Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Optimal Defender Strategies for CAGE-2 using Causal Modeling and Tree Search
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Nätverk och systemteknik.ORCID-id: 0000-0003-1773-8354
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Nätverk och systemteknik.ORCID-id: 0000-0001-6039-8493
(engelsk)Manuskript (preprint) (Annet vitenskapelig)
Abstract [en]

The CAGE-2 challenge is considered a standard benchmark to compare methods for automated security response. Current state-of-the-art methods evaluated against this benchmark are based on model-free (offline) reinforcement learning, which does not provide provably optimal defender strategies. We address this limitation and present a formal (causal) model of CAGE-2 together with a method that produces a provably optimal defender strategy, which we call Causal-Partially Observable Monte-Carlo Planning (C-POMCP). It has two key properties. First, it incorporates the causal structure of the target system, i.e., the causal relationships among the system variables. This structure allows for a significant reduction of the search space of defender strategies. Second, it is an online method that uses tree search to update the defender strategy at each time step. Evaluations against the CAGE-2 benchmark show that C-POMCP achieves state-of-the-art performance with respect to effectiveness and is two orders of magnitude more efficient in computing time than the closest competitor method.

Emneord [en]
Decision theory, Causality, Tree Search, Cybersecurity
HSV kategori
Forskningsprogram
Elektro- och systemteknik; Datalogi
Identifikatorer
URN: urn:nbn:se:kth:diva-354764OAI: oai:DiVA.org:kth-354764DiVA, id: diva2:1905273
Merknad

QC 20241014

Tilgjengelig fra: 2024-10-12 Laget: 2024-10-12 Sist oppdatert: 2024-10-14bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Person

Hammar, KimStadler, Rolf

Søk i DiVA

Av forfatter/redaktør
Hammar, KimStadler, Rolf
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric

urn-nbn
Totalt: 89 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf