清晨好,您是今天最早来到科研通的研友!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您科研之路漫漫前行!

Attacker-Centric View of a Detection Game against Advanced Persistent Threats

对手 恶意软件 计算机网络
作者
Liang Xiao,Dongjin Xu,Narayan B. Mandayam,H. Vincent Poor
出处
期刊:IEEE Transactions on Mobile Computing [Institute of Electrical and Electronics Engineers]
卷期号:17 (11): 2512-2523 被引量:26
标识
DOI:10.1109/tmc.2018.2814052
摘要

Advanced persistent threats (APTs) are a major threat to cyber-security, causing significant financial and privacy losses each year. In this paper, cumulative prospect theory (CPT) is applied to study the interactions between a cyber system and an APT attacker when each of them makes subjective decisions to choose their scan interval and attack interval, respectively. Both the probability distortion effect and the framing effect are applied to model the deviation of subjective decisions of end-users from the objective decisions governed by expected utility theory, under uncertain attack durations in a pure-strategy game and scan interval in a mixed-strategy game. The CPT-based APT detection game incorporates both the probability weighting distortion and the framing effect of the subjective attacker and security agent of the cyber system, rather than discrete decision weights, as in earlier prospect theoretic study of APT detection. The Nash equilibria of the APT detection game are derived, showing that a subjective attacker becomes risk-seeking if the frame of reference for evaluating the utility is large, and becomes risk-averse if the frame of reference for evaluating the utility is small. A policy hill-climbing (PHC) based detection scheme is proposed to increase the policy uncertainty to fool the attacker in the dynamic game, and a “hotbooting” technique that exploits experiences in similar scenarios to initialize the quality values is developed to accelerate the learning speed of PHC-based detection. A practical example of a mobile network is presented to evaluate the performance of the proposed detection strategy. Simulation results show that the proposed strategy can improve detection performance with a higher data protection level and utilities of the cloud in the presence of an attacker compared with a standard Q-learning strategy.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
沉沉完成签到 ,获得积分0
32秒前
musei完成签到 ,获得积分10
38秒前
orixero应助Jack80采纳,获得30
38秒前
2分钟前
star应助科研通管家采纳,获得10
2分钟前
巨人文发布了新的文献求助10
2分钟前
lunar完成签到 ,获得积分10
2分钟前
2分钟前
3分钟前
3分钟前
3分钟前
4分钟前
七喜完成签到 ,获得积分10
4分钟前
5分钟前
5分钟前
5分钟前
研友_X894JZ完成签到 ,获得积分10
5分钟前
6分钟前
6分钟前
mengyuhuan完成签到 ,获得积分10
6分钟前
6分钟前
7分钟前
俊哲之家发布了新的文献求助10
7分钟前
7分钟前
紫熊完成签到,获得积分10
7分钟前
7分钟前
WoUHaai完成签到 ,获得积分10
7分钟前
7分钟前
烟花应助2.17;10.13采纳,获得10
8分钟前
8分钟前
8分钟前
star应助科研通管家采纳,获得10
8分钟前
乐乐应助科研通管家采纳,获得10
8分钟前
8分钟前
绽放完成签到 ,获得积分10
8分钟前
8分钟前
LSH970829发布了新的文献求助10
8分钟前
9分钟前
10分钟前
10分钟前
高分求助中
Manual of Clinical Microbiology, 4 Volume Set (ASM Books) 13th Edition 1000
Sport in der Antike 800
De arte gymnastica. The art of gymnastics 600
少脉山油柑叶的化学成分研究 530
Mechanical Methods of the Activation of Chemical Processes 510
Electronic Structure Calculations and Structure-Property Relationships on Aromatic Nitro Compounds 500
Berns Ziesemer - Maos deutscher Topagent: Wie China die Bundesrepublik eroberte 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 有机化学 工程类 生物化学 纳米技术 物理 内科学 计算机科学 化学工程 复合材料 遗传学 基因 物理化学 催化作用 电极 光电子学 量子力学
热门帖子
关注 科研通微信公众号,转发送积分 2419077
求助须知:如何正确求助?哪些是违规求助? 2110196
关于积分的说明 5337774
捐赠科研通 1837360
什么是DOI,文献DOI怎么找? 914970
版权声明 561134
科研通“疑难数据库(出版商)”最低求助积分说明 489315