Game-Theoretic Foundations for the Strategic Use of Honeypots in Network Security

Game-Theoretic Foundations for the Strategic Use of Honeypots in Network Security
复制标题

DOI:
10.1007/978-3-319-14039-1_5
复制
发表时间:
2015-01-01
期刊:
CYBER WARFARE: BUILDING THE SCIENTIFIC FOUNDATION
影响因子:
--
通讯作者:
Pibil, Radek
Pibil, Radek
中科院分区:
其他
文献类型:
--
作者:
Kiekintveld, Christopher;Lisy, Viliam;Pibil, Radek

文献摘要

被引文献

相似文献

安全数学和科学基础中的一个重要元素是对欺骗和信息操纵的战略使用进行建模。我们认为,博弈论为推理对抗性环境中的信息操纵(包括欺骗和随机化策略)提供了一个重要的理论框架。此外,博弈论在确定随机巡逻和资源分配的最佳策略方面具有实际用途。我们讨论了三个博弈论模型,这些模型捕获了蜜罐如何在网络安全中使用的各个方面。蜜罐是引入网络的虚假主机,用于收集有关攻击者的信息并分散他们对真实目标的注意力。它们的资源是有限的,因此如何部署它们以发挥最大效果是一个重要的战略问题,从根本上讲,欺骗攻击者选择虚假目标而不是真实目标进行攻击。我们描述了几种解决蜜罐部署策略的游戏模型,包括基本的蜜罐选择游戏、允许攻击者进行额外探测操作的游戏扩展,以及最后一个使用攻击图表示攻击者策略的版本。最后,我们讨论了网络安全背景下博弈论的优点和局限性。
An important element in the mathematical and scientific foundations for security is modeling the strategic use of deception and information manipulation. We argue that game theory provides an important theoretical framework for reasoning about information manipulation in adversarial settings, including deception and randomization strategies. In addition, game theory has practical uses in determining optimal strategies for randomized patrolling and resource allocation. We discuss three game-theoretic models that capture aspects of how honeypots can be used in network security. Honeypots are fake hosts introduced into a network to gather information about attackers and to distract them from real targets. They are a limited resource, so there are important strategic questions about how to deploy them to the greatest effect, which is fundamentally about deceiving attackers into choosing fake targets instead of real ones to attack. We describe several game models that address strategies for deploying honeypots, including a basic honeypot selection game, an extension of this game that allows additional probing actions by the attacker, and finally a version in which attacker strategies are represented using attack graphs. We conclude with a discussion of the strengths and limitations of game theory in the context of network security.