ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Journal Article E-NASim: A reinforcement-learning-based cyberattack simulation framework with pre-/post-state modeling based on MITRE ATT&CK
Cited - time in scopus Download 9 time Share share facebook twitter linkedin kakaostory
Authors
Ki Jong Koo, Daesung Moon, Byung Chul Kim, Jae Yong Lee
Citation
ETRI Journal, Early Access
ISSN
1225-6463
Publisher
한국전자통신연구원
Language
English
Type
Journal Article
DOI
https://dx.doi.org/10.4218/etrij.2025-0365
Abstract
The increasing prevalence of advanced persistent threats and automated cyberattacks highlights the need for proactive cybersecurity strategies. Reinforcement-learning-based autonomous penetration testing has shown promise; however, many existing simulation environments rely on abstract, probability-driven attack models, resulting in limited reproducibility and gaps relative to real-world conditions. This paper presents E-NASim as a reinforcement-learning-based cyberattack simulation framework that explicitly models attack feasibility and system evolution using pre-/post-attack state (PPS) transitions derived from MITRE ATT&CK subtechniques. In E-NASim, attack execution conditions and state transitions are deterministically governed by PPS definitions, whereas reinforcement learning is used to learn effective multistage attack sequencing under fixed constraints. Experimental results demonstrate that E-NASim enables agents to learn coherent and executable multistage attack strategies in complex network environments, providing a practical foundation for automated penetration testing and security evaluation.
Keyword
automated penetration testing, cyberattack simulation, Markov decision process (MDP), MITRE ATT&CK, pre-/post-state modeling, reinforcement learning
KSP Keywords
Attack feasibility, Attack strategy, Automated penetration testing, Complex network(CN), Learning-based, Markov Decision process, Multi-Stage attacks, Real-world, Security Evaluation, Simulation framework, State Modeling
This work is distributed under the term of Korea Open Government License (KOGL)
(Type 4: : Type 1 + Commercial Use Prohibition+Change Prohibition)
Type 4: