ZeroHour
arXiv cs.CRpublished ()ingested Jakob Nyberg

A Cyber Range Evaluation of Autonomous Network Incident Response Agents

infoResearchimportance 38
AI summary · glm-5.3

Cyber range evaluation shows reinforcement learning incident response agents defend emulated networks more efficiently than heuristic policies, depending heavily on adversary behavior.

The paper evaluates agents for automated network intrusion response in a cyber range designed for human operator training, featuring variable topology, red-team emulation, and simulated users. Alerts are generated by a SIEM platform and mapped to a data modeling language used by the agents, with reinforcement learning policies optimized to minimize combined defense and availability costs using a cyber attack simulator. Reinforcement learning agents defended the system more efficiently than heuristic policies, with performance highly dependent on the adversary policy and simulated user behavior.

  • RL agents outperform heuristic policies defending hosts in an emulated network range
  • Policies trained in a simulator minimize combined defense and availability cost
  • Performance depends heavily on adversary policy and simulated user behavior
  • SIEM alerts mapped to a data modeling language consumed by the agents
Full article153 words · extracted from arxiv.org · click to collapse

We test the performance of agents for automated network intrusion response in a cyber range intended for human operator training. The range implements an emulated networking environment with a variable network topology, red-team emulation and simulated user agents. The goal of the defensive agents is to prevent hosts in the network from being accessed by the red-team agent, while minimizing the availability costs induced from defensive measures. Alerts are generated using a SIEM platform and mapped to a data modeling language used by the agents. We test a combination of heuristic agents and policies learned using reinforcement learning. The learned policies are optimized to minimize the combined cost using a cyber attack simulator modeling the network. We found that the reinforcement learning agents were overall more efficient at defending the system than the heuristic policy, and that the performance depends highly on the policy of the adversary in combination with the simulated users.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.16541