awesome-rl-for-cybersecurity
by Limmen
A curated list of resources dedicated to reinforcement learning applied to cyber security.
AI summary
Cybersecurity RL library
A curated list of resources dedicated to reinforcement learning applied to cyber security
- stars
- 782
- forks
- 116
- watching
- 31
- awesome lists
- 2
- entries
- 691
What's in the list
691 links in 104 sections, with live GitHub stats.activeno commit in 2y
Links
↑ Environments / Cyborg++
↑ Environments / Cyborg++ / CybORG++: An Enhanced Gym for the Development of Autonomous Cyber Agents
↑ Environments / Cyborg++
↑ Environments / Cybershield
↑ Environments / Cybershield / CYBERSHIELD: A Competitive Simulation Environment for Training AI in Cybersecurity
↑ Environments / Cybershield
↑ Environments / Cyberwheel
↑ Environments / Cyberwheel / Cyberwheel: A Reinforcement Learning Simulation Environment
↑ Environments / Cyberwheel
↑ Environments / Pentesting Training Framework for Reinforcement Learning Agents (PenGym)
↑ Environments / Pentesting Training Framework for Reinforcement Learning Agents (PenGym) / PenGym: Pentesting Training Framework for Reinforcement Learning Agents
↑ Environments / Pentesting Training Framework for Reinforcement Learning Agents (PenGym)
↑ Environments / The ARCD Primary-level AI Training Environment (PrimAITE)
↑ Environments / CSLE: The Cyber Security Learning Environment
↑ Environments / CSLE: The Cyber Security Learning Environment / CSLE: The Cyber Security Learning Environment
- (2022) Intrusion Prevention Through Optimal Stopping
Paper: Thesis:
↑ Environments / CSLE: The Cyber Security Learning Environment
- (2022) Intrusion Prevention Through Optimal Stopping
Paper: Thesis:
↑ Environments / AutoPentest-DRL
↑ Environments / AutoPentest-DRL / AutoPentest-DRL: Automated Penetration Testing Using Deep Reinforcement Learning
- CROND
AutoPentest-DRL is an automated penetration testing framework based on Deep Reinforcement Learning (DRL) techniques. AutoPentest-DRL can determine the most appropriate attack path for a given logical network, and can also be used to execute a penetration testing attack on a real network via tools such as Nmap and Metasploit. This framework is intended for educational purposes, so that users can study the penetration testing attack mechanisms. AutoPentest-DRL is being developed by the Cyber Range Organization and Design ( ) NEC-endowed chair at the Japan Advanced Institute of Science and Technology ( ) in Ishikawa,Japan
↑ Environments / AutoPentest-DRL
- CROND
AutoPentest-DRL is an automated penetration testing framework based on Deep Reinforcement Learning (DRL) techniques. AutoPentest-DRL can determine the most appropriate attack path for a given logical network, and can also be used to execute a penetration testing attack on a real network via tools such as Nmap and Metasploit. This framework is intended for educational purposes, so that users can study the penetration testing attack mechanisms. AutoPentest-DRL is being developed by the Cyber Range Organization and Design ( ) NEC-endowed chair at the Japan Advanced Institute of Science and Technology ( ) in Ishikawa,Japan
↑ Environments / NASimEmu
↑ Environments / NASimEmu / NASimEmu
- (2023) NASimEmu: Network Attack Simulator & Emulator for Training Agents Generalizing to Novel Scenarios
NASimEmu is a framework for training deep RL agents in offensive penetration-testing scenarios. It includes both a simulator and an emulator so that a simulation-trained agent can be seamlessly deployed in emulation. Additionally, it includes a random generator that can create scenario instances varying in network configuration and size while fixing certain features, such as exploits and privilege escalations. Furthermore, agents can be trained and tested in multiple scenarios simultaneously. Paper: Framework: Implemented agents:
↑ Environments / NASimEmu
- (2023) NASimEmu: Network Attack Simulator & Emulator for Training Agents Generalizing to Novel Scenarios
NASimEmu is a framework for training deep RL agents in offensive penetration-testing scenarios. It includes both a simulator and an emulator so that a simulation-trained agent can be seamlessly deployed in emulation. Additionally, it includes a random generator that can create scenario instances varying in network configuration and size while fixing certain features, such as exploits and privilege escalations. Furthermore, agents can be trained and tested in multiple scenarios simultaneously. Paper: Framework: Implemented agents:
↑ Environments / gym-idsgame
↑ Environments / gym-idsgame / gym-idsgame
- (2020) Finding Effective Security Strategies through Reinforcement Learning and Self-Play
An Abstract Cyber Security Simulation and Markov Game for OpenAI Gym. Paper:
↑ Environments / gym-idsgame
- (2020) Finding Effective Security Strategies through Reinforcement Learning and Self-Play
An Abstract Cyber Security Simulation and Markov Game for OpenAI Gym. Paper:
↑ Environments / CyberBattleSim (Microsoft)
↑ Environments / CyberBattleSim (Microsoft) / CyberBattleSim
- (2021) Gamifying machine learning for stronger security and AI models
CyberBattleSim is an experimentation research platform to investigate the interaction of automated agents operating in a simulated abstract enterprise network environment. The simulation provides a high-level abstraction of computer networks and cyber security concepts. Its Python-based Open AI Gym interface allows for the training of automated agents using reinforcement learning algorithms. Blogpost:
↑ Environments / CyberBattleSim (Microsoft)
- (2021) Gamifying machine learning for stronger security and AI models
CyberBattleSim is an experimentation research platform to investigate the interaction of automated agents operating in a simulated abstract enterprise network environment. The simulation provides a high-level abstraction of computer networks and cyber security concepts. Its Python-based Open AI Gym interface allows for the training of automated agents using reinforcement learning algorithms. Blogpost:
↑ Environments / gym-malware
↑ Environments / gym-malware / gym-malware
- (2018) Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
Malware Env for OpenAI Gym Paper:
↑ Environments / gym-malware
- (2018) Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
Malware Env for OpenAI Gym Paper:
↑ Environments / malware-rl
↑ Environments / malware-rl / malware-rl
- (2018) Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
Extended and Updated `gym_malware` which supports recent LIEF versionS and an enhanced collection of models (EMBER, MalConv and SOREL-20M) Paper:
↑ Environments / malware-rl
- (2018) Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
Extended and Updated `gym_malware` which supports recent LIEF versionS and an enhanced collection of models (EMBER, MalConv and SOREL-20M) Paper:
↑ Environments / gym-flipit
↑ Environments / gym-flipit / gym-flipit
- (2019) QFlip: An Adaptive Reinforcement Learning Strategy for the FlipIt Security Game
Gym environment for FLIPIT: The Game of "Stealthy Takeover" invented by Marten van Dijk, Ari Juels, Alina Oprea, and Ronald L. Rivest. Paper:
↑ Environments / gym-flipit
- (2019) QFlip: An Adaptive Reinforcement Learning Strategy for the FlipIt Security Game
Gym environment for FLIPIT: The Game of "Stealthy Takeover" invented by Marten van Dijk, Ari Juels, Alina Oprea, and Ronald L. Rivest. Paper:
↑ Environments / gym-threat-defense
↑ Environments / gym-threat-defense / gym-threat-defense
- (2019) Optimal Defense Policies for Partially Observable Spreading Processes on Bayesian Attack Graphs
Gym environment for the environment described in the paper:
↑ Environments / gym-threat-defense
- (2019) Optimal Defense Policies for Partially Observable Spreading Processes on Bayesian Attack Graphs
Gym environment for the environment described in the paper:
↑ Environments / gym-nasim
↑ Environments / gym-nasim / gym-nasim
↑ Environments / gym-nasim
↑ Environments / gym-optimal-intrusion-response
↑ Environments / gym-optimal-intrusion-response / gym-optimal-intrusion-response
- (2021) Learning Intrusion Prevention Policies through Optimal Stopping
An OpenAI Gym interface to a MDP/Markov Game model for optimal intrusion response of a realistic infrastructure simulated using system traces. Paper:
↑ Environments / gym-optimal-intrusion-response
- (2021) Learning Intrusion Prevention Policies through Optimal Stopping
An OpenAI Gym interface to a MDP/Markov Game model for optimal intrusion response of a realistic infrastructure simulated using system traces. Paper:
↑ Environments / sql_env
↑ Environments / sql_env / sql_env
↑ Environments / sql_env
↑ Environments / cage-challenge
↑ Environments / cage-challenge / cage-challenge-2
- (2023) On Autonomous Agents in a Cyber Defence Environment
The second Cyber Autonomous Gym for Experimentation (CAGE) challenge environment announced at the AAAI-22 Workshop on Artificial Intelligence for Cyber Security Workshop (AICS). Paper:
↑ Environments / cage-challenge
- (2023) On Autonomous Agents in a Cyber Defence Environment
The second Cyber Autonomous Gym for Experimentation (CAGE) challenge environment announced at the AAAI-22 Workshop on Artificial Intelligence for Cyber Security Workshop (AICS). Paper:
↑ Environments / ATMoS
↑ Environments / ATMoS / ATMoS
↑ Environments / ATMoS
↑ Environments / MAB-Malware
↑ Environments / MAB-Malware / MAB-malware
↑ Environments / MAB-Malware
↑ Environments / ASAP
↑ Environments / ASAP / Autonomous Security Analysis and Penetration Testing framework (ASAP)
↑ Environments / ASAP
↑ Environments / Yawning Titan
↑ Environments / Cyborg
↑ Environments / SecureAI
↑ Environments / SecureAI / SecureAI
- (2021) An Intrusion Response Approach for Elastic Applications Based on Reinforcement Learning
SecureAI: Deep Reinforcement Learning for Self-Protection in Non-Stationary Cloud Architectures Paper:
↑ Environments / SecureAI
- (2021) An Intrusion Response Approach for Elastic Applications Based on Reinforcement Learning
SecureAI: Deep Reinforcement Learning for Self-Protection in Non-Stationary Cloud Architectures Paper:
↑ Environments / CYST
↑ Environments / CYST / CYST
- (2020) Session-level Adversary Intent-Driven Cyberattack Simulator
CYST is a multi-agent discrete-event simulation framework tailored for cybersecurity domain. Its goal is to enable high-throughput and realistic simulation of cybersecurity interactions in arbitrary infrastructures. Paper: Code:
↑ Environments / CYST
- (2020) Session-level Adversary Intent-Driven Cyberattack Simulator
CYST is a multi-agent discrete-event simulation framework tailored for cybersecurity domain. Its goal is to enable high-throughput and realistic simulation of cybersecurity interactions in arbitrary infrastructures. Paper: Code:
↑ Environments / CLAP
↑ Environments / CLAP / CLAP: Curiosity-Driven Reinforcment Learning Automatic Penetration Testing Agent
- (2022) Behaviour-Diverse Automatic Penetration Testing: A Curiosity-Driven Multi-Objective Deep Reinforcement Learning Approach
CLAP is a reinforcement learning PPO agent performs Penetration Testing in simulated computer network environment (we use Network Attack Simulator (NASim)). The agent is trained to scan for vulnerabilities in the network and exploit them to gain access to various network resources. Paper: Code:
↑ Environments / CLAP
- (2022) Behaviour-Diverse Automatic Penetration Testing: A Curiosity-Driven Multi-Objective Deep Reinforcement Learning Approach
CLAP is a reinforcement learning PPO agent performs Penetration Testing in simulated computer network environment (we use Network Attack Simulator (NASim)). The agent is trained to scan for vulnerabilities in the network and exploit them to gain access to various network resources. Paper: Code:
↑ Environments / CyGIL
↑ Environments / CyGIL / CyGIL: A Cyber Gym for Training Autonomous Agents over Emulated Network Systems
- (2021) CyGIL: A Cyber Gym for Training Autonomous Agents over Emulated Network Systems
CyGIL is an experimental testbed of an emulated RL training environment for network cyber operations. CyGIL uses a stateless environment architecture and incorporates the MITRE ATT&CK framework to establish a high fidelity training environment, while presenting a sufficiently abstracted interface to enable RL training. Its comprehensive action space and flexible game design allow the agent training to focus on particular advanced persistent threat (APT) profiles, and to incorporate a broad range of potential threats and vulnerabilities. By striking a balance between fidelity and simplicity, it aims to leverage state of the art RL algorithms for application to real-world cyber defence. Paper:
↑ Environments / CyGIL
- (2021) CyGIL: A Cyber Gym for Training Autonomous Agents over Emulated Network Systems
CyGIL is an experimental testbed of an emulated RL training environment for network cyber operations. CyGIL uses a stateless environment architecture and incorporates the MITRE ATT&CK framework to establish a high fidelity training environment, while presenting a sufficiently abstracted interface to enable RL training. Its comprehensive action space and flexible game design allow the agent training to focus on particular advanced persistent threat (APT) profiles, and to incorporate a broad range of potential threats and vulnerabilities. By striking a balance between fidelity and simplicity, it aims to leverage state of the art RL algorithms for application to real-world cyber defence. Paper:
↑ Environments / BRAWL
↑ Environments / DETERLAB
↑ Environments / DETERLAB / DeterLab: Cyber-Defense Technology Experimental Research Laboratory
- (2010) The DETER project: Advancing the science of cyber security experimentation and test
Since 2004, the DETER Cybersecurity Testbed Project has worked to create the necessary infrastructure - facilities, tools, and processes-to provide a national resource for experimentation in cyber security. The next generation of DETER envisions several conceptual advances in testbed design and experimental research methodology, targeting improved experimental validity, enhanced usability, and increased size, complexity, and diversity of experiments. Paper:
↑ Environments / DETERLAB
- (2010) The DETER project: Advancing the science of cyber security experimentation and test
Since 2004, the DETER Cybersecurity Testbed Project has worked to create the necessary infrastructure - facilities, tools, and processes-to provide a national resource for experimentation in cyber security. The next generation of DETER envisions several conceptual advances in testbed design and experimental research methodology, targeting improved experimental validity, enhanced usability, and increased size, complexity, and diversity of experiments. Paper:
↑ Environments / EmuLab
↑ Environments / EmuLab / Mininet creates a realistic virtual network, running real kernel, switch and application code, on a single machine (VM, cloud or native), in seconds, with a single command.
↑ Environments / EmuLab
↑ Environments / Vine
↑ Environments / Vine / VINE: A Cyber Emulation Environment for MTD Experimentation
↑ Environments / Vine
↑ Environments / CRATE
↑ Environments / CRATE / CRATE Exercise Control – A cyber defense exercise management and support tool
↑ Environments / CRATE
↑ Environments / GALAXY
↑ Environments / GALAXY / Galaxy: A Network Emulation Framework for Cybersecurity tool
↑ Environments / GALAXY
↑ Papers / Surveys
↑ Papers / Demonstration papers
↑ Papers / Position papers
↑ Papers / Regular Papers
↑ Papers / PhD Theses
↑ Papers / Master Theses
↑ Papers / Bachelor Theses
↑ Papers / Posters
↑ Books
↑ Blogposts
↑ Talks
↑ Miscellaneous
Nothing in this list matches your filter.
Featured in 2 awesome lists
Each link jumps to the spot where the list mentions awesome-rl-for-cybersecurity.