paper-with-me

홈 › Papers

POMDPs Make Better Hackers: Accounting for Uncertainty in Penetration Testing

2013-07-31 · Carlos Sarraute, Olivier Buffet, Joerg Hoffmann

Penetration Testing is a methodology for assessing network security, by generating and executing possible hacking attacks. Doing so automatically allows for regular and systematic testing. A key question is how to generate the attacks. This is naturally formulated as planning under uncertainty, i.e., under incomplete knowledge about the network configuration. Previous work uses classical planning, and requires costly pre-processes reducing this uncertainty by extensive application of scanning methods. By contrast, we herein model the attack planning problem in terms of partially observable Markov decision processes (POMDP). This allows to reason about the knowledge available, and to intelligently employ scanning actions as part of the attack. As one would expect, this accurate solution does not scale. We devise a method that relies on POMDPs to find good attacks on individual machines, which are then composed into an attack on the network as a whole. This decomposition exploits network structure to the extent possible, making targeted approximations (only) where needed. Evaluating this method on a suitably adapted industrial test suite, we demonstrate its effectiveness in both runtime and solution quality.

📄 PDF Abstract BibTeX arXiv:1307.8182

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Counterfactual equivalence for POMDPs, and underlying deterministic environments

2018-01-11 · Stuart Armstrong

Partially Observable Markov Decision Processes (POMDPs) are rich environments often used in machine learning. But the issue of information and causal structures in POMDPs has been relatively little studied. This paper pr…

BIG-bench Machine Learningcounterfactual

Les POMDP font de meilleurs hackers: Tenir compte de l'incertitude dans les tests de penetration

2013-07-30 · Carlos Sarraute, Olivier Buffet, Joerg Hoffmann

Penetration Testing is a methodology for assessing network security, by generating and executing possible hacking attacks. Doing so automatically allows for regular and systematic testing. A key question is how to genera…

Managing Geological Uncertainty in Critical Mineral Supply Chains: A POMDP Approach with Application to U.S. Lithium Resources

2025-02-08 · Mansur Arief, Yasmine Alonso, CJ Oshiro, William Xu 외

The world is entering an unprecedented period of critical mineral demand, driven by the global transition to renewable energy technologies and electric vehicles. This transition presents unique challenges in mineral reso…

Decision Making

A POMDP Extension with Belief-dependent Rewards

2010-12-01 · NeurIPS 2010 12 · Mauricio Araya, Olivier Buffet, Vincent Thomas, Françcois Charpillet

Partially Observable Markov Decision Processes (POMDPs) model sequential decision-making problems under uncertainty and partial observability. Unfortunately, some problems cannot be modeled with state-dependent reward fu…

Decision MakingSequential Decision Making

Actual Causality and Responsibility Attribution in Decentralized Partially Observable Markov Decision Processes

2022-04-01 · Stelios Triantafyllou, Adish Singla, Goran Radanovic

Actual causality and a closely related concept of responsibility attribution are central to accountable decision making. Actual causality focuses on specific outcomes and aims to identify decisions (actions) that were cr…

Decision MakingDecision Making Under UncertaintySequential Decision Making