论文标题

图表上的超级冠军理论,用于欺骗动态网络防御

A Theory of Hypergames on Graphs for Synthesizing Dynamic Cyber Defense with Deception

论文作者

Kulkarni, Abhishek N., Fu, Jie

论文摘要

在本章中,我们提出了一种使用形式方法来合成网络网络中的反应性防御策略的方法,该策略配备了一组诱饵系统。我们首先将正式的图形安全模型(攻击图形)概括为将Defender的对策纳入游戏理论模型,称为“攻击”剥离游戏。该游戏捕获了防守者与攻击者之间的动态相互作用,并以形式逻辑中的防御/攻击目标。然后,我们引入了一类超级游戏,以建模诱饵相互作用中诱饵创建的不对称信息。鉴于正式逻辑中的定性安全规范,我们表明,可以扩展来自超级策略的解决方案概念和反应性合成,以使用网络欺骗来综合有效的动态防御策略。该策略占据了攻击者误解的优势,以确保满足安全规范,而当信息为对称时,这可能无法满足。

In this chapter, we present an approach using formal methods to synthesize reactive defense strategy in a cyber network, equipped with a set of decoy systems. We first generalize formal graphical security models--attack graphs--to incorporate defender's countermeasures in a game-theoretic model, called an attack-defend game on graph. This game captures the dynamic interactions between the defender and the attacker and their defense/attack objectives in formal logic. Then, we introduce a class of hypergames to model asymmetric information created by decoys in the attacker-defender interactions. Given qualitative security specifications in formal logic, we show that the solution concepts from hypergames and reactive synthesis in formal methods can be extended to synthesize effective dynamic defense strategy using cyber deception. The strategy takes the advantages of the misperception of the attacker to ensure security specification is satisfied, which may not be satisfiable when the information is symmetric.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源