Ransomware presents a significant and increasing threat to individuals and organizations by encrypting their systems and not releasing them until a large fee has been extracted. To bolster preparedness against potential attacks, organizations commonly conduct red teaming exercises, which involve simulated attacks to assess existing security measures. This paper proposes a novel approach utilizing reinforcement learning (RL) to simulate ransomware attacks. By training an RL agent in a simulated environment mirroring real-world networks, effective attack strategies can be learned quickly, significantly streamlining traditional, manual penetration testing processes. The attack pathways revealed by the RL agent can provide valuable insights to the defense team, helping them identify network weak points and develop more resilient defensive measures. Experimental results on a 152-host example network confirm the effectiveness of the proposed approach, demonstrating the RL agent's capability to discover and orchestrate attacks on high-value targets while evading honeyfiles (decoy files strategically placed to detect unauthorized access).
翻译:勒索软件通过加密系统并索要高额赎金才予以解密,对个人和组织构成日益严重的威胁。为增强对潜在攻击的应对能力,组织通常开展红队演练,即通过模拟攻击来评估现有安全措施。本文提出一种利用强化学习(RL)模拟勒索软件攻击的新方法。通过在模拟真实网络的环境中训练RL智能体,可以快速学习有效的攻击策略,从而显著简化传统的手动渗透测试流程。RL智能体揭示的攻击路径能为防御团队提供宝贵洞见,帮助其识别网络弱点并制定更具韧性的防御措施。在一个包含152台主机的示例网络上进行的实验结果验证了所提方法的有效性,证明了RL智能体能够发现并组织对高价值目标的攻击,同时规避蜜罐文件(为检测未授权访问而策略性放置的诱饵文件)。