Node Fragility Reward Shaping Based on Reinforcement Learning in Intranet Penetration Scenario

Yinghui Xu, Haonan Tan, Jianyu Deng, Le Wang · 2024

As the core platform for internal communication and data sharing within an organization, the intranet environment is designed and operated with the characteristics of shared resources and dynamic adjustment. Consequently, it presents a multi-dimensional attack surface susceptible to exploitation by attackers. Reinforcement learning offers the capability to learn and adapt to the dynamics and complexity of intranet environments through interactive engagement with the environment. Over recent years, reinforcement learning has gained increasing prominence in intranet attack and defense penetration scenarios. To achieve better defense, researchers model the intranet environment to find the attack paths that exist in the environment. However, during the execution of penetration tasks, the attacking agent typically receives a reward only upon successful attacks, leading to sparse reward signals. This sparsity hampers the agent’s training process and limits its effectiveness in intranet penetration. To address the issue of sparse reward, we proposed a reward function based on node vulnerability in intranet scenarios to increase the density of reward values, thereby improving the attack capability of the agent. We conducted two sets of experiments to evaluate the proposed method. The first experiment demonstrated that the improved method achieved faster convergence compared to the original method. The second experiment assessed the attack process of the agent trained with the improved method, revealing superior attack performance.

Read the paper · More papers on PaperTik