Implementation and Validation of Reinforcement Learning Strategies in Automated Attack Testing

Jun Yang, Qiukai Ye, Ming Xian, Lin Ni · 2024

Attack testing refers to a series of testing methods proposed through simulating real network attack scenarios, characterizing corresponding intrusion environments, actively discovering network security vulnerabilities, and determining various threats faced by the target network. However, current manual testing faces issues such as high costs and poor adaptability. As a result, automated attack testing has become a hotspots in current research, with the automated attack strategy serving as its core. Its role is to replace attack testers in executing attack techniques. This article models the entire attack testing process as a Markov decision model, maps attack techniques to reinforcement learning strategies, and verifies the convergence and feasibility of these reinforcement learning strategies by training and testing various reinforcement learning and fixed strategies in a simulated network environment. The experimental results show that reinforcement learning strategies based on the DDQN algorithm are superior to other reinforcement learning strategies and have the fastest convergence speed. All three reinforcement learning strategies can stably achieve the testing objectives in the test experiments, and their performance is far superior to that of the fixed strategy.

Read the paper · More papers on PaperTik