paper-with-me

홈 › Papers

Deep VULMAN: A Deep Reinforcement Learning-Enabled Cyber Vulnerability Management Framework

2022-08-03 · Soumyadeep Hore, Ankit Shah, Nathaniel D. Bastian

Cyber vulnerability management is a critical function of a cybersecurity operations center (CSOC) that helps protect organizations against cyber-attacks on their computer and network systems. Adversaries hold an asymmetric advantage over the CSOC, as the number of deficiencies in these systems is increasing at a significantly higher rate compared to the expansion rate of the security teams to mitigate them in a resource-constrained environment. The current approaches are deterministic and one-time decision-making methods, which do not consider future uncertainties when prioritizing and selecting vulnerabilities for mitigation. These approaches are also constrained by the sub-optimal distribution of resources, providing no flexibility to adjust their response to fluctuations in vulnerability arrivals. We propose a novel framework, Deep VULMAN, consisting of a deep reinforcement learning agent and an integer programming method to fill this gap in the cyber vulnerability management process. Our sequential decision-making framework, first, determines the near-optimal amount of resources to be allocated for mitigation under uncertainty for a given system state and then determines the optimal set of prioritized vulnerability instances for mitigation. Our proposed framework outperforms the current methods in prioritizing the selection of important organization-specific vulnerabilities, on both simulated and real-world vulnerability data, observed over a one-year period.

📄 PDF Abstract BibTeX arXiv:2208.02369

Code (0)

등록된 구현이 없습니다.

Tasks

Decision MakingDeep Reinforcement LearningManagementreinforcement-learningReinforcement Learning (RL)Sequential Decision Making

Similar Papers 제목 키워드 기반

VulCPE: Context-Aware Cybersecurity Vulnerability Retrieval and Management

2025-05-20 · Yuning Jiang, Feiyang Shang, Freedy Tan Wei You, Huilin Wang 외

The dynamic landscape of cybersecurity demands precise and scalable solutions for vulnerability management in heterogeneous systems, where configuration-specific vulnerabilities are often misidentified due to inconsisten…

ManagementRelation ExtractionRetrieval

CVE-LLM : Ontology-Assisted Automatic Vulnerability Evaluation Using Large Language Models

2025-02-21 · Rikhiya Ghosh, Hans-Martin von Stockhausen, Martin Schmitt, George Marica Vasile 외

The National Vulnerability Database (NVD) publishes over a thousand new vulnerabilities monthly, with a projected 25 percent increase in 2024, highlighting the crucial need for rapid vulnerability identification to mitig…

Management

Integrated Cyber-Physical Resiliency for Power Grids under IoT-Enabled Dynamic Botnet Attacks

2024-01-03 · Yuhan Zhao, Juntao Chen, Quanyan Zhu

The wide adoption of Internet of Things (IoT)-enabled energy devices improves the quality of life, but simultaneously, it enlarges the attack surface of the power grid system. The adversary can gain illegitimate control …

Decision Making

Vulnerability of Building Energy Management against Targeted False Data Injection Attacks:Model Predictive Control vs. Proportional Integral

2023-12-06 · Xiaoyu Ge, Kamelia Norouzi, Faegheh Moazeni, Mirel Sehic 외

Cybersecurity in building energy management is crucial for protecting infrastructure, ensuring data integrity, and preventing unauthorized access or manipulation. This paper investigates the energy efficiency and cyberse…

energy managementManagementModel Predictive Control

A stochastic Gordon-Loeb model for optimal cybersecurity investment under clustered attacks

2025-05-02 · Giorgia Callegaro, Claudio Fontana, Caroline Hillairet, Beatrice Ongarato

We develop a continuous-time stochastic model for optimal cybersecurity investment under the threat of cyberattacks. The arrival of attacks is modeled using a Hawkes process, capturing the empirically relevant feature of…

ClusteringManagement