首页> 外文会议>International conference on decision and game theory for security >Manipulating Adversary's Belief: A Dynamic Game Approach to Deception by Design for Proactive Network Security
【24h】

Manipulating Adversary's Belief: A Dynamic Game Approach to Deception by Design for Proactive Network Security

机译:操纵对手的信念:动态设计的主动网络安全欺骗方法

获取原文

摘要

Due to the sophisticated nature of current computer systems, traditional defense measures, such as firewalls, malware scanners, and intrusion detection/prevention systems, have been found inadequate. These technological systems suffer from the fact that a sophisticated attacker can study them, identify their weaknesses and thus get an advantage over the defender. To prevent this from happening a proactive cyber defense is a new defense mechanism in which we strategically engage the attacker by using cyber deception techniques, and we influence his actions by creating and reinforcing his view of the computer system. We apply the cyber deception techniques in the field of network security and study the impact of the deception on attacker's beliefs using the quantitative framework of the game theory. We account for the sequential nature of an attack and investigate how attacker's belief evolves and influences his actions. We show how the defender should manipulate this belief to prevent the attacker from achieving his goals and thus minimize the damage inflicted to the network. To design a successful defense based on cyber deception, it is crucial to employ strategic thinking and account explicitly for attacker's belief that he is being exposed to deceptive attempts. By doing so, we can make the deception more believable from the perspective of the attacker.
机译:由于当前计算机系统的复杂性,已发现传统的防御措施(如防火墙,恶意软件扫描器和入侵检测/预防系统)不足。这些技术系统遭受这样一个事实的折磨:高级攻击者可以对其进行研究,找出其弱点,从而获得优于防御者的优势。为防止这种情况的发生,积极的网络防御是一种新的防御机制,在这种机制中,我们通过使用网络欺骗技术从战略上与攻击者进行互动,并通过创建和增强他对计算机系统的看法来影响攻击者的行为。我们将网络欺骗技术应用于网络安全领域,并使用博弈论的定量框架研究欺骗行为对攻击者信念的影响。我们考虑了攻击的顺序性质,并研究了攻击者的信念如何演变并影响其行为。我们展示了防御者应如何操纵这种信念,以防止攻击者实现其目标,从而最大程度地减少对网络造成的损害。要设计基于网络欺骗的成功防御,至关重要的是要运用战略思维,并明确说明攻击者的信念,即他正遭受欺骗性企图。这样,从攻击者的角度来看,我们可以使欺骗更加可信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号