3-Way game model for privacy-preserving cybersecurity information exchange framework

3-Way game model for privacy-preserving cybersecurity information exchange framework
复制标题

隐私保护网络安全信息交换框架的三向博弈模型

DOI:
10.1109/milcom.2017.8170842
复制
发表时间:
2017
期刊:
MILCOM 2017 - 2017 IEEE Military Communications Conference (MILCOM)
影响因子:
--
通讯作者:
S. Sengupta
S. Sengupta
中科院分区:
--
文献类型:
--
作者:
Iman Vakilinia;Deepak K. Tosh;S. Sengupta

文献摘要

被引文献

相似文献

随着网络攻击事件的不断增加,组织需要对网络安全环境拥有主动的知识,以有效地保护他们的资源。要实现这一点,组织必须培养与他人共享其威胁信息的文化,以便有效地评估相关风险。然而,共享网络安全信息对这些组织来说代价高昂,因为这些信息传递的是敏感和私人数据。因此,决定共享信息是一项具有挑战性的任务,需要解决共享优势和隐私暴露之间的权衡。另一方面,网络安全信息交换(Cybex)管理对于通过设定正确的参与费和分享激励措施来稳定系统至关重要。在这项工作中,我们使用动态博弈对共享系统中的组织、Cybex和攻击者之间的交互进行建模。通过为每个参与者设计合适的支付模型,我们通过在共享模型中加入组织的隐私部分来分析实体的最佳策略。利用最优响应分析,仿真结果验证了所提框架的有效性。
With the growing number of cyberattack incidents, organizations are required to have proactive knowledge on the cybersecurity landscape for efficiently defending their resources. To achieve this, organizations must develop the culture of sharing their threat information with others for effectively assessing the associated risks. However, sharing cybersecurity information is costly for the organizations due to the fact that the information conveys sensitive and private data. Hence, making the decision for sharing information is a challenging task and requires to resolve the trade-off between sharing advantages and privacy exposure. On the other hand, cybersecurity information exchange (CYBEX) management is crucial in stabilizing the system through setting the correct values for participation fees and sharing incentives. In this work, we model the interaction of organizations, CYBEX, and attackers involved in a sharing system using dynamic game. With devising appropriate payoff models for each player, we analyze the best strategies of the entities by incorporating the organizations' privacy component in the sharing model. Using the best response analysis, the simulation results demonstrate the efficiency of our proposed framework.