Skip to main content
QUICK REVIEW

[論文レビュー] When to Invest in Security? Empirical Evidence and a Game-Theoretic Approach for Time-Based Security

Sadegh Farhang, Jens Großklags|arXiv (Cornell University)|Jun 1, 2017
Information and Cyber Security参考文献 18被引用数 5
ひとこと要約

本稿は、保護時間、検出時間、反応時間を統合して最適な防御リセットタイミングを決定する、時間ベースのセキュリティのためのゲーム理論的モデルを提案する。実世界のデータをVERISコミュニティデータベース(VCDB)から得て、分布を特定し、報酬関数を通じてナッシュ均衡戦略を導出する。防衛者は攻撃者の隠密性とシステムの応答ダイナミクスに基づいてリセットタイミングを調整することで、リスクを最小化すべきであることを示している。

ABSTRACT

Games of timing aim to determine the optimal defense against a strategic attacker who has the technical capability to breach a system in a stealthy fashion. Key questions arising are when the attack takes place, and when a defensive move should be initiated to reset the system resource to a known safe state. In our work, we study a more complex scenario called Time-Based Security in which we combine three main notions: protection time, detection time, and reaction time. Protection time represents the amount of time the attacker needs to execute the attack successfully. In other words, protection time represents the inherent resilience of the system against an attack. Detection time is the required time for the defender to detect that the system is compromised. Reaction time is the required time for the defender to reset the defense mechanisms in order to recreate a safe system state. In the first part of the paper, we study the VERIS Community Database (VCDB) and screen other data sources to provide insights into the actual timing of security incidents and responses. While we are able to derive distributions for some of the factors regarding the timing of security breaches, we assess the state-of-the-art regarding the collection of timing-related data as insufficient. In the second part of the paper, we propose a two-player game which captures the outlined Time-Based Security scenario in which both players move according to a periodic strategy. We carefully develop the resulting payoff functions, and provide theorems and numerical results to help the defender to calculate the best time to reset the defense mechanism by considering protection time, detection time, and reaction time.

研究の動機と目的

  • 実世界のタイミングデータを、VERISコミュニティデータベース(VCDB)およびその他の出典を用いて、セキュリティインシデントとその対応の分析を目的とする。
  • セキュリティ侵害における主要な時間的要因、すなわち保護時間、検出時間、反応時間を特定し、モデル化することを目的とする。
  • スティール系攻撃と防御的リセットの戦略的タイミングを捉える2プレーヤーのゲーム理論的フレームワークを構築することを目的とする。
  • 定期的戦略の下で、防衛者と攻撃者の最適反応戦略を解析的に導出し、ナッシュ均衡を計算することを目的とする。
  • 防衛者が露出リスクを最小化するために、いつセキュリティメカニズムをリセットすべきかという実務的インサイトを提供することを目的とする。

提案手法

  • 本稿は、防衛者と攻撃者が周期的に行動する2プレーヤーのゲームを構築し、行動のタイミングを保護時間、検出時間、反応時間に基づく。
  • 攻撃と防御のコスト、および成功した侵害や防御的リセットのタイミングに基づいて、両プレーヤーの報酬関数を定義する。
  • 防衛者の戦略は、期待損失を最小化するための最適リセットインターバルの選択を含む。一方、攻撃者は報酬を最大化するための攻撃タイミングを選択する。
  • コストパラメータと時間閾値を考慮して、両プレーヤーの最適反応関数を解析的に導出する。
  • 数値シミュレーションにより、最適反応関数の交点を特定することで、ナッシュ均衡を可視化する。
  • VCDBからの実証データを用いて、マルウェアおよびハッキングインシデントの検出時間の分布を推定し、保護時間および反応時間のヒューリスティクスを支援する。

実験結果

リサーチクエスチョン

  • RQ1実際のセキュリティインシデントにおいて、検出時間、保護時間、反応時間の分布はどのようなものか?
  • RQ2保護時間、検出時間、反応時間が、防御的リセットの最適タイミングにどのように影響を与えるか?
  • RQ3スティール系攻撃に応じて定期的にセキュリティメカニズムをリセットする防衛者の均衡戦略は何か?
  • RQ4攻撃と防御のコストが変化すると、最適な防御行動のタイミングにどのような影響を与えるか?
  • RQ5防衛者と攻撃者の行動が周期的であるという性質は、セキュリティゲームの結果にどのように影響を与えるか?

主な発見

  • 分析により、実世界のデータにおいて、セキュリティ侵害の検出時間の平均が225日以上にのぼることを明らかにした。これは、顕著な隠密期間が存在することを示している。
  • VCDBからの実証データは、マルウェアおよびハッキングインシデントの検出時間に測定可能な分布が存在することを示しているが、データの質と一貫性には限界がある。
  • p=3, d=10, r=1, c_k=5, c_D=10, c_A=0.5 の数値例において、ナッシュ均衡が (t_A = 14.9, t_D = 28.9) に存在することが同定された。
  • 均衡状態では、防衛者の最適リセットインターバルは約28.9時間単位であり、攻撃者の最良攻撃タイミングは14.9単位である。
  • 均衡点において、攻撃者の最適反応は不連続性を示すが、両戦略の報酬はほぼ同等であり、戦略的同等性が成立している。
  • 防衛者の最適戦略は、攻撃と防御の相対的コストに依存しており、防衛者の応答が速いほど、均衡のリセットタイミングは後ろにずれる。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。