Leveraging Reinforcement Learning in Red Teaming for Advanced Ransomware Attack Simulations
Cheng Wang, Christopher Redino, Ryan Clark, Abdul Rahman, Sal, Aguinaga, Sathvik Murli, Dhruv Nandakumar, Roland Rao, Lanxiao Huang, Daniel, Radke, Edward Bowen

TL;DR
This paper introduces a reinforcement learning-based method for simulating ransomware attacks in red teaming exercises, enabling efficient discovery of attack strategies and network vulnerabilities to improve cybersecurity defenses.
Contribution
It presents a novel RL approach for automated ransomware attack simulation, enhancing traditional red teaming with faster, more effective attack strategy discovery.
Findings
RL agent successfully identified attack paths on a 152-host network
The approach effectively evaded honeyfiles, demonstrating realistic attack capabilities
Experimental results confirmed the method's ability to find high-value targets
Abstract
Ransomware presents a significant and increasing threat to individuals and organizations by encrypting their systems and not releasing them until a large fee has been extracted. To bolster preparedness against potential attacks, organizations commonly conduct red teaming exercises, which involve simulated attacks to assess existing security measures. This paper proposes a novel approach utilizing reinforcement learning (RL) to simulate ransomware attacks. By training an RL agent in a simulated environment mirroring real-world networks, effective attack strategies can be learned quickly, significantly streamlining traditional, manual penetration testing processes. The attack pathways revealed by the RL agent can provide valuable insights to the defense team, helping them identify network weak points and develop more resilient defensive measures. Experimental results on a 152-host example…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Information and Cyber Security · Network Security and Intrusion Detection
