A generic approach for network defense strategies generation based on evolutionary game theory

被引:2
|
作者
Liu, Liang [1 ]
Tang, Chuhao [1 ]
Zhang, Lei [1 ]
Liao, Shan [2 ]
机构
[1] Sichuan Univ, Sch Cyber Sci & Engn, Chengdu 610065, Peoples R China
[2] 30th Res Inst China Elect Technol Grp Corp, Chengdu 610041, Peoples R China
关键词
Evolutionary game theory; Dynamic attack and defense; Optimal defense strategy; Attack graph; Active directory security;
D O I
10.1016/j.ins.2024.120875
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The generation of optimal defense strategies in dynamic adversarial environments is crucial for cybersecurity. Recently, defense approaches based on evolutionary game theory have gained significant achievements. However, they would fail when facing complex networks and sophisticated attack strategies, due to the fatal drawbacks of defense strategy generation considering atomic attacks only. To relieve this issue, a generic approach for generating defense strategies using evolutionary game theory is proposed in this paper. Initially, a novel payoff quantification method for network attack -defense games based on attack graphs is designed. Innovatively, two factors concerning the decision-maker's degree of irrationality (DI) and the level of environmental security (LES) are introduced into the replicator dynamics equation to model the impacts on equilibrium solutions. Noting that Active Directory (AD) domain service is one of the most used and representative information security management system in Windows domains, from which attack graphs and paths can be plainly extracted and analyzed. Therefore, it is necessary and imperative to anchor AD to unfold the theoretical analyses and experiments validation based on a real environment. Case studies on a real -world AD network demonstrate that the proposed approach is effective and can generate stable and efficient defense strategies.
引用
收藏
页数:26
相关论文
共 50 条
  • [31] MAIAD: A Multistage Asymmetric Information Attack and Defense Model Based on Evolutionary Game Theory
    Yang, Yu
    Che, Bichen
    Zeng, Yang
    Cheng, Yang
    Li, Chenyang
    SYMMETRY-BASEL, 2019, 11 (02):
  • [32] A generic evolutionary computation approach based upon genetic algorithms and evolution strategies
    Affenzeller, Michael
    Systems Science, 2002, 28 (02): : 59 - 71
  • [33] Evolutionary Game Theory Based Network Selection for Constrained Heterogeneous Networks
    Sui, Nannan
    Zhang, Dongmei
    Zhong, Wei
    Wu, Lianguo
    Zhang, Zhensong
    2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CONTROL ENGINEERING ICISCE 2015, 2015, : 740 - 744
  • [34] Privacy and evolutionary cooperation in neural-network-based game theory
    Cheng, Zishuo
    Zhu, Tianqing
    Zhu, Congcong
    Ye, Dayong
    Zhou, Wanlei
    Yu, Philip S.
    KNOWLEDGE-BASED SYSTEMS, 2023, 282
  • [35] Multi-Player Evolutionary Game of Network Attack and Defense Based on System Dynamics
    Yang, Pengxi
    Gao, Fei
    Zhang, Hua
    MATHEMATICS, 2021, 9 (23)
  • [36] Network Defense Decision-making Method Based on Improved Evolutionary Game Model
    Ma, Runnian
    Zhang, Enning
    Wang, Gang
    Ma, Yufeng
    Weng, Jiang
    JOURNAL OF ELECTRONICS & INFORMATION TECHNOLOGY, 2023, 45 (06) : 1970 - 1980
  • [37] Analysis of Behavioral Strategies of Construction Safety Subjects Based on the Evolutionary Game Theory
    Wu, Fan
    Xu, Haiying
    Sun, Kuo-Shun
    Hsu, Wei-Ling
    BUILDINGS, 2022, 12 (03)
  • [38] ON A CONTINUOUS MIXED STRATEGIES MODEL FOR EVOLUTIONARY GAME THEORY
    Boccabella, Astridh
    Natalini, Roberto
    Pareschi, Lorenzo
    KINETIC AND RELATED MODELS, 2011, 4 (01) : 187 - 213
  • [39] An Evolutionary Game Theory Approach for Intelligent Patrolling
    Aguirre, Oswaldo
    Taboada, Heidi
    COMPLEX ADAPTIVE SYSTEMS 2012, 2012, 12 : 140 - 145
  • [40] Network Attack and Defense Game Theory Based on Bayes-Nash Equilibrium
    Liu, Liang
    Huang, Cheng
    Fang, Yong
    Wang, Zhenxue
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2019, 13 (10): : 5260 - 5275