Autonomous Discovery of Cyber Attack Paths With Complex Causal Relationships Among Optional Actions

Shudong Li, Ruichen Huang, Weihong Han, Xiaobo Wu, Shumei Li, Zhihong Tian · IEEE Transactions on Intelligent Transportation Systems · 2025

Reinforcement Learning (RL), particularly deep reinforcement learning (DRL) has shown significant potential in addressing optimal attack path discovery problems (OAPDPs) for cybersecurity. However, existing approaches often oversimplify the causal relationships among attack actions, limiting their applicability to complex systems. This study pioneers DRL-based solutions for OAPDPs in Intelligent Transportation Systems (ITS), specifically targeting scenarios where attack actions exhibit disjunctive, conjunctive, and hybrid causal relationships. We propose TTCRT, a novel attack pattern template that formalizes attack logic through vector-compatible representations of OAPDP-related attack components, while developing a refinement method for TTCRT-derived attack patterns and presenting a rigorous framework for formalizing OAPDPs as Markov Decision Processes (MDPs) based on refined attack patterns. Through extensive experiments, we demonstrate TTCRT’s capability to rigorously capture disjunctive, conjunctive, and hybrid causal relationships among attack actions, achieving semantic equivalence with Logical Attack Graphs (LAGs) while resolving their implementation bottlenecks in highly complex systems like ITS environments. The framework seamlessly integrates with established DRL algorithms to accurately identify optimal attack paths in an intelligent traffic management system. These findings establish TTCRT as a foundational framework for RL-driven OAPDP resolution in ITS and other sophisticated systems with complex attack dynamics.

Read the paper · More papers on PaperTik