2026· IEEE Transactions on Network and Service Management· Vol 23, pp. 7553-7575· 1 citation· 84 references
TL;DR
T tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles is presented.
Abstract
Open-source testbeds for intrusion detection and mitigation enable benchmarking the efficacy of machine-learning-based cyber-defensive systems under increasingly realistic, heterogeneous network scenarios. In this context, the open-world nature of network intrusion detection requires defences to use continual learning strategies to adapt pattern-matching to new attack classes. The cost of periodically fine-tuning pre-trained detectors is not only computational but also encompasses the broader Cyber Threat Intelligence (CTI) life-cycle, which involves collecting, analyzing, and processing raw data into actionable insights. For ML-driven defensive systems, such actionable CTI ultimately takes the form of curated, labelled traffic traces of novel attacks. However, the concurrent optimisation of these intelligence-gathering costs and defence effectiveness has received little attention from the research community. In this respect, this work presents tiger, an open-source Threat Intelligence Game Environment for Reinforcement learning-based agents to be trained and evaluated toward the optimisation of the costs-benefit trade-off associated with realistic ML-driven cyber-defence life-cycles. tiger uses realistic network simulation software to model an active-learning game in which an agent learns to timely purchase CTI—abstracted in our environment as labelled samples of Zero-day attacks— to retrain its intrusion detection machinery on new attack patterns, while considering a constrained resource availability scenario.
The findings demonstrate that integrating reinforcement learning with threat intelligence can provide a highly adaptive and proactive cyber defense mechanism suitable for modern network environments.
Abimbola B. Owolabi, F. Osang· Direct Research Journal of E...· 0 citations
Active cyber-defence employs anticipatory techniques to proactively mitigate cyber threats. Among such techniques, the most relevant one consists in the continuous updating of cyber-threat intelligence. In this respect, there is a trade-off between the cost of intelligence assets and the benefits derived from their exp...
Jesús F. Cevallos-Moreno, A. Rizzardi, S. Sicari et al.· Journal of Reliable Intellig...· 0 citations
The Hierarchical Adversarially-Driven Escalation System (hades) is introduced, a framework that addresses this vulnerability to adversarial examples through three coordinated mechanisms and maintains near-perfect detection accuracy under both normal and adversarial conditions.
A. Derhab, Adlen Kerboua, N. Seddari et al.· Computer Modeling in Enginee...· 0 citations
XAI-CTI is presented, a novel Explainable Artificial Intelligence (XAI)-driven Cyber Threat Intelligence (CTI) framework designed to enable proactive and adaptive cyberattack detection that achieves state-of-the-art detection accuracy and reduces analyst investigation time.
R. Yadav· Journal of Intelligent Decis...· 0 citations
The model uses an aggregated representation of system components as an aggregation of an attack graph built with the Meta Attack Language together with a stochastic initialization of initial conditions, which reduces the dimensionality of the state space and ensures the computational tractability of the analysis.