首页> 外文会议>International conference on decision and game theory for security >Game-Theoretic Approach to Feedback-Driven Multi-stage Moving Target Defense
【24h】

Game-Theoretic Approach to Feedback-Driven Multi-stage Moving Target Defense

机译:反馈驱动的多阶段移动目标防御的博弈论方法

获取原文

摘要

The static nature of computer networks allows malicious attackers to easily gather useful information about the network using network scanning and packet sniffing. The employment of secure perimeter firewalls and intrusion detection systems cannot fully protect the network from sophisticated attacks. As an alternative to the expensive and imperfect detection of attacks, it is possible to improve network security by manipulating the attack surface of the network in order to create a moving target defense. In this paper, we introduce a proactive defense scheme that dynamically alters the attack surface of the network to make it difficult for attackers to gather system information by increasing complexity and reducing its signatures. We use concepts from systems and control literature to design an optimal and efficient multi-stage defense mechanism based on a feedback information structure. The change of attack surface involves a reconfiguration cost and a utility gain resulting from risk reduction. We use information- and control-theoretic tools to provide closed-form optimal randomization strategies. The results are corroborated by a case study and several numerical examples.
机译:计算机网络的静态性质使恶意攻击者可以使用网络扫描和数据包嗅探轻松收集有关网络的有用信息。使用安全外围防火墙和入侵检测系统不能完全保护网络免受复杂攻击。作为昂贵且不完善的攻击检测的替代方法,可以通过操纵网络的攻击面来创建移动目标防御,从而提高网络安全性。在本文中,我们介绍了一种主动防御方案,该方案可以动态更改网络的攻击面,从而使攻击者难以通过增加复杂性和减少其签名来收集系统信息。我们使用系统和控制文献中的概念来设计基于反馈信息结构的最优,高效的多阶段防御机制。攻击面的改变涉及重新配置成本和降低风险所带来的效用收益。我们使用信息理论和控制理论工具来提供封闭形式的最佳随机策略。案例研究和几个数值示例证实了这一结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号