Intelligent Hopping Mechanism for Deception Defense Scenarios Based on Reinforcement Learning

Yazhuo Gao, Lin Yang, Ran Zhu, Yang Feng, Yining Cao, Long Zhang · 2024

Strategies such as deploying honeypots and utilizing Moving Target Defense can occasionally mislead attackers. However, these methods often struggle to counteract the advanced detection and analysis tactics employed by attackers, particularly when the defenses are based on static probabilities for scenario changes. In response, a sophisticated deceptive defense mechanism named DSHopping (Deception Scenario Hopping) has been meticulously developed, utilizing reinforcement learning. DSHopping intelligently calculates transition probabilities, considering the current network state and available resources, which enhances its effectiveness in deception. The experimental results from the prototype system are remarkable, demonstrating that DSHopping has boosted the capture rate by a substantial 46%. This performance starkly contrasts with the best static transition probability observed in various attack detection scenarios. Ultimately, DSHopping has proven to be crucial in strengthening the system's ability to effectively capture attacks.

Read the paper · More papers on PaperTik