Autonomous Network Defence using Reinforcement Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Foley, Myles, Hicks, Chris, Highnam, Kate, Mavroudis, Vasilios
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912047877324800
author Foley, Myles
Hicks, Chris
Highnam, Kate
Mavroudis, Vasilios
author_facet Foley, Myles
Hicks, Chris
Highnam, Kate
Mavroudis, Vasilios
contents In the network security arms race, the defender is significantly disadvantaged as they need to successfully detect and counter every malicious attack. In contrast, the attacker needs to succeed only once. To level the playing field, we investigate the effectiveness of autonomous agents in a realistic network defence scenario. We first outline the problem, provide the background on reinforcement learning and detail our proposed agent design. Using a network environment simulation, with 13 hosts spanning 3 subnets, we train a novel reinforcement learning agent and show that it can reliably defend continual attacks by two advanced persistent threat (APT) red agents: one with complete knowledge of the network layout and another which must discover resources through exploration but is more general.
format Preprint
id arxiv_https___arxiv_org_abs_2409_18197
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Autonomous Network Defence using Reinforcement Learning
Foley, Myles
Hicks, Chris
Highnam, Kate
Mavroudis, Vasilios
Artificial Intelligence
Cryptography and Security
Machine Learning
In the network security arms race, the defender is significantly disadvantaged as they need to successfully detect and counter every malicious attack. In contrast, the attacker needs to succeed only once. To level the playing field, we investigate the effectiveness of autonomous agents in a realistic network defence scenario. We first outline the problem, provide the background on reinforcement learning and detail our proposed agent design. Using a network environment simulation, with 13 hosts spanning 3 subnets, we train a novel reinforcement learning agent and show that it can reliably defend continual attacks by two advanced persistent threat (APT) red agents: one with complete knowledge of the network layout and another which must discover resources through exploration but is more general.
title Autonomous Network Defence using Reinforcement Learning
topic Artificial Intelligence
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2409.18197