2018/11/13 by Shana Moothedath, Moothedath, Shana, Dinuka Sahabandu +11
Computer Science · Engineering · #Computer Science and Game Theory (cs.GT) #FOS: Computer and information sciences #Information and Cyber Security #Network Security and Intrusion Detection #Smart Grid Security and Resilience
paper · pdf · doi:10.48550/arxiv.1811.05622
openalex publication_date 2018/11/13 · openalex created_date 2022/08/02 · openalex updated_date 2026/07/28
Advanced Persistent Threats (APTs) infiltrate cyber systems and compromise\nspecifically targeted data and/or resources through a sequence of stealthy\nattacks consisting of multiple stages. Dynamic information flow tracking has\nbeen proposed to detect APTs. In this paper, we develop a dynamic information\nflow tracking game for resource-efficient detection of APTs via multi-stage\ndynamic games. The game evolves on an information flow graph, whose nodes are\nprocesses and objects (e.g. file, network endpoints) in the system and the\nedges capture the interaction between different processes and objects. Each\nstage of the game has pre-specified targets which are characterized by a set of\nnodes of the graph and the goal of the APT is to evade detection and reach a\ntarget node of that stage. The goal of the defender is to maximize the\ndetection probability while minimizing performance overhead on the system. The\nresource costs of the players are different and the information structure is\nasymmetric resulting in a nonzero-sum imperfect information game. We first\ncalculate the best responses of the players and characterize the set of Nash\nequilibria for single stage attacks. Subsequently, we provide a polynomial-time\nalgorithm to compute a correlated equilibrium for the multi-stage attack case.\nFinally, we experiment our model and algorithms on real-world nation state\nattack data obtained from Refinable Attack Investigation system.\n