paper-with-me

Papers

Automated Security Response through Online Learning with Adaptive Conjectures

2024-02-19 · Kim Hammar, Tao Li, Rolf Stadler, Quanyan Zhu

We study automated security response for an IT infrastructure and formulate the interaction between an attacker and a defender as a partially observed, non-stationary game. We relax the standard assumption that the game model is correctly specified and consider that each player has a probabilistic conjecture about the model, which may be misspecified in the sense that the true model has probability 0. This formulation allows us to capture uncertainty and misconception about the infrastructure and the intents of the players. To learn effective game strategies online, we design Conjectural Online Learning (COL), a novel method where a player iteratively adapts its conjecture using Bayesian learning and updates its strategy through rollout. We prove that the conjectures converge to best fits, and we provide a bound on the performance improvement that rollout enables with a conjectured model. To characterize the steady state of the game, we propose a variant of the Berk-Nash equilibrium. We present COL through an advanced persistent threat use case. Testbed evaluations show that COL produces effective security strategies that adapt to a changing environment. We also find that COL enables faster convergence than current reinforcement learning techniques.

📄 PDF Abstract BibTeX arXiv:2402.12499

Code (1)

limmen/csle 공식 구현

Similar Papers 제목 키워드 기반

AgenticCyber: A GenAI-Powered Multi-Agent System for Multimodal Threat Detection and Adaptive Response in Cybersecurity

2025-12-06 · Shovan Roy arxiv

The increasing complexity of cyber threats in distributed environments demands advanced frameworks for real-time detection and response across multimodal data streams. This paper introduces AgenticCyber, a generative AI …

Intrusion Detection

REGARD: Rules of EngaGement for Automated cybeR Defense to aid in Intrusion Response

2023-05-23 · Damodar Panigrahi, William Anderson, Joshua Whitman, Sudip Mittal 외

Automated Intelligent Cyberdefense Agents (AICAs) that are part Intrusion Detection Systems (IDS) and part Intrusion Response Systems (IRS) are being designed to protect against sophisticated and automated cyber-attacks.…

Intrusion Detection

Large Language Models in Cybersecurity: Applications, Vulnerabilities, and Defense Techniques

2025-07-18 · Niveen O. Jaffal, Mohammed Alkhanafseh, David Mohaisen arxiv

Large Language Models (LLMs) are transforming cybersecurity by enabling intelligent, adaptive, and automated approaches to threat detection, vulnerability assessment, and incident response. With their advanced language u…

Advancing Autonomous Incident Response: Leveraging LLMs and Cyber Threat Intelligence

2025-08-14 · Amine Tellache, Abdelaziz Amara Korba, Amdjed Mokhtari, Horea Moldovan 외 arxiv

Effective incident response (IR) is critical for mitigating cyber threats, yet security teams are overwhelmed by alert fatigue, high false-positive rates, and the vast volume of unstructured Cyber Threat Intelligence (CT…

Response Generation

An Object Detection based Solver for Google's Image reCAPTCHA v2

2021-04-07 · Md Imran Hossen, Yazhou Tu, Md Fazle Rabby, Md Nazmul Islam 외

Previous work showed that reCAPTCHA v2's image challenges could be solved by automated programs armed with Deep Neural Network (DNN) image classifiers and vision APIs provided by off-the-shelf image recognition services.…

Objectobject-detectionObject Detection