【24h】

Cut-The-Rope: A Game of Stealthy Intrusion

机译:割草绳:隐形入侵游戏

获取原文

摘要

A major characteristic of Advanced Persistent Threats (APTs) is their stealthiness over a possibly long period, during which the victim system is being penetrated and prepared for the finishing blow. We model an APT as a game played on an attack graph G, and consider the following interaction pattern: the attacker chooses an attack path in G towards its target v_0, and step-by-step works its way towards the goal by repeated penetrations. In each step, it leaves a backdoor for an easy return to learn how to accomplish the next step. We call this return path the "rope". The defender's aim is "cutting" this rope by cleaning the system from (even unknown) backdoors, e.g., by patching systems or changing configurations. While the defender is doing so in fixed intervals governed by working hours/shifts, the attacker is allowed to take any number of moves at any point in time. The game is thus repeated, i.e., in discrete time, only for the defender, while the second player (adversary) moves in continuous time. It also has asymmetric information, since the adversary is stealthy at all times, until the damage causing phase of the APT. The payoff in the game is the attacker's chance to reach this final stage, while the defender's goal is minimizing this likelihood (risk). We illustrate the model by a numerical example and open access implementation in R.
机译:高级持续威胁(APT)的主要特征是它们可能在很长一段时间内保持隐身状态,在此期间,受害者系统正在渗透并为最终打击做好准备。我们将APT建模为在攻击图G上玩的游戏,并考虑以下交互模式:攻击者在G中选择朝向其目标v_0的攻击路径,并通过反复穿透逐步实现其向目标的方式。在每个步骤中,都会留下一个后门,以便轻松返回以学习如何完成下一步。我们将此返回路径称为“绳索”。防御者的目的是通过(例如通过修补系统或更改配置)从(甚至是未知的)后门清洗系统来“切断”该绳索。在防御者按照工作时间/轮班制固定的时间间隔这样做的同时,允许攻击者在任何时间点进行任何数量的移动。因此,仅针对防守者重复比赛,即在离散时间内重复比赛,而第二名玩家(对手)则连续比赛。它也具有不对称信息,因为对手一直都是隐身的,直到造成APT的损害阶段为止。游戏的收益是攻击者达到最后阶段的机会,而防御者的目标是使这种可能性(风险)最小化。我们通过一个数值示例和R中的开放访问实现来说明该模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号