Autonomous Network Defence using Reinforcement Learning
In the network security arms race, the defender is significantly disadvantaged as they need to successfully detect and counter every malicious attack. In contrast, the attacker needs to succeed only once. To level the playing field, we investigate the effectiveness of autonomous agents in a realistic network defence scenario. We first outline the problem, provide the background on reinforcement learning and detail our proposed agent design. Using a network environment simulation, with 13 hosts spanning 3 subnets, we train a novel reinforcement learning agent and show that it can reliably defend continual attacks by two advanced persistent threat (APT) red agents: one with complete knowledge of the network layout and another which must discover resources through exploration but is more general.
Code (1)
Tasks
reinforcement-learningReinforcement LearningSimilar Papers 제목 키워드 기반
Entity-based Reinforcement Learning for Autonomous Cyber Defence
A significant challenge for autonomous cyber defence is ensuring a defensive agent's ability to generalise across diverse network topologies and configurations. This capability is necessary for agents to remain effective…
Deep Reinforcement Learningreinforcement-learningReinforcement LearningInroads into Autonomous Network Defence using Explained Reinforcement Learning
Computer network defence is a complicated task that has necessitated a high degree of human involvement. However, with recent advancements in machine learning, fully autonomous network defence is becoming increasingly pl…
Decision MakingDeep Reinforcement Learningreinforcement-learningReinforcement LearningLearning Cyber Defence Tactics from Scratch with Multi-Agent Reinforcement Learning
Recent advancements in deep learning techniques have opened new possibilities for designing solutions for autonomous cyber defence. Teams of intelligent agents in computer network defence roles may reveal promising avenu…
Multi-agent Reinforcement Learningreinforcement-learningAdversarial Reinforcement Learning under Partial Observability in Autonomous Computer Network Defence
Recent studies have demonstrated that reinforcement learning (RL) agents are susceptible to adversarial manipulation, similar to vulnerabilities previously demonstrated in the supervised learning setting. While most exis…
reinforcement-learningReinforcement LearningReinforcement Learning (RL)Reinforcement Learning for Autonomous Defence in Software-Defined Networking
Despite the successful application of machine learning (ML) in a wide range of domains, adaptability---the very property that makes machine learning desirable---can be exploited by adversaries to contaminate training and…
BIG-bench Machine LearningGeneral Classificationreinforcement-learningReinforcement Learning+1