An Intrusion Response System utilizing Deep Q-Networks and System Partitions

02/16/2022
by   Valeria Cardellini, et al.
0

Intrusion Response is a relatively new field of research. Recent approaches for the creation of Intrusion Response Systems (IRSs) use Reinforcement Learning (RL) as a primary technique for the optimal or near-optimal selection of the proper countermeasure to take in order to stop or mitigate an ongoing attack. However, most of them do not consider the fact that systems can change over time or, in other words, that systems exhibit a non-stationary behavior. Furthermore, stateful approaches, such as those based on RL, suffer the curse of dimensionality, due to a state space growing exponentially with the size of the protected system. In this paper, we introduce and develop an IRS software prototype, named irs-partition. It leverages the partitioning of the protected system and Deep Q-Networks to address the curse of dimensionality by supporting a multi-agent formulation. Furthermore, it exploits transfer learning to follow the evolution of non-stationary systems.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/10/2020

The Impact of Non-stationarity on Generalisation in Deep Reinforcement Learning

Non-stationarity arises in Reinforcement Learning (RL) even in stationar...
research
05/10/2019

Reinforcement Learning in Non-Stationary Environments

Reinforcement learning (RL) methods learn optimal decisions in the prese...
research
03/30/2022

Factored Adaptation for Non-Stationary Reinforcement Learning

Dealing with non-stationarity in environments (i.e., transition dynamics...
research
03/06/2023

Intrusion Response Systems: Past, Present and Future

The rapid expansion of the Internet of Things and the emergence of edge ...
research
06/08/2022

A Study of Continual Learning Methods for Q-Learning

We present an empirical study on the use of continual learning (CL) meth...
research
03/25/2021

Near Real-time Learning and Extraction of Attack Models from Intrusion Alerts

Critical and sophisticated cyberattacks often take multitudes of reconna...
research
03/15/2023

Joint Security-vs-QoS Game Theoretical Optimization for Intrusion Response Mechanisms for Future Network Systems

Network connectivity exposes the network infrastructure and assets to vu...

Please sign up or login with your details

Forgot password? Click here to reset