首页> 外文期刊>IEEE transactions on information forensics and security >Effective Repair Strategy Against Advanced Persistent Threat: A Differential Game Approach
【24h】

Effective Repair Strategy Against Advanced Persistent Threat: A Differential Game Approach

机译:针对高级持久威胁的有效修复策略:一种差分博弈方法

获取原文
获取原文并翻译 | 示例
           

摘要

Advanced persistent threat (APT) is a new kind of cyberattack that poses a serious threat to modern society. When an APT campaign on an organization has been identified, the available repair resources must be reasonably allocated to the potentially insecure hosts to mitigate the potential loss of the organization. We refer to the feasible repair resource allocation strategies as repair strategies. This paper focuses on the APT repair problem, i.e., the problem of developing effective repair strategies for organizations. First, for an organization with time-varying communication relationship, we establish an evolution model of the organization's expected state, in which the impact of lateral movement of APT is accommodated. On this basis, we model the APT repair problem as a differential Nash game problem (the APT repair game) in which the attacker attempts to maximize his potential benefit, and the organization manages to minimize its potential loss. Second, we derive a system (the potential system) for calculating a potential Nash equilibrium of an APT repair game, and we examine the structure of the potential attack and repair strategies in a potential Nash equilibrium. Next, we solve some potential systems to get the corresponding potential Nash equilibria. Finally, by comparison with a large number of randomly generated attack and repair strategies, we conclude that the potential Nash equilibrium of each APT repair game is a Nash equilibrium of the game. Therefore, we recommend to organizations their respective potential repair strategies. Our findings help to better understand and effectively defend against APT.
机译:高级持续威胁(APT)是一种新型的网络攻击,对现代社会构成了严重威胁。确定组织上的APT活动后,必须将可用的维修资源合理地分配给潜在不安全的主机,以减轻组织的潜在损失。我们将可行的维修资源分配策略称为维修策略。本文着重于APT维修问题,即为组织制定有效维修策略的问题。首先,对于具有时变通信关系的组织,我们建立了组织期望状态的演化模型,其中考虑了APT横向移动的影响。在此基础上,我们将APT修复问题建模为差分Nash游戏问题(APT修复游戏),在该问题中,攻击者试图最大化其潜在利益,而组织则设法将其潜在损失最小化。其次,我们推导了一个用于计算APT维修博弈的潜在Nash均衡的系统(潜在系统),并研究了潜在Nash均衡中潜在攻击和修复策略的结构。接下来,我们解决一些潜在系统以获得相应的潜在纳什均衡。最后,通过与大量随机生成的攻击和修复策略进行比较,我们得出结论,每个APT修复游戏的潜在Nash平衡是游戏的Nash平衡。因此,我们建议组织各自的潜在修复策略。我们的发现有助于更好地理解和有效防御APT。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号