Dynamic defense strategy against advanced persistent threat under heterogeneous networks

被引:14
|
作者
Lv, Kun [1 ]
Chen, Yun [1 ]
Hu, Changzhen [1 ]
机构
[1] Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China
关键词
Advanced persistent threat; Dynamic defense strategy; Game theory; Information fusion; Heterogeneous network; GAME; INFORMATION; FUSION; MODEL;
D O I
10.1016/j.inffus.2019.01.001
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Advanced persistent threats (APTs) pose a grave threat in cyberspace because of their long latency and concealment. In this paper, we propose a hybrid strategy game-based dynamic defense model to optimally allocate constrained secure resources for the target network. In addition, values of profits of players in this game are computed by a novel data-fusion method called NetF. Based on network protocols and log documents, the NetF deciphers data packets collected from different networks to natural language to make them comparable. Using this algorithm, data observed from the Internet and wireless sensor networks (WSNs) can be fused to calculate the comprehensive payoff of every node precisely. The Nash equilibrium can be computed using the value to detect the possibility of a node being a malicious node. Using this method, the dynamic optimal defense strategy can be allocated to every node at different times, which enhances the security of the target network obviously. In experiments, we illustrate the obtained results via case studies of a cluster of heterogeneous networks. The results guide planning of optimal defense strategies for different kinds of nodes at different times.
引用
收藏
页码:216 / 226
页数:11
相关论文
共 50 条
  • [21] Defense of Advanced Persistent Threat on Industrial Internet of Things With Lateral Movement Modeling
    Bi, Jichao
    He, Shibo
    Luo, Fengji
    Meng, Wenchao
    Ji, Luyue
    Huang, Da-Wen
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2023, 19 (09) : 9619 - 9630
  • [22] Defense against malware propagation in complex heterogeneous networks
    Hosseini, Soodeh
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2021, 24 (02): : 1199 - 1215
  • [23] Defense against malware propagation in complex heterogeneous networks
    Soodeh Hosseini
    Cluster Computing, 2021, 24 : 1199 - 1215
  • [24] Deep Reinforcement Learning for Advanced Persistent Threat Detection in Wireless Networks
    Saheed, Kazeem
    Henna, Shagufta
    2023 31ST IRISH CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COGNITIVE SCIENCE, AICS, 2023,
  • [25] CAPTAIN: Community-based Advanced Persistent Threat Analysis in IT Networks
    Ramaki, Ali Ahmadian
    Ghaemi-Bafghi, Abbas
    Rasoolzadegan, Abbas
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2023, 42
  • [26] A dynamic games approach to proactive defense strategies against Advanced Persistent Threats in cyber-physical systems
    Huang, Linan
    Zhu, Quanyan
    COMPUTERS & SECURITY, 2020, 89
  • [27] Moving Target Defense against Advanced Persistent Threats for Cybersecurity Enhancement
    Khosravi-Farmad, Masoud
    Ramaki, Ali Ahmadian
    Bafghi, Abbas Ghaemi
    2018 8TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2018, : 280 - 285
  • [28] Defense Against Advanced Persistent Threats with Expert System for Internet of Things
    Hu, Qing
    Lv, Shichao
    Shi, Zhiqiang
    Sun, Limin
    Xiao, Liang
    WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2017, 2017, 10251 : 326 - 337
  • [29] Defense Against Advanced Persistent Threats: A Colonel Blotto Game Approach
    Min, Minghui
    Xiao, Liang
    Xie, Caixia
    Hajimirsadeghi, Mohammad
    Mandayam, Narayan B.
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [30] Multi-layered Defense against Advanced Persistent Threats (APT)
    Torii, Satoru
    Morinaga, Masanobu
    Yoshioka, Takashi
    Terada, Takeaki
    Unno, Yuki
    FUJITSU SCIENTIFIC & TECHNICAL JOURNAL, 2014, 50 (01): : 52 - 59