REVIEW 2 cited by
Evaluation of Reinforcement Learning for Autonomous Penetration Testing using A3C, Q-learning and DQN
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Penetration testing is the process of searching for security weaknesses by simulating an attack. It is usually performed by experienced professionals, where scanning and attack tools are applied. By automating the execution of such tools, the need for human interaction and decision-making could be reduced. In this work, a Network Attack Simulator (NASim) was used as an environment to train reinforcement learning agents to solve three predefined security scenarios. These scenarios cover techniques of exploitation, post-exploitation and wiretapping. A large hyperparameter grid search was performed to find the best hyperparameter combinations. The algorithms Q-learning, DQN and A3C were used, whereby A3C was able to solve all scenarios and achieve generalization. In addition, A3C could solve these scenarios with fewer actions than the baseline automated penetration testing. Although the training was performed on rather small scenarios and with small state and action spaces for the agents, the results show that a penetration test can successfully be performed by the RL agent.
Forward citations
Cited by 2 Pith papers
-
VulnGym: Evaluating Vulnerability Management Strategies against Advanced Persistent Threats
A shared-network RL simulator shows importance-based patching cuts APT goal success far more than CVSS or centrality policies under limited defender budget.
-
Attack Effect Model based Malicious Behavior Detection
FEAD derives security monitoring items from attack reports with an LLM, decomposes them across existing collectors, and applies locality-aware graph analysis, reporting an 8.23% higher F1-score than ThreaTrace with 5....
Discussion (0). Continue with ORCID to comment.