Intelligent asset parameterisation for risk-based moving target defence
Konstantinos G. Kyriakopoulos, Lincoln Kamau Kiarie, Marios Aristodemou, Susan Babirye, Amitkumar Patel, Isaiah Nassiuma, Mercedeh Jafarkhanloo-Rezaei, Iain W. Phillips, Carsten R. Maple, Carsten R. Maple, Gregory Epiphaniou · Computers & Security · 2026
In an era characterised by evolving cyber threats and sophisticated adversar-ial behaviour, the field of cyber-security faces a continuous and formidablechallenge. The development of dynamic and adaptive security control mea-sures is imperative in order to safeguard critical assets and information.This article delves into the realm of Moving Target Defence (MTD), astrategic approach that seeks to outmanoeuvre adversaries by constantlyshifting the security landscape. Our research specifically focuses on the ap-plication of Reinforcement Learning (RL) in MTD, with a focus on threatexposure and the efficacy of control strategies with respect to risk reduction.A defensive RL agent is proposed that incorporates attack graphs as ablueprint to assess possible paths that an adversary may take. By consideringreceived events about an adversary’s actions, the defensive agent continuouslyupdates its knowledge about the adversary’s position on the attack graph.The proposed research establishes and evaluates a risk-based, RL-drivenagent capable of MTD operations in order to address adversarial behaviours.The proposed approach provides valuable insights into optimally deployingsecurity controls under dynamic threat scenarios and restricted budget resources.