A generic approach for network defense strategies generation based on evolutionary game theory

被引:2
|
作者
Liu, Liang [1 ]
Tang, Chuhao [1 ]
Zhang, Lei [1 ]
Liao, Shan [2 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610065, Peoples R China
[2] 30th Res Inst China Elect Technol Grp Corp, Chengdu 610041, Peoples R China
关键词
Evolutionary game theory; Dynamic attack and defense; Optimal defense strategy; Attack graph; Active directory security;
D O I
10.1016/j.ins.2024.120875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The generation of optimal defense strategies in dynamic adversarial environments is crucial for cybersecurity. Recently, defense approaches based on evolutionary game theory have gained significant achievements. However, they would fail when facing complex networks and sophisticated attack strategies, due to the fatal drawbacks of defense strategy generation considering atomic attacks only. To relieve this issue, a generic approach for generating defense strategies using evolutionary game theory is proposed in this paper. Initially, a novel payoff quantification method for network attack -defense games based on attack graphs is designed. Innovatively, two factors concerning the decision-maker's degree of irrationality (DI) and the level of environmental security (LES) are introduced into the replicator dynamics equation to model the impacts on equilibrium solutions. Noting that Active Directory (AD) domain service is one of the most used and representative information security management system in Windows domains, from which attack graphs and paths can be plainly extracted and analyzed. Therefore, it is necessary and imperative to anchor AD to unfold the theoretical analyses and experiments validation based on a real environment. Case studies on a real -world AD network demonstrate that the proposed approach is effective and can generate stable and efficient defense strategies.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] Generation of security system defense strategies based on evolutionary game theory
    Zou, Bowen
    Wang, Yongdong
    Liu, Chunqiang
    Dai, Mingguang
    Du, Qianwen
    Zhu, Xiang
    NUCLEAR ENGINEERING AND TECHNOLOGY, 2024, 56 (09) : 3463 - 3471
  • [2] Research on Optimization of Array Honeypot Defense Strategies Based on Evolutionary Game Theory
    Shi, Leyi
    Wang, Xiran
    Hou, Huiwen
    MATHEMATICS, 2021, 9 (08)
  • [3] Incumbents' defense strategies: a comparison of deterrence and shakeout strategy based on evolutionary game theory
    Homburg, Christian
    Fuerst, Andreas
    Ehrmann, Thomas
    Scheinker, Eugen
    JOURNAL OF THE ACADEMY OF MARKETING SCIENCE, 2013, 41 (02) : 185 - 205
  • [4] Incumbents’ defense strategies: a comparison of deterrence and shakeout strategy based on evolutionary game theory
    Christian Homburg
    Andreas Fürst
    Thomas Ehrmann
    Eugen Scheinker
    Journal of the Academy of Marketing Science, 2013, 41 : 185 - 205
  • [5] Analysis of Bidding Strategies of Generation Companies by Evolutionary Game Theory
    Huang, Xian
    Wang, Zhanhua
    ICIC 2009: SECOND INTERNATIONAL CONFERENCE ON INFORMATION AND COMPUTING SCIENCE, VOL 3, PROCEEDINGS: APPLIED MATHEMATICS, SYSTEM MODELLING AND CONTROL, 2009, : 62 - 65
  • [6] Research on Offense and Defense of DDos Based on Evolutionary Game Theory
    Zhao, Tengteng
    Zhang, Wei
    Li, Xiaolong
    Wang, Wenjing
    Niu, Xu
    Guo, Hui
    ARTIFICIAL INTELLIGENCE AND SECURITY, ICAIS 2022, PT III, 2022, 13340 : 3 - 15
  • [7] A Generic Cyber Defense Scheme Based on Stackelberg Game for Vehicular Network
    Sedjelmaci, Hichem
    Brahmi, Imane Horiya
    Boudguiga, Aymen
    Klaudel, Witold
    2018 15TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2018,
  • [8] A Method for Selecting Defense Strategies Based on Stochastic Evolutionary Game Model
    Huang J.-M.
    Zhang H.-W.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2018, 46 (09): : 2222 - 2228
  • [9] Optimal Network Defense Strategy Selection Method Based on Evolutionary Network Game
    Liu, Xiaohu
    Zhang, Hengwei
    Zhang, Yuchen
    Shao, Lulu
    SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [10] Attack and Defense Strategies in Complex Networks Based on Game Theory
    LI Yapeng
    DENG Ye
    XIAO Yu
    WU Jun
    JournalofSystemsScience&Complexity, 2019, 32 (06) : 1630 - 1640