Adaptive Network Security Policies via Belief Aggregation and Rollout

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hammar, Kim, Li, Yuchao, Alpcan, Tansu, Lupu, Emil C., Bertsekas, Dimitri
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917455487565824
author Hammar, Kim
Li, Yuchao
Alpcan, Tansu
Lupu, Emil C.
Bertsekas, Dimitri
author_facet Hammar, Kim
Li, Yuchao
Alpcan, Tansu
Lupu, Emil C.
Bertsekas, Dimitri
contents Evolving security vulnerabilities and shifting operational conditions require frequent updates to network security policies. These updates include adjustments to incident response procedures and modifications to access controls, among others. Reinforcement learning methods have been proposed for automating such policy adaptations, but most methods in the research literature lack performance guarantees and adapt slowly to changes. In this paper, we address these limitations and present a method for computing security policies that is scalable, offers theoretical guarantees, and adapts quickly to changes. The method uses a model or simulator of the system, which is updated when changes occur, and combines three components: belief estimation through particle filtering, offline policy computation through feature-based aggregation, and online policy adaptation through rollout. In particular, feature-based aggregation enables scalable offline optimization of a policy, while rollout adapts the policy online to changes in the system model without repeating the offline optimization. We analyze the approximation error of the aggregation and show that the rollout efficiently adapts policies to changes under certain conditions. Simulations and testbed results demonstrate that our method outperforms state-of-the-art methods on several benchmarks, including CAGE-2.
format Preprint
id arxiv_https___arxiv_org_abs_2507_15163
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adaptive Network Security Policies via Belief Aggregation and Rollout
Hammar, Kim
Li, Yuchao
Alpcan, Tansu
Lupu, Emil C.
Bertsekas, Dimitri
Systems and Control
Cryptography and Security
Evolving security vulnerabilities and shifting operational conditions require frequent updates to network security policies. These updates include adjustments to incident response procedures and modifications to access controls, among others. Reinforcement learning methods have been proposed for automating such policy adaptations, but most methods in the research literature lack performance guarantees and adapt slowly to changes. In this paper, we address these limitations and present a method for computing security policies that is scalable, offers theoretical guarantees, and adapts quickly to changes. The method uses a model or simulator of the system, which is updated when changes occur, and combines three components: belief estimation through particle filtering, offline policy computation through feature-based aggregation, and online policy adaptation through rollout. In particular, feature-based aggregation enables scalable offline optimization of a policy, while rollout adapts the policy online to changes in the system model without repeating the offline optimization. We analyze the approximation error of the aggregation and show that the rollout efficiently adapts policies to changes under certain conditions. Simulations and testbed results demonstrate that our method outperforms state-of-the-art methods on several benchmarks, including CAGE-2.
title Adaptive Network Security Policies via Belief Aggregation and Rollout
topic Systems and Control
Cryptography and Security
url https://arxiv.org/abs/2507.15163