TY - GEN
T1 - Adaptive MTD Security using Markov Game Modeling
AU - Chowdhary, Ankur
AU - Sengupta, Sailik
AU - Alshamrani, Adel
AU - Huang, Dijiang
AU - Sabur, Abdulhakim
N1 - Publisher Copyright:
© 2019 IEEE.
PY - 2019/4/8
Y1 - 2019/4/8
N2 - Large scale cloud networks consist of distributed networking and computing elements that process critical information and thus security is a key requirement for any environment. Unfortunately, assessing the security state of such networks is a challenging task and the tools used in the past by security experts such as packet filtering, firewall, Intrusion Detection Systems (IDS) etc., provide a reactive security mechanism. In this paper, we introduce a Moving Target Defense (MTD) based proactive security framework for monitoring attacks which lets us identify and reason about multi-stage attacks that target software vulnerabilities present in a cloud network. We formulate the multi-stage attack scenario as a two-player zero-sum Markov Game (between the attacker and the network administrator) on attack graphs. The rewards and transition probabilities are obtained by leveraging the expert knowledge present in the Common Vulnerability Scoring System (CVSS). Our framework identifies an attacker's optimal policy and places countermeasures to ensure that this attack policy is always detected, thus forcing the attacker to use a sub-optimal policy with higher cost.
AB - Large scale cloud networks consist of distributed networking and computing elements that process critical information and thus security is a key requirement for any environment. Unfortunately, assessing the security state of such networks is a challenging task and the tools used in the past by security experts such as packet filtering, firewall, Intrusion Detection Systems (IDS) etc., provide a reactive security mechanism. In this paper, we introduce a Moving Target Defense (MTD) based proactive security framework for monitoring attacks which lets us identify and reason about multi-stage attacks that target software vulnerabilities present in a cloud network. We formulate the multi-stage attack scenario as a two-player zero-sum Markov Game (between the attacker and the network administrator) on attack graphs. The rewards and transition probabilities are obtained by leveraging the expert knowledge present in the Common Vulnerability Scoring System (CVSS). Our framework identifies an attacker's optimal policy and places countermeasures to ensure that this attack policy is always detected, thus forcing the attacker to use a sub-optimal policy with higher cost.
UR - https://www.scopus.com/pages/publications/85064966125
U2 - 10.1109/ICCNC.2019.8685647
DO - 10.1109/ICCNC.2019.8685647
M3 - Conference Proceeding
AN - SCOPUS:85064966125
T3 - 2019 International Conference on Computing, Networking and Communications, ICNC 2019
SP - 577
EP - 581
BT - 2019 International Conference on Computing, Networking and Communications, ICNC 2019
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2019 International Conference on Computing, Networking and Communications, ICNC 2019
Y2 - 18 February 2019 through 21 February 2019
ER -