[论文解读] Computing Optimal Security Strategies for Interdependent Assets
本文提出了一种新颖的线性规划框架,用于计算相互依赖网络中最佳随机化安全策略,将Stackelberg安全博弈模型扩展至涵盖任意安全配置、级联故障以及外生故障。该方法在真实网络拓扑上实现了更优的防御策略与可扩展性,同时为内生安全决策下的网络韧性提供了理论洞见。
We introduce a novel framework for computing optimal randomized security policies in networked domains which extends previous approaches in several ways. First, we extend previous linear programming techniques for Stackelberg security games to incorporate benefits and costs of arbitrary security configurations on individual assets. Second, we offer a principled model of failure cascades that allows us to capture both the direct and indirect value of assets, and extend this model to capture uncertainty about the structure of the interdependency network. Third, we extend the linear programming formulation to account for exogenous (random) failures in addition to targeted attacks. The goal of our work is two-fold. First, we aim to develop techniques for computing optimal security strategies in realistic settings involving interdependent security. To this end, we evaluate the value of our technical contributions in comparison with previous approaches, and show that our approach yields much better defense policies and scales to realistic graphs. Second, our computational framework enables us to attain theoretical insights about security on networks. As an example, we study how allowing security to be endogenous impacts the relative resilience of different network topologies.
研究动机与目标
- 开发一种计算可扩展的框架,用于在相互依赖网络中计算最优安全策略。
- 将传统Stackelberg安全博弈模型扩展,以包含任意安全配置及其相关成本与收益。
- 对相互依赖网络结构中的级联故障及其影响进行建模与考量。
- 在安全优化框架中同时整合针对性攻击与外生(随机)故障。
- 提供关于内生安全决策如何影响不同网络拓扑下网络韧性的理论洞见。
提出的方法
- 将标准Stackelberg博弈的线性规划公式扩展,以包含具有相关成本与收益的单个资产安全配置。
- 提出一种系统化的级联故障模型,通过相互依赖关系捕捉资产的直接与间接价值。
- 利用概率模型在LP框架内对相互依赖网络结构中的不确定性进行建模。
- 通过将故障概率整合到优化目标中,将模型扩展以包含外生故障,而不仅限于针对性攻击。
- 采用博弈论方法,防御者承诺采用混合策略,攻击者则理性响应以最大化预期损害。
- 采用分解技术,将解法扩展至大规模真实网络图。
实验结果
研究问题
- RQ1在资产具有任意安全配置的相互依赖网络中,如何计算最优安全策略?
- RQ2级联故障对相互依赖资产整体价值的影响是什么?如何在安全优化框架中对此进行建模?
- RQ3相互依赖网络结构中的不确定性如何影响所计算安全策略的鲁棒性?
- RQ4与仅考虑针对性攻击的模型相比,外生故障在多大程度上改变了最优防御策略?
- RQ5将安全决策内生化对不同网络拓扑的韧性有何影响?
主要发现
- 所提出的框架在真实网络拓扑上的防御有效性显著优于以往方法。
- 该模型可高效扩展至大规模图结构,支持在真实世界相互依赖系统中的实际部署。
- 引入级联故障可实现对资产价值的更准确评估,从而支持更明智的安全投资决策。
- 考虑网络结构中的不确定性可提升所计算安全策略的鲁棒性。
- 外生故障可能显著改变最优防御资源配置,凸显了显式建模其影响的必要性。
- 内生安全决策导致不同网络拓扑间韧性出现非平凡差异,其中无标度网络在特定条件下表现出更高脆弱性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。