ExploitFlow, cyber security exploitation routes for Game Theory and AI research in robotics

08/04/2023
by   Víctor Mayoral Vilches, et al.
0

This paper addresses the prevalent lack of tools to facilitate and empower Game Theory and Artificial Intelligence (AI) research in cybersecurity. The primary contribution is the introduction of ExploitFlow (EF), an AI and Game Theory-driven modular library designed for cyber security exploitation. EF aims to automate attacks, combining exploits from various sources, and capturing system states post-action to reason about them and understand potential attack trees. The motivation behind EF is to bolster Game Theory and AI research in cybersecurity, with robotics as the initial focus. Results indicate that EF is effective for exploring machine learning in robot cybersecurity. An artificial agent powered by EF, using Reinforcement Learning, outperformed both brute-force and human expert approaches, laying the path for using ExploitFlow for further research. Nonetheless, we identified several limitations in EF-driven agents, including a propensity to overfit, the scarcity and production cost of datasets for generalization, and challenges in interpreting networking states across varied security settings. To leverage the strengths of ExploitFlow while addressing identified shortcomings, we present Malism, our vision for a comprehensive automated penetration testing framework with ExploitFlow at its core.

READ FULL TEXT

page 9

page 15

page 16

page 18

page 20

page 21

research
02/07/2020

Proceedings of the Artificial Intelligence for Cyber Security (AICS) Workshop 2020

The workshop will focus on the application of artificial intelligence to...
research
04/20/2021

Prospective Artificial Intelligence Approaches for Active Cyber Defence

Cybercriminals are rapidly developing new malicious tools that leverage ...
research
05/12/2020

A Survey of Behavior Trees in Robotics and AI

Behavior Trees (BTs) were invented as a tool to enable modular AI in com...
research
02/15/2023

AI Security Threats against Pervasive Robotic Systems: A Course for Next Generation Cybersecurity Workforce

Robotics, automation, and related Artificial Intelligence (AI) systems h...
research
01/05/2022

AI for Beyond 5G Networks: A Cyber-Security Defense or Offense Enabler?

Artificial Intelligence (AI) is envisioned to play a pivotal role in emp...
research
06/05/2023

Building Resilient SMEs: Harnessing Large Language Models for Cyber Security in Australia

The escalating digitalisation of our lives and enterprises has led to a ...

Please sign up or login with your details

Forgot password? Click here to reset