A Dynamic Games Approach to Proactive Defense Strategies against Advanced Persistent Threats in Cyber-Physical Systems
arXiv:1906.09687 · doi:10.1016/j.cose.2019.101660
Abstract
Advanced Persistent Threats (APTs) have recently emerged as a significant security challenge for a cyber-physical system due to their stealthy, dynamic and adaptive nature. Proactive dynamic defenses provide a strategic and holistic security mechanism to increase the costs of attacks and mitigate the risks. This work proposes a dynamic game framework to model a long-term interaction between a stealthy attacker and a proactive defender. The stealthy and deceptive behaviors are captured by the multi-stage game of incomplete information, where each player has his own private information unknown to the other. Both players act strategically according to their beliefs which are formed by the multi-stage observation and learning. The perfect Bayesian Nash equilibrium provides a useful prediction of both players' policies because no players benefit from unilateral deviations from the equilibrium. We propose an iterative algorithm to compute the perfect Bayesian Nash equilibrium and use the Tennessee Eastman process as a benchmark case study. Our numerical experiment corroborates the analytical results and provides further insights into the design of proactive defense-in-depth strategies.
References in corpus (1)
Cited by in corpus (23)
- Adaptive Honeypot Engagement through Reinforcement Learning of Semi-Markov Decision Processes
- A Survey on Cyber-Resilience Approaches for Cyber-Physical Systems
- A Threat-Intelligence Driven Methodology to Incorporate Uncertainty in Cyber Risk Analysis and Enhance Decision Making
- Adaptive Anomaly Detection for Identifying Attacks in Cyber-Physical Systems: A Systematic Literature Review
- A Dynamic Game Framework for Rational and Persistent Robot Deception With an Application to Deceptive Pursuit-Evasion
- ADVERT: An Adaptive and Data-Driven Attention Enhancement Mechanism for Phishing Prevention
- Learning Near-Optimal Intrusion Responses Against Dynamic Attackers
- RADAMS: Resilient and Adaptive Alert and Attention Management Strategy against Informational Denial-of-Service (IDoS) Attacks
- Feedback and Open-Loop Nash Equilibria for LQ Infinite-Horizon Discrete-Time Dynamic Games
- Coordinated Cyber-Attack Detection Model of Cyber-Physical Power System Based on the Operating State Data Link
- Automated Security Response through Online Learning with Adaptive Conjectures
- ZETAR: Modeling and Computational Design of Strategic and Adaptive Compliance Policies
- A Consolidated Game Framework for Cooperative Defense Against Cross-Domain Cyber Attacks in Satellite-Enabled Internet of Things
- Convergence of Bayesian Nash Equilibrium in Infinite Bayesian Games under Discretization
- Control Challenges for Resilient Control Systems
- Duplicity Games for Deception Design with an Application to Insider Threat Mitigation
- A Study on the Importance of Features in Detecting Advanced Persistent Threats Using Machine Learning
- Dynamic Games for Secure and Resilient Control System Design
- A Receding-Horizon MDP Approach for Performance Evaluation of Moving Target Defense in Networks
- Strategic Learning for Active, Adaptive, and Autonomous Cyber Defense
- Combating Informational Denial-of-Service (IDoS) Attacks: Modeling and Mitigation of Attentional Human Vulnerability
- Farsighted Risk Mitigation of Lateral Movement Using Dynamic Cognitive Honeypots
- The Confluence of Networks, Games and Learning