A Probabilistic Logic of Cyber Deception

A Probabilistic Logic of Cyber Deception
复制标题

网络欺骗的概率逻辑

DOI:
10.1109/tifs.2017.2710945
复制
发表时间:
2017
影响因子:
6.8
通讯作者:
V. S. Subrahmanian
V. S. Subrahmanian
中科院分区:
计算机科学1区
文献类型:
--
作者:
S. Jajodia;Noseong Park;Fabio Pierazzi;Andrea Pugliese;Edoardo Serra;Gerardo I. Simari;V. S. Subrahmanian

文献摘要

被引文献

相似文献

恶意攻击者经常在网络中扫描节点,以确定他们在本文中遍历网络时可能会利用的漏洞。所有扫描结果都是正确的,然后他将走错路,如果他认为一些扫描结果是伪造的,他将不得不探索时间和精力,以便我们提出一个概率。欺骗的逻辑表明,各种计算是NP-HARD。我们开发了一种幼稚的算法和一种快速的启发式算法,供防守者使用并在实验上显示后者在我们详细介绍的运行时间中表现良好实验评估这些算法的性能并进一步表明,通过运行快速PLD离线并存储结果,我们可以非常有效地回答运行时扫描请求。
Malicious attackers often scan nodes in a network in order to identify vulnerabilities that they may exploit as they traverse the network. In this paper, we propose that the system generates a mix of true and false answers in response to scan requests. If the attacker believes that all scan results are true, then he will be on a wrong path. If he believes some scan results are faked, he would have to expend time and effort in order to separate fact from fiction. We propose a probabilistic logic of deception and show that various computations are NP-hard. We model the attacker’s state and show the effects of faked scan results. We then show how the defender can generate fake scan results in different states that minimize the damage the attacker can produce. We develop a Naive-PLD algorithm and a Fast-PLD heuristic algorithm for the defender to use and show experimentally that the latter performs well in a fraction of the run time of the former. We ran detailed experiments to assess the performance of these algorithms and further show that by running Fast-PLD off-line and storing the results, we can very efficiently answer run-time scan requests.