Turn it off and on again, but for critical infrastructure

Turn it off and on again, but for critical infrastructure
Researchers at KTH Royal Institute of Technology built a replica of a segmented industrial network, repeatedly attacked it, and used the captured traffic to train a defense agent that decides when to intervene. The study shows that packet-count-based belief tracking can help the agent infer intrusion progress and reset affected hosts or processes, while also highlighting limits in generalization and operational safety. #KTHRoyalInstituteofTechnology #CVE-2017-7494

Keypoints

  • KTH researchers emulated a segmented industrial network and attacked it for 14 days.
  • The defense agent used six packet-count signals to estimate intrusion progress.
  • The agent could reset hosts, tank processes, or all supervisory and control systems.
  • The best agent used belief tracking and nearly matched a full-visibility baseline.
  • The test network included weak credentials and exposure to CVE-2017-7494.

Read More: https://www.helpnetsecurity.com/2026/09/14/ot-intrusion-response-agent/