Multi-Stage Attack Graph Security Games: Heuristic Strategies, with Empirical Game-Theoretic Analysis

Multi-Stage Attack Graph Security Games: Heuristic Strategies, with Empirical Game-Theoretic Analysis
复制标题

多阶段攻击图安全博弈:启发式策略,以及实证博弈论分析

DOI:
10.1145/3140549.3140562
复制
发表时间:
2017
期刊:
Proceedings of the 2017 Workshop on Moving Target Defense
影响因子:
--
通讯作者:
Satinder Singh
Satinder Singh
中科院分区:
--
文献类型:
--
作者:
T. Nguyen;Mason Wright;Michael P. Wellman;Satinder Singh

文献摘要

被引文献

相似文献

我们研究了针对贝叶斯攻击图建模的场景分配有限的安全对策以保护网络数据免受网络攻击的问题。我们考虑网络管理员和网络犯罪分子之间的多阶段交互,将其制定为安全游戏。该公式能够代表具有显着动态和不确定性以及非常大的策略空间的安全环境。对于游戏模型,我们为双方玩家提出参数化启发式策略。我们的启发式方法利用攻击图的拓扑结构,并采用不同的采样方法来克服确定玩家行为时的计算复杂性。考虑到游戏的复杂性,我们采用基于模拟的方法,并对列举的一组启发式策略进行实证游戏分析。最后,我们基于各种游戏设置进行实验,以证明我们的启发式方法在获得对安全环境的不确定性具有鲁棒性的有效防御策略方面的优势。
We study the problem of allocating limited security countermeasures to protect network data from cyber-attacks, for scenarios modeled by Bayesian attack graphs. We consider multi-stage interactions between a network administrator and cybercriminals, formulated as a security game. This formulation is capable of representing security environments with significant dynamics and uncertainty, and very large strategy spaces. For the game model, we propose parameterized heuristic strategies for both players. Our heuristics exploit the topological structure of the attack graphs and employ different sampling methodologies to overcome the computational complexity in determining players' actions. Given the complexity of the game, we employ a simulation-based methodology, and perform empirical game analysis over an enumerated set of these heuristic strategies. Finally, we conduct experiments based on a variety of game settings to demonstrate the advantages of our heuristics in obtaining effective defense strategies which are robust to the uncertainty of the security environment.