A Focus on the Adaptation Phase of Cyber Resilience: Obfuscating Attack Graphs using a Reinforcement Learning Model

Aymar Le Père Tchimwa Bouom, Jean-Pierre Lienou, Frederica F. Nelson, Sachin S. Shetty, Wilson Ejuh Geh, Charles Kamhoua · 2023

Future networks provide reliable connectivity and require secure end-to-end networks for diverse applications. Due to the inevitability of cyber incidents, future networks need to be flexible, adaptive, scalable, and capable of dynamically responding to adverse events. Cyber resilience is an essential approach to tackling inevitable cyber incidents. Although it is important, there are very few contributions to the adaptation aspect of cyber resilience. In this paper, we propose an adaptation process based on obfuscating a network's attack graph with fake vulnerabilities. We use Q-learning to model the optimal assignment of fake vulnerabilities to hosts of a given network. Our model aims to obfuscate the known attack paths from an attack graph, as a resilient system must adapt to these attacks. In order to assess the methodology, we applied it to a small network scenario containing two vulnerable hosts both running their services. Our findings indicate that the proposed Q-learning model offers an optimal allocation of fake vulnerabilities, enabling network defenders to enhance their network's adaptability to cyber attacks. This, in turn, contributes to the overall improvement of cyber resilience.

Read the paper · More papers on PaperTik