Optimal Repair Strategy Against Advanced Persistent Threats Under Time-Varying Networks

09/01/2023
by   Zixuan Wang, et al.
0

Advanced persistent threat (APT) is a kind of stealthy, sophisticated, and long-term cyberattack that has brought severe financial losses and critical infrastructure damages. Existing works mainly focus on APT defense under stable network topologies, while the problem under time-varying dynamic networks (e.g., vehicular networks) remains unexplored, which motivates our work. Besides, the spatiotemporal dynamics in defense resources, complex attackers' lateral movement behaviors, and lack of timely defense make APT defense a challenging issue under time-varying networks. In this paper, we propose a novel game-theoretical APT defense approach to promote real-time and optimal defense strategy-making under both periodic time-varying and general time-varying environments. Specifically, we first model the interactions between attackers and defenders in an APT process as a dynamic APT repair game, and then formulate the APT damage minimization problem as the precise prevention and control (PPAC) problem. To derive the optimal defense strategy under both latency and defense resource constraints, we further devise an online optimal control-based mechanism integrated with two backtracking-forward algorithms to fastly derive the near-optimal solution of the PPAC problem in real time. Extensive experiments are carried out, and the results demonstrate that our proposed scheme can efficiently obtain optimal defense strategy in 54481 ms under seven attack-defense interactions with 9.64% resource occupancy in stimulated periodic time-varying and general time-varying networks. Besides, even under static networks, our proposed scheme still outperforms existing representative APT defense approaches in terms of service stability and defense resource utilization.

READ FULL TEXT

page 1

page 16

research
01/19/2018

Defense Against Advanced Persistent Threats in Dynamic Cloud Storage: A Colonel Blotto Game Approach

Advanced Persistent Threat (APT) attackers apply multiple sophisticated ...
research
10/29/2022

Collaborative Honeypot Defense in UAV Networks: A Learning-Based Game Approach

The proliferation of unmanned aerial vehicles (UAVs) opens up new opport...
research
01/10/2020

Time-Varying Graph Learning with Constraints on Graph Temporal Variation

We propose a novel framework for learning time-varying graphs from spati...
research
06/06/2019

Connected Subgraph Defense Games

We study a security game over a network played between a defender and k ...
research
05/30/2019

Optimal Timing of Moving Target Defense: A Stackelberg Game Model

As an effective approach to thwarting advanced attacks, moving target de...
research
05/25/2020

Optimal assignment of collaborating agents in multi-body asset-guarding games

We study a multi-body asset-guarding game in missile defense where teams...
research
12/05/2019

Turnpike in optimal shape design

We introduce and study the turnpike property for time-varying shapes, wi...

Please sign up or login with your details

Forgot password? Click here to reset