A Cyber Range Evaluation of Autonomous Network Incident Response Agents

📅 2026-09-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究在模拟网络环境中测试自动化响应代理对网络入侵的防御效果,使用强化学习优化策略,相比启发式方法更有效。
📝 Abstract
We test the performance of agents for automated network intrusion response in a cyber range intended for human operator training. The range implements an emulated networking environment with a variable network topology, red-team emulation and simulated user agents. The goal of the defensive agents is to prevent hosts in the network from being accessed by the red-team agent, while minimizing the availability costs induced from defensive measures. Alerts are generated using a SIEM platform and mapped to a data modeling language used by the agents. We test a combination of heuristic agents and policies learned using reinforcement learning. The learned policies are optimized to minimize the combined cost using a cyber attack simulator modeling the network. We found that the reinforcement learning agents were overall more efficient at defending the system than the heuristic policy, and that the performance depends highly on the policy of the adversary in combination with the simulated users.
Problem

Research questions and friction points this paper is trying to address.

Cyber Range
Autonomous Network Incident Response
Red-Team Emulation
Availability Costs
Reinforcement Learning
Innovation

Methods, ideas, or system contributions that make the work stand out.

reinforcement learning
cyber range
automated network intrusion response
heuristic policy
SIEM platform
🔎 Similar Papers
No similar papers found.
J
Jakob Nyberg
Department of Network and Systems Engineering at KTH Royal Institute of Technology in Stockholm, Sweden
Teodor Sommestad
Teodor Sommestad
Swedish Defence Research Agency FOI
A
Andrei Buhaiu
Department of Network and Systems Engineering at KTH Royal Institute of Technology in Stockholm, Sweden
J
Joakim Loxdal
Department of Network and Systems Engineering at KTH Royal Institute of Technology in Stockholm, Sweden
Pontus Johnson
Pontus Johnson
Professor, KTH Royal Institute of Technology
cyber securityenterprise architecture
Mathias Ekstedt
Mathias Ekstedt
Professor, KTH Royal Institute of Technology
Cyber SecurityInformation SecuritySCADA and ICS securityThreat ModelingSoftware Systems Architecture