Title
Policy-Based Profiles for Network Intrusion Response Systems
Abstract
Attacks on computer networks are increasingly common, often leading to severe economical and reputational damage to organisations. Subsequently, Intrusion Response Systems are recently an active area of research which seek to automatically respond to alerts generated by Intrusion Detection Systems. Current Intrusion Response Systems often seek to find optimal responses based on a general and balanced policy such as the cost and benefit to the network overall. However, organisations are encouraged to prepare Incident Response Policies, which outline prioritisations and performance measures for their response. These policies are highly individualised to the organisation, often influenced by the type of data present within the network. Building on this it is possible for several subsections of a network to have differing Incident Response Policies, for example in a Cyber-Physical network, a Control Area Network may have a much stricter policy in order to preserve a physical process. In this work we utilise a Deep Reinforcement Learning approach to allow the customisation of Reward Functions which in turn facilitates the creation of Response Profiles to align with differing Incident Response Policies. Evaluation of the Profiles is performed in a Cyber-Physical System testbed consisting of Web and Business local area networks configured using Mininet and integrated with a Tennessee Eastman Process plant running in Matlab. Experimentation demonstrates the ability of a Reinforcement Learning Agent to converge on near-optimal response to multi-stage attack scenarios in accordance with their Response Profile.
Year
DOI
Venue
2022
10.1109/CSR54599.2022.9850304
2022 IEEE International Conference on Cyber Security and Resilience (CSR)
Keywords
DocType
ISBN
intrusion,response,systems,multi-profile,response policy
Conference
978-1-6654-9953-8
Citations 
PageRank 
References 
0
0.34
7
Authors
3
Name
Order
Citations
PageRank
Kieran Hughes100.68
Kieran McLaughlin200.34
Sakir Sezer3101084.22