Markov Decision Process For Automatic Cyber Defense

07/12/2022
by   Xiaofan Zhou, et al.
0

It is challenging for a security analyst to detect or defend against cyber-attacks. Moreover, traditional defense deployment methods require the security analyst to manually enforce the defenses in the presence of uncertainties about the defense to deploy. As a result, it is essential to develop an automated and resilient defense deployment mechanism to thwart the new generation of attacks. In this paper, we propose a framework based on Markov Decision Process (MDP) and Q-learning to automatically generate optimal defense solutions for networked system states. The framework consists of four phases namely; the model initialization phase, model generation phase, Q-learning phase, and the conclusion phase. The proposed model collects real network information as inputs and then builds them into structural data. We implement a Q-learning process in the model to learn the quality of a defense action in a particular state. To investigate the feasibility of the proposed model, we perform simulation experiments and the result reveals that the model can reduce the risk of network systems from cyber attacks. Furthermore, the experiment shows that the model has shown a certain level of flexibility when different parameters are used for Q-learning.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/22/2019

Markov Decision Process to Enforce Moving Target Defence Policies

Moving Target Defense (MTD) is an emerging game-changing defense strateg...
research
09/03/2020

Developing Enterprise Cyber Situational Awareness

The topic will focus on the U.S. Department of Defense strategy towards ...
research
05/24/2023

From Shortcuts to Triggers: Backdoor Defense with Denoised PoE

Language models are often at risk of diverse backdoor attacks, especiall...
research
10/29/2018

An approach to predictively securing critical cloud infrastructures through probabilistic modeling

Cloud infrastructures are being increasingly utilized in critical infras...
research
02/12/2021

Deep Reinforcement Learning for Backup Strategies against Adversaries

Many defensive measures in cyber security are still dominated by heurist...
research
11/23/2022

Principled Data-Driven Decision Support for Cyber-Forensic Investigations

In the wake of a cybersecurity incident, it is crucial to promptly disco...
research
01/26/2022

Autonomous Cyber Defense Introduces Risk: Can We Manage the Risk?

From denial-of-service attacks to spreading of ransomware or other malwa...

Please sign up or login with your details

Forgot password? Click here to reset