Co-Evolutionary Defence of Active Directory Attack Graphs via GNN-Approximated Dynamic Programming

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Goel, Diksha, Ahmad, Hussain, Moore, Kristen, Guo, Mingyu
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909855347900416
author Goel, Diksha
Ahmad, Hussain
Moore, Kristen
Guo, Mingyu
author_facet Goel, Diksha
Ahmad, Hussain
Moore, Kristen
Guo, Mingyu
contents Modern enterprise networks increasingly rely on Active Directory (AD) for identity and access management. However, this centralization exposes a single point of failure, allowing adversaries to compromise high-value assets. Existing AD defense approaches often assume static attacker behavior, but real-world adversaries adapt dynamically, rendering such methods brittle. To address this, we model attacker-defender interactions in AD as a Stackelberg game between an adaptive attacker and a proactive defender. We propose a co-evolutionary defense framework that combines Graph Neural Network Approximated Dynamic Programming (GNNDP) to model attacker strategies, with Evolutionary Diversity Optimization (EDO) to generate resilient blocking strategies. To ensure scalability, we introduce a Fixed-Parameter Tractable (FPT) graph reduction method that reduces complexity while preserving strategic structure. Our framework jointly refines attacker and defender policies to improve generalization and prevent premature convergence. Experiments on synthetic AD graphs show near-optimal results (within 0.1 percent of optimality on r500) and improved performance on larger graphs (r1000 and r2000), demonstrating the framework's scalability and effectiveness.
format Preprint
id arxiv_https___arxiv_org_abs_2505_11710
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Co-Evolutionary Defence of Active Directory Attack Graphs via GNN-Approximated Dynamic Programming
Goel, Diksha
Ahmad, Hussain
Moore, Kristen
Guo, Mingyu
Cryptography and Security
Modern enterprise networks increasingly rely on Active Directory (AD) for identity and access management. However, this centralization exposes a single point of failure, allowing adversaries to compromise high-value assets. Existing AD defense approaches often assume static attacker behavior, but real-world adversaries adapt dynamically, rendering such methods brittle. To address this, we model attacker-defender interactions in AD as a Stackelberg game between an adaptive attacker and a proactive defender. We propose a co-evolutionary defense framework that combines Graph Neural Network Approximated Dynamic Programming (GNNDP) to model attacker strategies, with Evolutionary Diversity Optimization (EDO) to generate resilient blocking strategies. To ensure scalability, we introduce a Fixed-Parameter Tractable (FPT) graph reduction method that reduces complexity while preserving strategic structure. Our framework jointly refines attacker and defender policies to improve generalization and prevent premature convergence. Experiments on synthetic AD graphs show near-optimal results (within 0.1 percent of optimality on r500) and improved performance on larger graphs (r1000 and r2000), demonstrating the framework's scalability and effectiveness.
title Co-Evolutionary Defence of Active Directory Attack Graphs via GNN-Approximated Dynamic Programming
topic Cryptography and Security
url https://arxiv.org/abs/2505.11710