Pith. sign in

REVIEW 2 cited by

Network Defense is Not a Game

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2104.10262 v1 pith:AKLJCCG6 submitted 2021-04-20 cs.CR cs.AIcs.GT

classification cs.CRcs.AIcs.GT
keywords networkdefenseautonomousttpsdefinelearningmitretasks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Research seeks to apply Artificial Intelligence (AI) to scale and extend the capabilities of human operators to defend networks. A fundamental problem that hinders the generalization of successful AI approaches -- i.e., beating humans at playing games -- is that network defense cannot be defined as a single game with a fixed set of rules. Our position is that network defense is better characterized as a collection of games with uncertain and possibly drifting rules. Hence, we propose to define network defense tasks as distributions of network environments, to: (i) enable research to apply modern AI techniques, such as unsupervised curriculum learning and reinforcement learning for network defense; and, (ii) facilitate the design of well-defined challenges that can be used to compare approaches for autonomous cyberdefense. To demonstrate that an approach for autonomous network defense is practical it is important to be able to reason about the boundaries of its applicability. Hence, we need to be able to define network defense tasks that capture sets of adversarial tactics, techniques, and procedures (TTPs); quality of service (QoS) requirements; and TTPs available to defenders. Furthermore, the abstractions to define these tasks must be extensible; must be backed by well-defined semantics that allow us to reason about distributions of environments; and should enable the generation of data and experiences from which an agent can learn. Our approach named Network Environment Design for Autonomous Cyberdefense inspired the architecture of FARLAND, a Framework for Advanced Reinforcement Learning for Autonomous Network Defense, which we use at MITRE to develop RL network defenders that perform blue actions from the MITRE Shield matrix against attackers with TTPs that drift from MITRE ATT&CK TTPs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Training RL Agents for Multi-Objective Network Defense Tasks

    cs.LG 2025-05 conditional novelty 6.0 of 10

    Diverse, dynamically ordered training tasks make network-defense RL agents generalize to unseen attacks better than single-task training.

  2. A Framework for Adversarial Analysis of Decision Support Systems Prior to Deployment

    cs.LG 2025-05 conditional novelty 4.0 of 10

    A framework for pre-deployment adversarial analysis of DRL decision-support systems, demonstrated in the CyberStrike game, ranks attack targets and shows partial attack transferability across training algorithms.

Pith tools