Researchers at KTH Royal Institute of Technology built a replica of a segmented industrial network, repeatedly attacked it, and used the captured traffic to train a defense agent that decides when to intervene. The study shows that packet-count-based belief tracking can help the agent infer intrusion progress and reset affected hosts or processes, while also highlighting limits in generalization and operational safety. #KTHRoyalInstituteofTechnology #CVE-2017-7494
Keypoints
- KTH researchers emulated a segmented industrial network and attacked it for 14 days.
- The defense agent used six packet-count signals to estimate intrusion progress.
- The agent could reset hosts, tank processes, or all supervisory and control systems.
- The best agent used belief tracking and nearly matched a full-visibility baseline.
- The test network included weak credentials and exposure to CVE-2017-7494.
Read More: https://www.helpnetsecurity.com/2026/09/14/ot-intrusion-response-agent/