning
This paper addresses a significant gap in Autonomous Cyber Operations (ACO) literature: the absence of effective edge-blocking ACO strategies in dynamic, real-world networks. It specifically targets the cybersecurity vulnerabilities of organizational Active Directory (AD) systems. Unlike the existing literature on edge-blocking defenses which considers AD systems as static entities, our study counters this by recognizing their dynamic nature and developing advanced edge-blocking defenses through a Stackelberg game model between attacker and defender. We devise a Reinforcement Learning (RL)-based attack strategy and an RL-assisted Evolutionary Diversity Optimization-based defense strategy, where the attacker and defender improve each other strategy via parallel gameplay. To address the computational challenges of training attacker-defender strategies on numerous dynamic AD graphs, we propose an RL Training Facilitator that prunes environments and neural networks to eliminate irrelevant elements, enabling efficient and scalable training for large graphs. We extensively train the attacker strategy, as a sophisticated attacker model is essential for a robust defense. Our empirical results successfully demonstrate that our proposed approach enhances defender's proficiency in hardening dynamic AD graphs while ensuring scalability for large-scale AD.
title Optimizing Cyber Defense in Dynamic Active Directories through Reinforcement Learning
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2406.19596