[논문 리뷰] When to Invest in Security? Empirical Evidence and a Game-Theoretic Approach for Time-Based Security
이 논문은 보호 시간, 탐지 시간, 반응 시간을 통합하여 최적의 방어 재설정 시점을 결정하는 시간 기반 보안을 위한 게임 이론 모델을 제안한다. VERIS 커뮤니티 데이터베이스에서 수집한 실증 데이터를 활용해 분포를 정의하고, 지ay 함수를 통해 나시 균형 전략을 도출하여, 공격자의 은밀함과 시스템 반응 역학에 따라 방어자가 리셋 시간을 조정함으로써 위험을 최소화해야 한다고 밝힌다.
Games of timing aim to determine the optimal defense against a strategic attacker who has the technical capability to breach a system in a stealthy fashion. Key questions arising are when the attack takes place, and when a defensive move should be initiated to reset the system resource to a known safe state. In our work, we study a more complex scenario called Time-Based Security in which we combine three main notions: protection time, detection time, and reaction time. Protection time represents the amount of time the attacker needs to execute the attack successfully. In other words, protection time represents the inherent resilience of the system against an attack. Detection time is the required time for the defender to detect that the system is compromised. Reaction time is the required time for the defender to reset the defense mechanisms in order to recreate a safe system state. In the first part of the paper, we study the VERIS Community Database (VCDB) and screen other data sources to provide insights into the actual timing of security incidents and responses. While we are able to derive distributions for some of the factors regarding the timing of security breaches, we assess the state-of-the-art regarding the collection of timing-related data as insufficient. In the second part of the paper, we propose a two-player game which captures the outlined Time-Based Security scenario in which both players move according to a periodic strategy. We carefully develop the resulting payoff functions, and provide theorems and numerical results to help the defender to calculate the best time to reset the defense mechanism by considering protection time, detection time, and reaction time.
연구 동기 및 목표
- 실제 보안 사고 및 대응의 시간 데이터를 VERIS 커뮤니티 데이터베이스(VCDB) 및 기타 자료를 활용해 분석한다.
- 보안 침해에서 핵심적인 시간 요소인 보호 시간, 탐지 시간, 반응 시간을 식별하고 모델링한다.
- 은밀한 공격과 방어적 리셋 전략 간의 전략적 시간 조정을 반영한 이중자 게임 이론 프레임워크를 개발한다.
- 정기적인 전략 하에서 방어자와 공격자의 분석적 최적 반응 전략을 유도하고, 나시 균형을 계산한다.
- 방어자가 노출 시간을 최소화하기 위해 보안 메커니즘을 언제 리셋할 것인지에 대한 실질적인 통찰을 제공한다.
제안 방법
- 논문은 방어자와 공격자가 정기적으로 행동하는 이중자 게임을 구성하며, 이동 시간은 보호 시간, 탐지 시간, 반응 시간에 기반한다.
- 공격 및 방어 비용과 성공적 침입 및 방어 리셋의 시점에 기반한 양측의 지급 함수를 정의한다.
- 방어자의 전략은 기대 손실을 최소화하기 위해 최적의 리셋 간격을 선택하는 데 있으며, 공격자는 수익을 극대화하기 위해 공격 시점을 선택한다.
- 비용 파rameter와 시간 임계값을 고려해 양측의 최적 반응 함수를 분석적으로 유도한다.
- 수치 시뮬레이션을 통해 최적 반응을 시각화하고, 이러한 함수의 교차점을 찾음으로써 나시 균형을 식별한다.
- VCDB에서의 실증 데이터를 활용해 악성코드 및 해킹 사고의 탐지 시간 분포를 추정하고, 보호 시간과 반응 시간에 대한 히우리스틱을 제공한다.
실험 결과
연구 질문
- RQ1실제 보안 사고에서 탐지 시간, 보호 시간, 반응 시간의 실제 분포는 무엇인가?
- RQ2보호 시간, 탐지 시간, 반응 시간이 방어 리셋 최적 시점에 어떻게 영향을 미치는가?
- RQ3은밀한 공격자에 대응해 정기적으로 보안 메커니즘을 리셋하는 방어자의 균형 전략은 무엇인가?
- RQ4공격 및 방어 비용의 변화가 최적 방어 조치의 시점에 어떻게 영향을 미치는가?
- RQ5방어자와 공격자의 행동이 정기적인 성격을 띠는 것이 보안 게임의 결과에 어떤 방식으로 영향을 미치는가?
주요 결과
- 분석 결과, 실증 데이터에 따르면 보안 침해의 탐지 시간 평균이 225일 이상으로 나타나, 상당한 은밀한 기간이 존재함을 시사한다.
- VCDB에서의 실증 데이터는 악성코드 및 해킹 사고의 탐지 시간 분포를 측정 가능하게 보여주지만, 데이터의 품질과 일관성은 여전히 제한되어 있다.
- p=3, d=10, r=1, c_k=5, c_D=10, c_A=0.5 조건 하에서 수치 예제에서 나시 균형이 (t_A = 14.9, t_D = 28.9)에 도달함을 확인했다.
- 균형 상태에서 방어자의 최적 리셋 간격은 약 28.9 단위이며, 공격자의 최적 공격 시점은 14.9 단위이다.
- 균형에서 공격자의 최적 반응은 불연속성을 보이지만, 양측 전략의 지급은 거의 동일하여 전략적 동치성을 나타낸다.
- 방어자의 최적 전략은 공격 비용과 방어 비용의 상대적 비율에 따라 달라지며, 방어자의 빠른 반응은 균형을 더 늦은 리셋 시간으로 이동시킨다.
더 나은 연구,지금 바로 시작하세요
논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.
카드 등록 없음 · 무료 플랜 제공
이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.