A Bayesian-network-based cybersecurity adversarial risk analysis framework with numerical examples

06/01/2021
by   Jiali Wang, et al.
0

Cybersecurity risk analysis plays an essential role in supporting organizations make effective decision about how to manage and control cybersecurity risk. Cybersecurity risk is a function of the interplay between the defender, i.e., the organisation, and the attacker: decisions and actions made by the defender second guess the decisions and actions taken by the attacker and vice versa. Insight into this game between these two agents provides a means for the defender to identify and make optimal decisions. To date, the adversarial risk analysis framework has provided a decision-analytical approach to solve such game problems in the presence of uncertainty and uses Monte Carlo simulation to calculate and identify optimal decisions. We propose an alternative framework to construct and solve a serial of sequential Defend-Attack models, that incorporates the adversarial risk analysis approach, but uses a new class of influence diagrams algorithm, called hybrid Bayesian network inference, to identify optimal decision strategies. Compared to Monte Carlo simulation the proposed hybrid Bayesian network inference is more versatile because it provides an automated way to compute hybrid Defend-Attack models and extends their use to involve mixtures of continuous and discrete variables, of any kind. More importantly, the hybrid Bayesian network approach is novel in that it supports dynamic decision making whereby new real-time observations can update the Defend-Attack model in practice. We also extend the Defend-Attack model to support cases involving extra variables and longer decision sequence. Examples are presented, illustrating how the proposed framework can be adjusted for more complicated scenarios, including dynamic decision making.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/25/2017

D numbers theory based game-theoretic framework in adversarial decision making under fuzzy environment

Adversarial decision making is a particular type of decision making prob...
research
10/08/2015

Exact Inference Techniques for the Analysis of Bayesian Attack Graphs

Attack graphs are a powerful tool for security risk assessment by analys...
research
11/09/2019

Markov-chain Monte-Carlo Sampling for Optimal Fidelity Determination in Dynamic Decision-Making

Decision making for dynamic systems is challenging due to the scale and ...
research
07/19/2022

Economics and Optimal Investment Policies of Attackers and Defenders in Cybersecurity

In our time cybersecurity has grown to be a topic of massive proportion ...
research
10/10/2019

Augmented Probability Simulation Methods for Non-cooperative Games

We present a comprehensive robust decision support framework with novel ...
research
01/18/2010

A Monte Carlo Algorithm for Universally Optimal Bayesian Sequence Prediction and Planning

The aim of this work is to address the question of whether we can in pri...
research
12/12/2012

Unconstrained Influence Diagrams

We extend the language of influence diagrams to cope with decision scena...

Please sign up or login with your details

Forgot password? Click here to reset