Outline

Ingegneria Sismica

Ingegneria Sismica

Automated Penetration Test Path Optimization and Decision Making Based on Artificial Intelligence Models

Author(s): Wei Li1, Zixuan Zhao1, Youchen Shi1, Yinquan Wang1, Zeyang Zhao1, Hanlin Tu1
1Digital Intelligence Technology Company, PetroChina Xinjiang Oilfield Company, Karamay, Xinjiang, 834000, China
Li, Wei. et al “Automated Penetration Test Path Optimization and Decision Making Based on Artificial Intelligence Models.” Ingegneria Sismica Volume 43 Issue 2: 1-22, doi:10.65102/is2026574.

Abstract

Automating penetration testing has been a challenge as it requires extensive expertise and experience from security professionals and usually requires a tedious manual testing process. In this study, with the help of an artificial intelligence model, a Markov decision process is constructed for describing the process of defining penetration tests. The objective is established to maximize the cumulative reward value and acquire an optimal strategy to guarantee the maximization of the expected return. Subsequently, the state and action reward functions are defined to accomplish penetration test modeling. A DQN algorithm founded on deep reinforcement learning is put forward to obtain the optimal strategy by learning the precise Q – function during environmental interactions. Moreover, a Dueling DQN algorithm known as empirical campaigning is proposed to more effectively handle the intricate state and action space.For the purpose of verifying the penetration success ratio of the arithmetic method this research employed, an aggressive person carries out an attack toward the object under the experimental environment. The attack measurement index of the penetration attack which this study carries out is comparatively high, reaching as high as 27.348. This effect exceeds the attack index values of the other two wide-used calculation methods.Comparing the optimal environmental reward values of the algorithms in different scenarios, the Dueling_DDQN algorithm is able to reach convergence in fewer training times, and reaches the desired reward value after 50 training times. It shows that the algorithm in this paper is able to achieve optimization and decision making for automated penetration test paths.

Keywords
Artificial Intelligence Model; Markov Decision Making; Dueling_DDQN; Q-Function; Automated Penetration

Related Articles

Qianwen Xiong1, Yuhong Chen1
1Guangzhou University of Chinese Medicine, School of Pharmaceutical Medicine, Guangzhou,Guangdong,China,510006
Zhihao Jiang1,2, Limi Chen1,2, Jing Yang1
1Hainan Vocational University of Science and Technology, Haikou 571126, China
2Institute for Mathematical Research, Universiti Putra Malaysia, Serdang 43400, Malaysia
Limi Chen1,2, Zhihao Jiang1,2, Jing Yang1
1Hainan Vocational University of Science and Technology, Haikou 571126, China
2Institute for Mathematical Research, Universiti Putra Malaysia, Serdang 43400, Malaysia
Hui Yuan1, Minjie Chai2, Siqing Xu1, Jinsong Li1, Jinwan Zheng1
1Electric Power Research Institute, State Grid Shanxi Electric Power Co., Ltd., Taiyuan, 030001, Shanxi, China
2Jincheng Power Supply Branch, State Grid Shanxi Electric Power Co., Ltd., Jincheng, 048000, Shanxi, China
Yanhan Zhu1,2
1China Academy of Cultural Heritage, Chaoyang District, 100029, Beijing, China
2Beijing University of Civil Engineering and Architecture, Xicheng District, 100044, Beijing, China