Simulating Network Lateral Movements through the CyberBattleSim Web Platform

Modern cyber attacks demand immediate action plans based on an overwhelming amount of information and options. Microsoft has made available a highly parameterizable model of enterprise networks with the capability of simulating automated cyber-attacks. We provide an extension of this project by mean...

Full description

Bibliographic Details
Main Author: Esteban, Jonathan
Other Authors: Siegel, Michael
Format: Thesis
Published: Massachusetts Institute of Technology 2022
Online Access:https://hdl.handle.net/1721.1/143191
_version_ 1826216957108551680
author Esteban, Jonathan
author2 Siegel, Michael
author_facet Siegel, Michael
Esteban, Jonathan
author_sort Esteban, Jonathan
collection MIT
description Modern cyber attacks demand immediate action plans based on an overwhelming amount of information and options. Microsoft has made available a highly parameterizable model of enterprise networks with the capability of simulating automated cyber-attacks. We provide an extension of this project by means of a web platform. The platform allows a user to model an enterprise network topology, interact with the topology manually, and simulate an automated adversarial agent. Leveraging the CyberBattleSim toolkit, we enable the swift prototyping of different network configurations that can then be analyzed by a defensive security team member either manually or automatically through the automated agent. We demonstrate that the platform can simulate any network topology supported by CyberBattleSim as well as evaluate different Q-Learning strategies. This in turn can provide us with valuable insight regarding the progression of cyber attacks, aiding us at generating appropriate cyber-attack response plans.
first_indexed 2024-09-23T16:55:51Z
format Thesis
id mit-1721.1/143191
institution Massachusetts Institute of Technology
last_indexed 2024-09-23T16:55:51Z
publishDate 2022
publisher Massachusetts Institute of Technology
record_format dspace
spelling mit-1721.1/1431912022-06-16T03:01:39Z Simulating Network Lateral Movements through the CyberBattleSim Web Platform Esteban, Jonathan Siegel, Michael Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science Modern cyber attacks demand immediate action plans based on an overwhelming amount of information and options. Microsoft has made available a highly parameterizable model of enterprise networks with the capability of simulating automated cyber-attacks. We provide an extension of this project by means of a web platform. The platform allows a user to model an enterprise network topology, interact with the topology manually, and simulate an automated adversarial agent. Leveraging the CyberBattleSim toolkit, we enable the swift prototyping of different network configurations that can then be analyzed by a defensive security team member either manually or automatically through the automated agent. We demonstrate that the platform can simulate any network topology supported by CyberBattleSim as well as evaluate different Q-Learning strategies. This in turn can provide us with valuable insight regarding the progression of cyber attacks, aiding us at generating appropriate cyber-attack response plans. M.Eng. 2022-06-15T13:02:28Z 2022-06-15T13:02:28Z 2022-02 2022-02-22T18:31:54.831Z Thesis https://hdl.handle.net/1721.1/143191 In Copyright - Educational Use Permitted Copyright MIT http://rightsstatements.org/page/InC-EDU/1.0/ application/pdf Massachusetts Institute of Technology
spellingShingle Esteban, Jonathan
Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title_full Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title_fullStr Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title_full_unstemmed Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title_short Simulating Network Lateral Movements through the CyberBattleSim Web Platform
title_sort simulating network lateral movements through the cyberbattlesim web platform
url https://hdl.handle.net/1721.1/143191
work_keys_str_mv AT estebanjonathan simulatingnetworklateralmovementsthroughthecyberbattlesimwebplatform