Attacker Hunting in the Intranet Using Multi-Agent Reinforcement Learning

Guanhua Kong, Guozhen Cheng, Xiaohan Yang · 2024

For attacker's intranet lateral movement stage of the cyber kill chain, current cyber defense strategies face the problems of lacking dynamism, being unable to make realtime decisions, and failure to take into account the dynamic changes of attacker's strategies. In order to solve the above problems, this paper proposes a new gridworld model to describe the lateral movement scenario. The multi-agent stochastic game is used to model attack and defense process, and the Nash Q-learning algorithm is used to solve the optimal cyber defense strategy. Through multiple simulation experiments, it turns out that the proposed model has good convergence, and the average defense success rate of the defender is more than 70%, which verifies the effectiveness of the model.

Read the paper · More papers on PaperTik