Incorporating Deception into CyberBattleSim for Autonomous Defense

08/31/2021
by   Erich Walter, et al.
0

Deceptive elements, including honeypots and decoys, were incorporated into the Microsoft CyberBattleSim experimentation and research platform. The defensive capabilities of the deceptive elements were tested using reinforcement learning based attackers in the provided capture the flag environment. The attacker's progress was found to be dependent on the number and location of the deceptive elements. This is a promising step toward reproducibly testing attack and defense algorithms in a simulated enterprise network with deceptive defensive elements.

READ FULL TEXT

page 7

page 8

research
04/08/2021

Secure (S)Hell: Introducing an SSH Deception Proxy Framework

Deceiving an attacker in the network security domain is a well establish...
research
04/20/2021

Network Defense is Not a Game

Research seeks to apply Artificial Intelligence (AI) to scale and extend...
research
04/01/2023

Coordinated Defense Allocation in Reach-Avoid Scenarios with Efficient Online Optimization

Deriving strategies for multiple agents under adversarial scenarios pose...
research
08/31/2021

Informing Autonomous Deception Systems with Cyber Expert Performance Data

The performance of artificial intelligence (AI) algorithms in practice d...
research
07/03/2021

Too Expensive to Attack: Enlarge the Attack Expense through Joint Defense at the Edge

The distributed denial of service (DDoS) attack is detrimental to busine...
research
08/02/2022

A Model for Perimeter-Defense Problems with Heterogeneous Teams

We develop a model of the multi-agent perimeter-defense game to calculat...
research
11/23/2021

Fixed Points in Cyber Space: Rethinking Optimal Evasion Attacks in the Age of AI-NIDS

Cyber attacks are increasing in volume, frequency, and complexity. In re...

Please sign up or login with your details

Forgot password? Click here to reset