An Adaptive Reinforcement Learning-Based Approach for Effective Cyber Denial and Deception Strategies Finding
摘要
Existing literature primarily focuses on static or semi-dynamic approaches for the placement of deception resources that do not fully exploit the network security state. To address these limitations, we introduce an adaptive reinforcement learning approach to enhance the selection of denial & deception strategies, employing honeypatches as a key deception method. Our approach entails modeling the network using an attack graph, capturing the attacker’s strategy, and the defender’s action space. Tailored to each attacker, our approach uses Q-learning to determine the optimal type and placement of denial & deception actions. We constructed an attack graph of real attack scenarios on a target network and used it to run our Q-learning simulation, providing a realistic environment for evaluation.