Game Theoretic Model of Strategic Honeypot Selection in Computer Networks

Game Theoretic Model of Strategic Honeypot Selection in Computer Networks
复制标题

计算机网络中策略蜜罐选择的博弈论模型

DOI:
10.1007/978-3-642-34266-0_12
复制
发表时间:
2012
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
M. Pechoucek
M. Pechoucek
中科院分区:
--
文献类型:
--
作者:
Radek Píbil;V. Lisý;Christopher Kiekintveld;B. Bosanský;M. Pechoucek

文献摘要

被引文献

相似文献

蜜罐是一种用于网络安全的诱饵计算机系统,用于浪费攻击者的时间和资源,并分析他们的行为。虽然有关于如何设计蜜罐系统的重要研究,但很少有人知道如何在网络防御中战略性地使用蜜罐。正式的欺骗游戏的基础上,我们开发了两个博弈论模型,提供洞察如何有价值的蜜罐看起来像最大化的概率,一个理性的攻击者将攻击蜜罐。第一个模型捕获静态情况,第二个模型允许攻击者在发起攻击之前不完全地探测网络上的某些系统,以确定哪些系统可能是真实的系统(而不是蜜罐)。我们正式分析的游戏中的最优策略的属性,并提供线性规划的计算。最后,我们提出了一组游戏实例的最佳解决方案,并将其质量与几个基线进行比较。
A honeypot is a decoy computer system used in network security to waste the time and resources of attackers and to analyze their behaviors. While there has been significant research on how to design honeypot systems, less is known about how to use honeypots strategically in network defense. Based on formal deception games, we develop two game-theoretic models that provide insight into how valuable should honeypots look like to maximize the probability that a rational attacker will attack a honeypot. The first model captures a static situation and the second allows attackers to imperfectly probe some of the systems on the network to determine which ones are likely to be real systems (and not honeypots) before launching an attack. We formally analyze the properties of the optimal strategies in the games and provide linear programs for their computation. Finally, we present the optimal solutions for a set of instances of the games and evaluate their quality in comparison to several baselines.