Learning Intrusion Response Strategies for OT Systems

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文使用POMDP框架和基于PPO的学习方法,为OT系统开发自动化入侵响应策略,以应对针对工业控制系统的网络攻击。
📝 Abstract
Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response strategies is highly important. In this paper, we present a formal model of an OT intrusion response use case using the POMDP framework. It includes a realistic model of partial observability that is based on traffic measurements. This approach allows us to develop tractable, learning-based solution methods for automated intrusion response, which are based on PPO. We evaluate the obtained response strategies on an emulated OT system and find that they are effective against several types of MITRE attacks for the studied use case.
Problem

Research questions and friction points this paper is trying to address.

Operational Technology
Cyberattacks
Intrusion Response
Automated Strategies
Innovation

Methods, ideas, or system contributions that make the work stand out.

POMDP
partial observability
PPO
automated intrusion response
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
D
Duc Huy Le
Dept. of Network and Systems Engineering, KTH Royal Institute of Technology, Stockholm, Sweden
Rolf Stadler
Rolf Stadler
Professor, School of EECS, KTH Royal Institute of Technology
network managementcyber securitymachine learningdistributed systemscloud computing