Learning Games for Defending Advanced Persistent Threats in Cyber Systems

被引:9
|
作者
Zhu, Tianqing [1 ]
Ye, Dayong [2 ,3 ]
Cheng, Zishuo [2 ,3 ]
Zhou, Wanlei [4 ]
Yu, Philip S. [5 ]
机构
[1] China Univ Geosci, Sch Comp Sci, Wuhan 430074, Peoples R China
[2] Univ Technol Sydney, Ctr Cyber Secur & Privacy, Ultimo, NSW 2007, Australia
[3] Univ Technol Sydney, Sch Comp Sci, Ultimo, NSW 2007, Australia
[4] City Univ Macau, Inst Data Sci, Macau, Peoples R China
[5] Univ Illinois, Dept Comp Sci, Chicago, IL 60607 USA
基金
美国国家科学基金会;
关键词
Advanced persistent threats (APTs); cyber system security; deep reinforcement learning; game theory; SECURITY;
D O I
10.1109/TSMC.2022.3211866
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A cyber system may face to multiple attackers from diverse adversaries, who usually employ sophisticated techniques to both continuously steal sensitive data and avoid being detected by defense strategies. This continuous process is typically involved in an advanced persistent threat (APT). Since the game theory is an ideal mathematical model for investigating continuous decision making of competing players, it is broadly used to research the interaction between defenders and APT attackers. Although many researchers are now using the game theory to defend against APT attacks, most of the existing solutions are limited to single-defender, single-attacker scenarios. In the real world, threats by multiple attackers are not uncommon and multiple defenders can be put in place. Therefore, to overcome the limitation of the existing solutions, we develop a multiagent deep reinforcement learning (MADRL) method with a novel sampling approach. The MADRL method allows defenders to create strategies on the fly and share their experience with other defenders. To develop this method, we create a multidefender, multiattacker game model and analyze the equilibrium of this model. The results of a series of experiments demonstrate that, with MADRL, defenders can quickly learn efficient strategies against attackers.
引用
收藏
页码:2410 / 2422
页数:13
相关论文
共 50 条
  • [21] Defending the Defender: Adversarial Learning Based Defending Strategy for Learning Based Security Methods in Cyber-Physical Systems (CPS)
    Sheikh, Zakir Ahmad
    Singh, Yashwant
    Singh, Pradeep Kumar
    Goncalves, Paulo J. Sequeira
    SENSORS, 2023, 23 (12)
  • [22] Modeling Observability in Adaptive Systems to Defend Against Advanced Persistent Threats
    Kinneer, Cody
    Wagner, Ryan
    Fang, Fei
    Le Goues, Claire
    Garlan, David
    17TH ACM-IEEE INTERNATIONAL CONFERENCE ON FORMAL METHODS AND MODELS FOR SYSTEM DESIGN (MEMOCODE), 2019,
  • [23] Systems Dynamics Modeling for Evaluating SocioTechnical Vulnerabilities in Advanced Persistent Threats
    Nicho, Mathew
    Girija, Shini
    2022 15TH INTERNATIONAL CONFERENCE ON HUMAN SYSTEM INTERACTION (HSI), 2022,
  • [24] A Practical Study on Advanced Persistent Threats
    Jeun, Inkyung
    Lee, Youngsook
    Won, Dongho
    COMPUTER APPLICATIONS FOR SECURITY, CONTROL AND SYSTEM ENGINEERING, 2012, 339 : 144 - +
  • [25] Advanced Persistent Threats & Social Engineering
    Weippl, Edgar
    2014 11TH INTERNATIONAL CONFERENCE ON E-BUSINESS (ICE-B), 2014, : IS21 - IS21
  • [26] Advanced Persistent Threats - Detection and Defense
    Vukalovic, J.
    Delija, D.
    2015 8TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2015, : 1324 - 1330
  • [27] Advanced Persistent Threats & Social Engineering
    Weippl, Edgar
    2014 INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MULTIMEDIA APPLICATIONS (SIGMAP), 2014, : IS13 - IS13
  • [28] Advanced Persistent Threats: Behind the Scenes
    Ussath, Martin
    Jaeger, David
    Cheng, Feng
    Meinel, Christoph
    2016 ANNUAL CONFERENCE ON INFORMATION SCIENCE AND SYSTEMS (CISS), 2016,
  • [29] A performance overview of machine learning-based defense strategies for advanced persistent threats in industrial control systems
    Imran, Muhammad
    Siddiqui, Hafeez Ur Rehman
    Raza, Ali
    Raza, Muhammad Amjad
    Rustam, Furqan
    Ashraf, Imran
    COMPUTERS & SECURITY, 2023, 134
  • [30] Advanced Persistent Threats in Autonomous Driving
    Kant K.
    Performance Evaluation Review, 2020, 47 (04): : 25 - 28