{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T01:39:49Z","timestamp":1742953189819,"version":"3.40.3"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031541285"},{"type":"electronic","value":"9783031541292"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_42","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"719-737","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Simulating Deception for\u00a0Web Applications Using Reinforcement Learning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0090-2322","authenticated-orcid":false,"given":"Andrei","family":"Kvasov","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Merve","family":"Sahin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5030-8271","authenticated-orcid":false,"given":"Cedric","family":"Hebert","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0364-6328","authenticated-orcid":false,"given":"Anderson Santana","family":"De Oliveira","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"42_CR1","doi-asserted-by":"publisher","unstructured":"Betarte, G., Pardo, A., Mart\u00ednez, R.: Web application attacks detection using machine learning techniques. In: 2018 17th IEEE International Conference on Machine Learning and Applications (ICMLA), pp. 1065\u20131072 (Dec 2018). https:\/\/doi.org\/10.1109\/ICMLA.2018.00174","DOI":"10.1109\/ICMLA.2018.00174"},{"key":"42_CR2","unstructured":"Brockman, G., et al.: Openai gym. CoRR (2016). http:\/\/arxiv.org\/abs\/1606.01540"},{"key":"42_CR3","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1016\/j.comnet.2019.05.013","volume":"159","author":"G Caminero Fern\u00e1ndez","year":"2019","unstructured":"Caminero Fern\u00e1ndez, G., Lopez-Martin, M., Carro, B.: Adversarial environment reinforcement learning algorithm for intrusion detection. Comput. Netw. 159, 96\u2013109 (2019). https:\/\/doi.org\/10.1016\/j.comnet.2019.05.013","journal-title":"Comput. Netw."},{"key":"42_CR4","doi-asserted-by":"publisher","unstructured":"Charpentier, A., Boulahia Cuppens, N., Cuppens, F., Yaich, R.: Deep Reinforcement Learning-Based Defense Strategy Selection. In: Proceedings of the 17th International Conference on Availability, Reliability and Security, pp. 1\u201311. ACM, Vienna Austria (Aug 2022). https:\/\/doi.org\/10.1145\/3538969.3543789","DOI":"10.1145\/3538969.3543789"},{"key":"42_CR5","doi-asserted-by":"publisher","unstructured":"El-Kosairy, A., Azer, M.A.: A New web deception system framework. In: 2018 1st International Conference on Computer Applications & Information Security (ICCAIS), pp. 1\u201310 (Apr 2018). https:\/\/doi.org\/10.1109\/CAIS.2018.8442027","DOI":"10.1109\/CAIS.2018.8442027"},{"key":"42_CR6","doi-asserted-by":"publisher","unstructured":"Elderman, R., Pater, J.J., L., S. Thie, A., M. Drugan, M., M. Wiering, M.: Adversarial Reinforcement Learning in a Cyber Security Simulation. In: Proceedings of the 9th International Conference on Agents and Artificial Intelligence, pp. 559\u2013566. SCITEPRESS - Science and Technology Publications, Porto, Portugal (2017). https:\/\/doi.org\/10.5220\/0006197105590566, http:\/\/www.scitepress.org\/DigitalLibrary\/Link.aspx?doi=10.5220\/0006197105590566","DOI":"10.5220\/0006197105590566"},{"key":"42_CR7","doi-asserted-by":"publisher","unstructured":"Erd\u0151di, L., Sommervoll, A.A., Zennaro, F.M.: Simulating SQL injection vulnerability exploitation using Q-learning reinforcement learning agents. Journal of Information Security and Applications 61(C) (Sep 2021). https:\/\/doi.org\/10.1016\/j.jisa.2021.102903","DOI":"10.1016\/j.jisa.2021.102903"},{"key":"42_CR8","doi-asserted-by":"publisher","unstructured":"Even-Dar, E., Mansour, Y.: Learning Rates for Q-Learning. In: Goos, G., Hartmanis, J., Van Leeuwen, J., Helmbold, D., Williamson, B. (eds.) Computational Learning Theory, vol. 2111, pp. 589\u2013604. Springer, Berlin Heidelberg, Berlin, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-44581-1_39, http:\/\/link.springer.com\/10.1007\/3-540-44581-1_39, series Title: Lecture Notes in Computer Science","DOI":"10.1007\/3-540-44581-1_39"},{"key":"42_CR9","doi-asserted-by":"publisher","unstructured":"Gan, Y., et al.: An Open-Source Benchmark Suite for Microservices and Their Hardware-Software Implications for Cloud & Edge Systems. In: Proceedings of the Twenty-Fourth International Conference on Architectural Support for Programming Languages and Operating Systems, pp. 3\u201318. ACM, Providence RI USA (Apr 2019). https:\/\/doi.org\/10.1145\/3297858.3304013, https:\/\/dl.acm.org\/doi\/10.1145\/3297858.3304013","DOI":"10.1145\/3297858.3304013"},{"key":"42_CR10","doi-asserted-by":"publisher","unstructured":"Han, X., Kheir, N., Balzarotti, D.: Evaluation of Deception-Based Web Attacks Detection. In: Proceedings of the 2017 Workshop on Moving Target Defense, pp. 65\u201373. ACM, Dallas Texas USA (Oct 2017). https:\/\/doi.org\/10.1145\/3140549.3140555, https:\/\/dl.acm.org\/doi\/10.1145\/3140549.3140555","DOI":"10.1145\/3140549.3140555"},{"key":"42_CR11","doi-asserted-by":"publisher","unstructured":"Han, X., Kheir, N., Balzarotti, D.: Deception techniques in computer security: a research perspective. ACM Comput. Surv. 51(4), 80 (2018). https:\/\/doi.org\/10.1145\/3214305","DOI":"10.1145\/3214305"},{"key":"42_CR12","unstructured":"van Hasselt, H., Guez, A., Silver, D.: Deep reinforcement learning with double q-learning. CoRR (2015). http:\/\/arxiv.org\/abs\/1509.06461"},{"key":"42_CR13","unstructured":"Kunz, T., Fisher, C., La Novara-Gsell, J., Nguyen, C., Li, L.: A Multiagent CyberBattleSim for RL Cyber Operation Agents (Apr 2023). 10.48550\/arXiv. 2304.11052, http:\/\/arxiv.org\/abs\/2304.11052, arXiv:2304.11052 [cs]"},{"key":"42_CR14","doi-asserted-by":"publisher","unstructured":"Li, H., Guo, Y., Huo, S., Hu, H., Sun, P.: Defensive deception framework against reconnaissance attacks in the cloud with deep reinforcement learning. Sci. China Inf. Sci. 65(7), 170305 (Jul 2022). https:\/\/doi.org\/10.1007\/s11432-021-3462-4, https:\/\/link.springer.com\/10.1007\/s11432-021-3462-4","DOI":"10.1007\/s11432-021-3462-4"},{"key":"42_CR15","doi-asserted-by":"publisher","unstructured":"Li, L., Fayad, R., Taylor, A.: CyGIL: A Cyber Gym for Training Autonomous Agents over Emulated Network Systems (Sep 2021). https:\/\/doi.org\/10.48550\/arXiv.2109.03331","DOI":"10.48550\/arXiv.2109.03331"},{"key":"42_CR16","doi-asserted-by":"publisher","unstructured":"Li, Q., et al.: A hierarchical deep reinforcement learning model with expert prior knowledge for intelligent penetration testing. Computers & Security 132, 103358 (Sep 2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103358, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404823002687","DOI":"10.1016\/j.cose.2023.103358"},{"key":"42_CR17","unstructured":"Mnih, V., Kavukcuoglu, K., Silver, D., Graves, A., Antonoglou, I., Wierstra, D., et al.: Playing Atari with Deep Reinforcement Learning. NIPS Deep Learning Workshop 2013 (Dec 2013), http:\/\/arxiv.org\/abs\/1312.5602,arXiv: 1312.5602"},{"key":"42_CR18","doi-asserted-by":"crossref","unstructured":"Reti, D., Elzer, K., Schotten, H.D.: SCANTRAP: Protecting Content Management Systems from Vulnerability Scanners with Cyber Deception and Obfuscation (Jan 2023). http:\/\/arxiv.org\/abs\/2301.10502arXiv:2301.10502 [cs]","DOI":"10.5220\/0011667400003405"},{"key":"42_CR19","doi-asserted-by":"publisher","unstructured":"Sahin, M., Hebert, C., De Oliveira, A.S.: Lessons Learned from SunDEW: A Self Defense Environment for Web Applications. In: Proceedings 2020 Workshop on Measurements, Attacks, and Defenses for the Web. Internet Society, San Diego, CA (2020). https:\/\/doi.org\/10.14722\/madweb.2020.23005, https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/2020\/02\/23005.pdf","DOI":"10.14722\/madweb.2020.23005"},{"key":"42_CR20","doi-asserted-by":"publisher","unstructured":"Sahin, M., H\u00e9bert, C., Cabrera Lozoya, R.: An Approach to Generate Realistic HTTP Parameters for Application Layer Deception. In: Ateniese, G., Venturi, D. (eds.) Applied Cryptography and Network Security. vol. 13269, pp. 337\u2013355. Springer International Publishing, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-09234-3-17, https:\/\/link.springer.com\/10.1007\/978-3-031-09234-3_17, series Title: Lecture Notes in Computer Science","DOI":"10.1007\/978-3-031-09234-3-17"},{"key":"42_CR21","doi-asserted-by":"publisher","unstructured":"Shashkov, A., Hemberg, E., Tulla, M., O\u2019Reilly, U.M.: Adversarial agent-learning for cybersecurity: a comparison of algorithms. The Knowledge Engineering Review 38, e3 (Jan 2023). https:\/\/doi.org\/10.1017\/S0269888923000012, publisher: Cambridge University Press","DOI":"10.1017\/S0269888923000012"},{"key":"42_CR22","doi-asserted-by":"publisher","unstructured":"Standen, M., Lucas, M., Bowman, D., Richer, T.J., Kim, J., Marriott, D.: CybORG: A Gym for the Development of Autonomous Cyber Agents (Aug 2021). https:\/\/doi.org\/10.48550\/arXiv.2108.09118","DOI":"10.48550\/arXiv.2108.09118"},{"key":"42_CR23","unstructured":"van der Stock, A., Glas, B., Smithline, N., Gigler, T.: Owasp Web Security Testing Guide v4.2. https:\/\/github.com\/OWASP\/wstg\/releases\/download\/v4.2\/wstg-v4.2.pdf (2014)"},{"key":"42_CR24","unstructured":"van der Stock, A., Glas, B., Smithline, N., Gigler, T.: Owasp Appsensor project guide v2. https:\/\/owasp.org\/www-pdf-archive\/Owasp-appsensor-guide-v2.pdf (2015)"},{"key":"42_CR25","unstructured":"van der Stock, A., Glas, B., Smithline, N., Gigler, T.: OWASP Top 10 project (2021). https:\/\/owasp.org\/Top10\/"},{"key":"42_CR26","unstructured":"Sutton, R.S., Barto, A.G.: Reinforcement Learning: An Introduction. MIT Press (2018)"},{"key":"42_CR27","unstructured":"Team., M.D.R.: Cyberbattlesim. https:\/\/github.com\/microsoft\/cyberbattlesim (2021)"},{"key":"42_CR28","unstructured":"Walter, E., Ferguson-Walter, K., Ridley, A.: Incorporating Deception into CyberBattleSim for Autonomous Defense. IJCAI-21 1st International Workshop on Adaptive Cyber Defense (Aug 2021), http:\/\/arxiv.org\/abs\/2108.13980arXiv:2108.13980 [cs]"},{"key":"42_CR29","doi-asserted-by":"publisher","unstructured":"Wang, S., Pei, Q., Wang, J., Tang, G., Zhang, Y., Liu, X.: An Intelligent Deployment Policy for Deception Resources Based on Reinforcement Learning. IEEE Access 8, 35792\u201335804 (2020). https:\/\/doi.org\/10.1109\/ACCESS.2020.2974786, conference Name: IEEE Access","DOI":"10.1109\/ACCESS.2020.2974786"},{"key":"42_CR30","doi-asserted-by":"publisher","first-page":"12","DOI":"10.4156\/jdcta.vol6.issue10.2","volume":"6","author":"W Xin","year":"2012","unstructured":"Xin, W., Gengyu, W., Yixian, Y.: Web application vulnerability detection based on reinforcement learning. Int. J. Digital Content Technol. Appl. 6, 12\u201320 (2012). https:\/\/doi.org\/10.4156\/jdcta.vol6.issue10.2","journal-title":"Int. J. Digital Content Technol. Appl."},{"key":"42_CR31","doi-asserted-by":"publisher","unstructured":"Yao, Q., Wang, Y., Xiong, X., Wang, P., Li, Y.: Adversarial decision-making for moving target defense: a multi-agent markov game and reinforcement learning approach. Entropy 25(4), 605 (Apr 2023). https:\/\/doi.org\/10.3390\/e25040605, https:\/\/www.mdpi.com\/1099-4300\/25\/4\/605, number: 4 Publisher: Multidisciplinary Digital Publishing Institute","DOI":"10.3390\/e25040605"},{"key":"42_CR32","doi-asserted-by":"publisher","unstructured":"Zhang, L., Thing, V.L.L.: Three Decades of Deception Techniques in Active Cyber Defense - Retrospect and Outlook. Computers & Security 106, 102288 (Jul 2021). https:\/\/doi.org\/10.1016\/j.cose.2021.102288, http:\/\/arxiv.org\/abs\/2104.03594,arXiv:2104.03594 [cs]","DOI":"10.1016\/j.cose.2021.102288"},{"key":"42_CR33","unstructured":"Zhu, M., Anwar, A.H., Wan, Z., Cho, J.H., Kamhoua, C., Singh, M.P.: Game-theoretic and machine learning-based approaches for defensive deception: a survey (May 2021). http:\/\/arxiv.org\/abs\/2101.10121arXiv:2101.10121 [cs]"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_42","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:08:39Z","timestamp":1710194919000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_42","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}