Learning Intrusion Response Strategies for OT Systems
Researchers model OT intrusion response as a POMDP and train PPO-based automated response strategies effective against MITRE attacks in an emulated OT system.
The paper formalizes automated intrusion response for OT systems as a partially observable Markov decision process, with partial observability modeled from traffic measurements. Learning-based solution methods built on PPO are developed and evaluated on an emulated OT system. The resulting response strategies proved effective against several types of MITRE attacks for the studied use case.
- OT intrusion response modeled as POMDP with traffic-based partial observability
- Response policies trained with PPO and evaluated on an emulated OT system
- Strategies effective against several MITRE attack types in the studied use case
Full article111 words · extracted from arxiv.org · click to collapse
Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response strategies is highly important. In this paper, we present a formal model of an OT intrusion response use case using the POMDP framework. It includes a realistic model of partial observability that is based on traffic measurements. This approach allows us to develop tractable, learning-based solution methods for automated intrusion response, which are based on PPO. We evaluate the obtained response strategies on an emulated OT system and find that they are effective against several types of MITRE attacks for the studied use case.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.10298