Deceptive elements, including honeypots and decoys, were incorporated into the Microsoft CyberBattleSim experimentation and research platform. The defensive capabilities of the deceptive elements were tested using reinforcement learning based attackers in the provided capture the flag environment. The attacker's progress was found to be dependent on the number and location of the deceptive elements. This is a promising step toward reproducibly testing attack and defense algorithms in a simulated enterprise network with deceptive defensive elements.
翻译:欺骗性元素,包括蜂蜜罐和诱饵,已纳入微软CyberBattleSim实验和研究平台; 欺骗性元素的防御能力通过在提供方的强化学习攻击者捕捉旗帜环境进行测试; 攻击者的进展取决于欺骗性元素的数量和位置; 这是朝向在装有欺骗性防御元素的模拟企业网络中重新测试攻击和防御算法迈出的有希望的步骤。