Markov Decision Process to Enforce Moving Target Defence Policies

05/22/2019
by   Jianjun Zheng, et al.
0

Moving Target Defense (MTD) is an emerging game-changing defense strategy in cybersecurity with the goal of strengthening defenders and conversely puzzling adversaries in a network environment. The successful deployment of an MTD system can be affected by several factors including 1) the effectiveness of the employed technique, 2) the deployment strategy, 3) the cost of the MTD implementation, and 4) the impact yielded by the enforced security policies. Many research efforts have been spent on introducing a variety of MTD techniques which are often evaluated through simulations. Nevertheless, this line of research needs more attention. In particular, the determination of optimal cost and policy analysis and the selection of those policies in an MTD setting is still an open research question. To advance the state-of-the-art of this line of research, this paper introduces an approach based on control theory to model, analyze and select optimal security policies for Moving Target Defense (MTD) deployment strategies. A Markov Decision Process (MDP) scheme is presented to model states of the system from attacking point of view. The employed value iteration method is based on the Bellman optimality equation for optimal policy selection for each state defined in the system. The model is then utilized to analyze the impact of various costs on the optimal policy. The MDP model is then applied to two case studies to evaluate the performance of the model.

READ FULL TEXT
research
02/07/2020

A Receding-Horizon MDP Approach for Performance Evaluation of Moving Target Defense in Networks

In this paper, we study the problem of assessing the effectiveness of a ...
research
07/12/2022

Markov Decision Process For Automatic Cyber Defense

It is challenging for a security analyst to detect or defend against cyb...
research
10/29/2018

An approach to predictively securing critical cloud infrastructures through probabilistic modeling

Cloud infrastructures are being increasingly utilized in critical infras...
research
11/27/2019

Deep Reinforcement Learning based Adaptive Moving Target Defense

Moving target defense (MTD) is a proactive defense approach that aims to...
research
09/09/2011

Integrating Learning from Examples into the Search for Diagnostic Policies

This paper studies the problem of learning diagnostic policies from trai...
research
07/12/2012

Learning Diagnostic Policies from Examples by Systematic Search

A diagnostic policy specifies what test to perform next, based on the re...
research
05/23/2019

Where to Find Next Passengers on E-hailing Platforms? - A Markov Decision Process Approach

Vacant taxi drivers' passenger seeking process in a road network generat...

Please sign up or login with your details

Forgot password? Click here to reset