Two Can Play That Game: An Adversarial Evaluation of a Cyber-alert Inspection System
Ankit Shah, Arunesh Sinha, Rajesh Ganesan, Sushil Jajodia, Hasan Cam

TL;DR
This paper evaluates a reinforcement learning-based cyber-alert inspection system by developing adversarial attack strategies, revealing its robustness, and proposing game-theoretic enhancements to improve defense against sophisticated attackers.
Contribution
It introduces an adversarial evaluation framework for RL-based cyber-defense, extends the model to a game-theoretic setting, and demonstrates how to enhance defender robustness using a double oracle approach.
Findings
Defender policy is robust to the best response attacker.
Game-theoretic defender policies can be robust against any adversarial policy.
The double oracle approach improves defender robustness against discovered attacker policies.
Abstract
Cyber-security is an important societal concern. Cyber-attacks have increased in numbers as well as in the extent of damage caused in every attack. Large organizations operate a Cyber Security Operation Center (CSOC), which form the first line of cyber-defense. The inspection of cyber-alerts is a critical part of CSOC operations. A recent work, in collaboration with Army Research Lab, USA proposed a reinforcement learning (RL) based approach to prevent the cyber-alert queue length from growing large and overwhelming the defender. Given the potential deployment of this approach to CSOCs run by US defense agencies, we perform a red team (adversarial) evaluation of this approach. Further, with the recent attacks on learning systems, it is even more important to test the limits of this RL approach. Towards that end, we learn an adversarial alert generation policy that is a best response to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdversarial Robustness in Machine Learning · Advanced Malware Detection Techniques · Smart Grid Security and Resilience
