{"title":"An Experimental Platform for Autonomous Intelligent Cyber-Defense Agents: Towards a collaborative community approach (WIPP)","authors":"Benjamin A. Blakely","doi":"10.1109/RWS55399.2022.9984037","DOIUrl":null,"url":null,"abstract":"Cyber defenses are increasingly challenged to keep up with attackers who might be using automation or machine learning as part of their attack strategies. Autonomous defensive systems will become critical in the coming years to respond to this threat. We present an update on ongoing work to build an autonomous intelligent cyber-defense agent. An initial prototype was demonstrated to NATO ACT in the fall of 2021, and work continues to add additional capabilities to it. The agent in its current state is capable of simple, statically-configured responsive actions as well as storing several types of observations (network scans, IDS alerts, Netflow data) in a knowledge graph. We outline the background for this work, detail the demonstration scenario used last fall, progress since then, and a future roadmap and collaborative strategy for this project including a reinforcement learning approach to automated reasoning.","PeriodicalId":170769,"journal":{"name":"2022 Resilience Week (RWS)","volume":"64 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-09-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 Resilience Week (RWS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RWS55399.2022.9984037","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
Cyber defenses are increasingly challenged to keep up with attackers who might be using automation or machine learning as part of their attack strategies. Autonomous defensive systems will become critical in the coming years to respond to this threat. We present an update on ongoing work to build an autonomous intelligent cyber-defense agent. An initial prototype was demonstrated to NATO ACT in the fall of 2021, and work continues to add additional capabilities to it. The agent in its current state is capable of simple, statically-configured responsive actions as well as storing several types of observations (network scans, IDS alerts, Netflow data) in a knowledge graph. We outline the background for this work, detail the demonstration scenario used last fall, progress since then, and a future roadmap and collaborative strategy for this project including a reinforcement learning approach to automated reasoning.