RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks

RADAMS: Resilient and adaptive alert and attention management strategy against Informational Denial-of-Service (IDoS) attacks
复制标题

RADAMS:针对信息拒绝服务 (IDoS) 攻击的弹性和自适应警报和注意力管理策略

DOI:
10.1016/j.cose.2022.102844
复制
发表时间:
2022
影响因子:
5.6
通讯作者:
Zhu, Quanyan
Zhu, Quanyan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Huang, Linan;Zhu, Quanyan

文献摘要

相似文献

利用人类注意力脆弱性的攻击对网络安全构成了严重威胁。在这项工作中,我们确定并正式定义了一种新型的主动注意攻击称为信息拒绝服务(IDoS)攻击,产生大量的佯攻超载人类操作员和隐藏真实的攻击之间的佯攻。我们将人为因素(例如,专业知识水平,压力和效率)和经验心理学结果(例如,耶基斯-多德森定律和沉没成本谬误)建模操作员的注意力动态和他们的决策过程沿着实时警报监控和检查。为了帮助人类操作员及时准确地消除伪装并升级真实的攻击,我们开发了一种弹性和自适应的数据驱动的警报和注意力管理策略(RADAMS),该策略根据警报的抽象类别标签选择性地淡化警报。RADAMS使用强化学习为各种人类操作员和不断发展的IDoS攻击实现定制和可转移的设计。综合建模和理论分析导致注意力的产品原则(PPoA),基本限制,以及关键的人力和经济因素之间的权衡。实验结果证实,该策略优于默认策略,可以降低IDoS风险高达20%。此外,该策略对成本、攻击频率和人类注意力能力的大变化具有弹性。我们已经认识到有趣的现象,如注意力风险等效性,攻击者的困境,和半真半假的最佳攻击策略。
Attacks exploiting human attentional vulnerability have posed severe threats to cybersecurity. In this work, we identify and formally define a new type of proactive attentional attacks called Informational Denial-of-Service (IDoS) attacks that generate a large volume of feint attacks to overload human operators and hide real attacks among feints. We incorporate human factors (eg, levels of expertise, stress, and efficiency) and empirical psychological results (eg, the Yerkes-Dodson law and the sunk cost fallacy) to model the operators’ attention dynamics and their decision-making processes along with the real-time alert monitoring and inspection. To assist human operators in dismissing the feints and escalating the real attacks timely and accurately, we develop a Resilient and Adaptive Data-driven alert and Attention Management Strategy (RADAMS) that de-emphasizes alerts selectively based on the abstracted category labels of the alerts. RADAMS uses reinforcement learning to achieve a customized and transferable design for various human operators and evolving IDoS attacks. The integrated modeling and theoretical analysis lead to the Product Principle of Attention (PPoA), fundamental limits, and the tradeoff among crucial human and economic factors. Experimental results corroborate that the proposed strategy outperforms the default strategy and can reduce the IDoS risk by as much as 20%. Besides, the strategy is resilient to large variations of costs, attack frequencies, and human attention capacities. We have recognized interesting phenomena such as attentional risk equivalency, attacker’s dilemma, and the half-truth optimal attack strategy.