ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Journal Article E-NASim: A reinforcement-learning-based cyberattack simulation framework with pre-/post-state modeling based on MITRE ATT&CK
Cited 0 time in scopus Download 28 time Share share facebook twitter linkedin kakaostory
Authors
Ki Jong Koo, Daesung Moon, Byung Chul Kim, Jae Yong Lee
Citation
ETRI Journal, Early Access
ISSN
1225-6463
Publisher
한국전자통신연구원
Language
English
Type
Journal Article
DOI
https://dx.doi.org/10.4218/etrij.2025-0365
Abstract
The increasing prevalence of advanced persistent threats and automated cyberattacks highlights the need for proactive cybersecurity strategies. Reinforcement-learning-based autonomous penetration testing has shown promise; however, many existing simulation environments rely on abstract, probability-driven attack models, resulting in limited reproducibility and gaps relative to real-world conditions. This paper presents E-NASim as a reinforcement-learning-based cyberattack simulation framework that explicitly models attack feasibility and system evolution using pre-/post-attack state (PPS) transitions derived from MITRE ATT&CK subtechniques. In E-NASim, attack execution conditions and state transitions are deterministically governed by PPS definitions, whereas reinforcement learning is used to learn effective multistage attack sequencing under fixed constraints. Experimental results demonstrate that E-NASim enables agents to learn coherent and executable multistage attack strategies in complex network environments, providing a practical foundation for automated penetration testing and security evaluation.
Keyword
automated penetration testing, cyberattack simulation, Markov decision process (MDP), MITRE ATT&CK, pre-/post-state modeling, reinforcement learning
KSP Keywords
Attack feasibility, Attack strategy, Automated penetration testing, Complex network(CN), Learning-based, Markov Decision process, Multi-Stage attacks, Real-world, Security Evaluation, Simulation framework, State Modeling
This work is distributed under the term of Korea Open Government License (KOGL)
(Type 4: : Type 1 + Commercial Use Prohibition+Change Prohibition)
Type 4: