当前位置:首页 > 报告详情

萨拉·法默_用于自主弹性网络防御的强化学习_WP.pdf

上传人: 张** 编号:175535 2024-09-13 11页 534.01KB

1、 1 Abstract Future cyber threats will include high volumes of sophisticated machine speed cyber-attacks that are able to evade and overwhelm traditional cyber defenders.In support of social good and global security we take the exceptional approach of summarising a large body of Defence research appl

2、ying Reinforcement Learning(RL)to automated cyber defence decision making i.e.,what action(s)do we take when a cyber-attack is detected?Promising concepts include two contrasting Multi Agent RL(MARL)approaches,deep RL combined with heterogenous Graph Neural Networks(GNNs),and a Cyber First Aid demon

3、strator.To achieve this we have matured simulators and tools including development of advanced adversaries to improve defender robustness.We have demonstrated that autonomous cyber defence is feasible on real representative networks and plan to quadruple the number of high fidelity projects in the n

4、ext year.1.Introduction Cyber-attackers are increasingly using Machine Learning(ML)approaches to launch high volumes of sophisticated machine speed cyber-attacks that can evade and overwhelm traditional cyber defenders(Kaloudi et al.,2020),(Guembe,et al.,2022).Furthermore,human cyber defenders are i

5、n high demand and cannot be located with all cyber systems.ML is a mature technology for anomaly detection,and commercial Security Orchestration and Automated Response(SOAR)platforms have begun implementing ML driven cyber defence decision making capability(i.e.,what action do we take when an attack

6、 is detected).However,they are not mission or context aware,which is of particular concern in a Defence application,where it is often impractical to deploy large numbers of skilled cyber defenders to the front line.1 Presented at Black Hat USA,August 2024 2 Frazer-Nash Consultancy,Leatherhead,UK 3 D

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要概括了使用强化学习(Reinforcement Learning, RL)进行自主弹性网络防御(Autonomous Resilient Cyber Defence, ARCD)的研究进展。主要内容包括: 1. 介绍了网络防御中使用机器学习(Machine Learning, ML)的挑战,特别是高维输入和组合动作空间的问题。 2. 总结了六个使用RL进行网络防御的研究项目,包括使用多智能体强化学习(Multi-Agent RL, MARL)的Co-Decyber项目,应用于海军系统的MARL项目,以及VIRA、泛化网络防御、Odin项目等。 3. 讨论了这些研究的发现,包括多智能体方法优于单智能体,RL智能体优于基于规则的防御者,以及能够防御训练中未见过的网络拓扑等。 4. 指出了研究的局限性,如大多数研究仍在各种复杂程度的模拟器中进行,需要转移到更真实的网络环境中。 5. 提出了未来的研究方向,包括提高智能体的泛化能力,探索人类-机器团队协作,以及提高智能体的可解释性等。 6. 强调了继续开放知识共享的重要性,以促进社会公益和全球安全。
强化学习如何应用于网络安全? 多智能体强化学习在网络安全中的应用有哪些优势? 如何通过强化学习提高网络安全的泛化能力?
客服
商务合作
小程序
服务号
折叠