Back to Search Start Over

Autonomous Penetration Testing Based on Improved Deep Q-Network.

Authors :
Zhou, Shicheng
Liu, Jingju
Hou, Dongdong
Zhong, Xiaofeng
Zhang, Yue
Source :
Applied Sciences (2076-3417); Oct2021, Vol. 11 Issue 19, p8823, 15p
Publication Year :
2021

Abstract

Penetration testing is an effective way to test and evaluate cybersecurity by simulating a cyberattack. However, the traditional methods deeply rely on domain expert knowledge, which requires prohibitive labor and time costs. Autonomous penetration testing is a more efficient and intelligent way to solve this problem. In this paper, we model penetration testing as a Markov decision process problem and use reinforcement learning technology for autonomous penetration testing in large scale networks. We propose an improved deep Q-network (DQN) named NDSPI-DQN to address the sparse reward problem and large action space problem in large-scale scenarios. First, we reasonably integrate five extensions to DQN, including noisy nets, soft Q-learning, dueling architectures, prioritized experience replay, and intrinsic curiosity model to improve the exploration efficiency. Second, we decouple the action and split the estimators of the neural network to calculate two elements of action separately, so as to decrease the action space. Finally, the performance of algorithms is investigated in a range of scenarios. The experiment results demonstrate that our methods have better convergence and scaling performance. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
20763417
Volume :
11
Issue :
19
Database :
Complementary Index
Journal :
Applied Sciences (2076-3417)
Publication Type :
Academic Journal
Accession number :
152970344
Full Text :
https://doi.org/10.3390/app11198823