Predictive Cyber Defense Remediation against Advanced Persistent Threat in Cyber-Physical Systems

Predictive Cyber Defense Remediation against Advanced Persistent Threat in Cyber-Physical Systems
复制标题

DOI:
10.1109/icccn54977.2022.9868886
复制
发表时间:
2022-07
期刊:
2022 International Conference on Computer Communications and Networks (ICCCN)
影响因子:
--
通讯作者:
Kamrul Hasan;Sachin Shetty;Tariqul Islam;Imtiaz Ahmed
Kamrul Hasan;Sachin Shetty;Tariqul Islam;Imtiaz Ahmed
中科院分区:
其他
文献类型:
--
作者:
Kamrul Hasan;Sachin Shetty;Tariqul Islam;Imtiaz Ahmed

文献摘要

相似文献

高级持续威胁(APT)极大地改变了网络安全的格局。APT是通过秘密的、持续的、复杂的和资金充足的攻击过程来执行的,目的是为了获得长期恶意收益,从而挫败大多数当前的防御机制。需要一种在长时间跨度内持续打击APT的防御策略,该策略不完全/不完整地反映攻击者的行为。针对这一需求,我们提出了随机进化博弈模型来模拟动态对手。我们在Logit量子反应动力学(LQ-RD)模型中加入了玩家的理性参数c来量化现实世界中玩家的认知差异。通过计算平衡国防成本和收益的稳定进化均衡,提出了一种最优决策方案。在能量传递系统(EDS)上进行的实例研究表明,该方法可以帮助防御者预测可能的攻击行为,随着时间的推移选择相关的最优网络防御补救措施,从而获得最大的防御收益。
Advanced Persistent Threat (APT) has dramatically changed the landscape of cybersecurity. APT is carried out by stealthy, continuous, sophisticated, and well-funded attack processes for long-term malicious gain thwarting most current defense mechanisms. There is a need for a defense strategy that continuously combats APT over a long time-span in imper-fect/incomplete information on attacker's actions. We propose the stochastic evolutionary game model to simulate the dynamic adversary to address this need in this work. We add the player's rationality parameter c to the Logit Quantal Response Dynamics (LQ RD) model to quantify the cognitive differences of real-world players. We propose an optimal decision-making plan by calculating the stable evolutionary equilibrium that balances a trade-off between defense cost and benefit. Cases studies conducted on Energy Delivery Systems (EDS) indicate that the proposed method can help the defender predict possible attack action, select the related optimal cyber defense remediation over time, and gain the maximum defense payoff.