Exploration of the Application of Reinforcement Learning Algorithms in Network Security Situation Awareness
Hao Yang, Jian Bao, Wanting Lv, Yang Gao, Wei Chen, Xuejiao Zhao · 2024
This article discusses the key technical challenges of accurate perception, real-time response and new threat identification in the field of network security situation awareness, and studies a network security situation awareness method based on reinforcement learning. Network security situation awareness is facing a surge in data volume and the continuous evolution of new threats, and existing methods have shortcomings in these aspects. This article introduces in detail the technical solutions including data collection, feature engineering, reinforcement learning model design and security policy optimization, aiming to improve the ability to identify and respond to complex network threats. The research results show that the proposed reinforcement learning model achieves 95.2 % accuracy and 94.6% recall in accurate perception, an average response time of 0.23 seconds and a recovery time of 0.35 seconds in real-time response capability, and an 85% tracing success rate and a 5% mis-tracing rate in attack tracing capability, which are better than traditional methods. The conclusion summarizes the application potential of reinforcement learning algorithms in network security situation awareness, points out the limitations of the research and future research directions, and provides new ideas and methods for network security research.