Pith. sign in

REVIEW 1 cited by

Using Cyber Terrain in Reinforcement Learning for Penetration Testing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2108.07124 v2 pith:FRBS4XAT submitted 2021-08-16 cs.LG cs.CRcs.NI

classification cs.LGcs.CRcs.NI
keywords attackgraphsterraincyberanalysislearningmethodsnotions
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Reinforcement learning (RL) has been applied to attack graphs for penetration testing, however, trained agents do not reflect reality because the attack graphs lack operational nuances typically captured within the intelligence preparation of the battlefield (IPB) that include notions of (cyber) terrain. In particular, current practice constructs attack graphs exclusively using the Common Vulnerability Scoring System (CVSS) and its components. We present methods for constructing attack graphs using notions from IPB on cyber terrain analysis of obstacles, avenues of approach, key terrain, observation and fields of fire, and cover and concealment. We demonstrate our methods on an example where firewalls are treated as obstacles and represented in (1) the reward space and (2) the state dynamics. We show that terrain analysis can be used to bring realism to attack graphs for RL.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Reinforcement Learning for Automated Cybersecurity Penetration Testing

    cs.CR 2025-06 reject novelty 6.0 of 10

    An RL agent using permutation-symmetric neural networks automates web pentesting on simulated sites and is claimed to find all reachable vulnerabilities on DVWA and DockerLabs.

Pith tools