Towards Autonomous Network Defense: Reinforcement Learning Environment for a Defense Agent

Ayesha Babar, Li Li, Adrian Taylor, Mohammad Zulkernine · 2024

In the present cyberspace, it is evident that the cyber attacks occur at a high pace that will surpass the human ability to respond in a timely fashion. Nations and government entities recognize the importance of addressing this issue and are increasingly emphasizing the necessity of autonomous defense systems. Defining autonomous defense entails deploying autonomous cyber agents and mechanisms to test these agents. Cyber agents are typically evaluated through cyber exercises, and the entity responsible for defensive tactics and maintaining internal network defense during the exercise is termed as a Blue Agent or a Defense Agent. The capacity of Reinforcement Learning (RL) to adapt and respond to novel threats makes it particularly valuable for enhancing cybersecurity measures. In this research, we leverage a well-known API, suited to create an RL-based environment for testing and training a defense agent. This environment is designed specifically to facilitate the RL agent in detecting multi-step aggressive access behavior. While a more sophisticated agent is not yet operational, the environment has been successfully tested against a rudimentary test agent, indicating its effectiveness.

Read the paper · More papers on PaperTik