Mission-Aware Cyber Incident Response Generation Using Reinforcement Learning
Aws Naser Jaber, Monica Endregard, Federico Mancini, Gudmund Grov · 2025
Cybersecurity in military missions is paramount for safeguarding critical assets and ensuring mission success. As cyber threats become increasingly sophisticated, the need for adaptive and optimal defense strategies is essential. This paper introduces a Reinforcement Learning based Markov Decision Process approach designed to model and mitigate cyber attacks within military operations. By leveraging simulations of the the company's critical infrastructure topologyin the Cyber Security Learning Environment, we show that this approach can provide a robust platform for evaluating and optimizing defensive responses against dynamic threat scenarios. The main novelty of this approach being the inclusion of mission-centric risk assessments in the reward function used to train the defence agent, The underlying idea is to offer a strategic tool to anticipate, detect, and neutralize cyber adversaries effectively. By simulating realistic attack vectors and adaptive defense mechanisms, this research provides insights and recommendations that can enhance the cybersecurity posture of military alliances, although not yet integrated with actual defense systems. Specifically, the framework can help in real-time threat detection, response optimization, and resilience against sophisticated cyber threats, thereby supporting overarching goals of ensuring collective security and operational integrity.