CyGym: A Simulation-Based Game-Theoretic Analysis Framework for Cybersecurity
Michael Lanier, Yevgeniy Vorobeychik

TL;DR
CyGym is a comprehensive simulation framework that models cyber defense scenarios using game theory, incorporating realistic network features and exploits, to analyze advanced persistent threats like Volt Typhoon.
Contribution
The paper introduces CyGym, a novel simulation environment integrated with game-theoretic modeling for cybersecurity, including a new approach to modeling zero-day exploits.
Findings
Game-theoretic strategies improve understanding of network resilience.
Simulation effectively models sophisticated APTs like Volt Typhoon.
Framework aids in identifying optimal defense strategies.
Abstract
We introduce a novel cybersecurity encounter simulator between a network defender and an attacker designed to facilitate game-theoretic modeling and analysis while maintaining many significant features of real cyber defense. Our simulator, built within the OpenAI Gym framework, incorporates realistic network topologies, vulnerabilities, exploits (including-zero-days), and defensive mechanisms. Additionally, we provide a formal simulation-based game-theoretic model of cyberdefense using this simulator, which features a novel approach to modeling zero-days exploits, and a PSRO-style approach for approximately computing equilibria in this game. We use our simulator and associated game-theoretic framework to analyze the Volt Typhoon advanced persistent threat (APT). Volt Typhoon represents a sophisticated cyber attack strategy employed by state-sponsored actors, characterized by stealthy,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
