The model uses an aggregated representation of system components as an aggregation of an attack graph built with the Meta Attack Language together with a stochastic initialization of initial conditions, which reduces the dimensionality of the state space and ensures the computational tractability of the analysis.
A risk-sensitive method for forming a web application security testing policy based on entropic-risk Q-learning in a two-agent Markov attack–defense model is proposed. The study addresses the need to detect short critical compromise trajectories under partial observability, noisy estimation of defensive attributes, and...
Andrii Prytula, L. Kupershtein· Computer Systems and Informa...· 0 citations
The MAL Simulator, a cyber operation simulator based on the Meta Attack Language (MAL), found that the trained attacker policy could reach the designated targets more efficiently than the compared search methods, and that the trained defender agent induced lower costs than a naive heuristic agent under noisy alert cond...
Jakob Nyberg, Sandor Berglund, Andrei Buhaiu et al.· 0 citations
As cyber threats to power grid infrastructures escalate, the urgency of understanding how to protect cyber-physical systems (CPS) has never been greater. These systems, which integrate physical processes with digital control, are increasingly susceptible to sophisticated cyberattacks that can lead to widespread disrupt...
A. Raptis, S. Gritzalis, A. Yannacopoulos· International Journal of Inf...· 0 citations
The traditional network attack-defense confrontation only considers the two parties of attack and defense, ignoring the intervention of users themselves and regulators. Aiming at the problem of defense strategy selection in network attack-defense confrontation, combined with the evolutionary game model, a four-party ga...
T tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles is presented.
Jesús F. Cevallos-Moreno, A. Rizzardi, S. Sicari et al.· IEEE Transactions on Network...· 1 citation
A five-stage Bayesian Stackelberg security game with five stage-specific actions per player is formulated, which examines whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known.