Learning Equilibria In Stochastic Information Flow Tracking Games With Partial Knowledge

2019 IEEE 58TH CONFERENCE ON DECISION AND CONTROL (CDC)(2019)

引用 3|浏览69
暂无评分
摘要
Dynamic Information Flow Tracking (DIFT) has been proposed to detect stealthy and persistent cyber attacks in a computer system that evade existing defense mechanisms such as firewalls and signature-based antivirus systems. A DIFT-based defense tracks the propagation of suspicious information flows across the system and dynamically generates security analysis to identify possible attacks, at the cost of additional performance and memory overhead for analyzing non-adversarial information flows. In this paper, we model the interaction between adversarial information flows and DIFT on a partially known system as a nonzero-sum stochastic game. Our game model captures the probability that the adversary evades detection even when it is analyzed using the security policies (false-negatives) and the performance overhead incurred by the defender for analyzing the non-adversarial flows in the system. We prove the existence of a Nash equilibrium (NE) and propose a supervised learning-based approach to find an approximate NE. Our approach is based on a partially input convex neural network that learns a mapping between the strategies and payoffs of the players with the available system knowledge, and an alternating optimization technique that updates the players' strategies to obtain an approximate equilibrium. We evaluate the performance of the proposed approach and empirically show the convergence to an approximate NE for synthetic random generated graphs and real-world dataset collected using Refinable Attack INvestigation (RAIN) framework.
更多
查看译文
关键词
approximate NE,Refinable Attack INvestigation framework,stochastic information flow,Dynamic Information Flow Tracking,DIFT,stealthy cyber attacks,persistent cyber attacks,computer system,defense mechanisms,firewalls,signature-based antivirus systems,DIFTbased defense tracks,suspicious information,security analysis,additional performance,memory overhead,adversarial information,partially known system,nonzero-sum stochastic game,game model,security policies,performance overhead,supervised learning-based approach,partially input convex neural network,nonadversarial information
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要