Skip to main content
QUICK REVIEW

[论文解读] Flip the Cloud: Cyber-Physical Signaling Games in the Presence of Advanced Persistent Threats

Jeffrey Pawlick, Sadegh Farhang|arXiv (Cornell University)|Jul 2, 2015
Smart Grid Security and Resilience参考文献 7被引用 10
一句话总结

本文提出了一种新颖的博弈论框架,用于在高级持续性威胁(APTs)下保护云连接的网络物理系统。该框架结合了云与设备之间的信号博弈以及云被攻破的FlipIt博弈,引入了一种新的均衡概念——整体均衡(Gestalt equilibrium),以捕捉信任决策与控制争夺之间的相互依赖性。主要贡献在于提出了一套统一的解决方案,用于判断设备在何种情况下应信任或拒绝来自可能被攻破的云的指令,该方案在无人车辆控制场景中得到验证。

ABSTRACT

Access to the cloud has the potential to provide scalable and cost effective enhancements of physical devices through the use of advanced computational processes run on apparently limitless cyber infrastructure. On the other hand, cyber-physical systems and cloud-controlled devices are subject to numerous design challenges; among them is that of security. In particular, recent advances in adversary technology pose Advanced Persistent Threats (APTs) which may stealthily and completely compromise a cyber system. In this paper, we design a framework for the security of cloud-based systems that specifies when a device should trust commands from the cloud which may be compromised. This interaction can be considered as a game between three players: a cloud defender/administrator, an attacker, and a device. We use traditional signaling games to model the interaction between the cloud and the device, and we use the recently proposed FlipIt game to model the struggle between the defender and attacker for control of the cloud. Because attacks upon the cloud can occur without knowledge of the defender, we assume that strategies in both games are picked according to prior commitment. This framework requires a new equilibrium concept, which we call Gestalt Equilibrium, a fixed-point that expresses the interdependence of the signaling and FlipIt games. We present the solution to this fixed-point problem under certain parameter cases, and illustrate an example application of cloud control of an unmanned vehicle. Our results contribute to the growing understanding of cloud-controlled systems.

研究动机与目标

  • 解决云可能被高级持续性威胁(APTs)无声攻破的云连接网络物理系统安全挑战。
  • 建模设备在信任或拒绝来自潜在恶意云管理员的指令时的决策行为。
  • 开发一个统一的博弈论模型,将云被攻破的动态过程(FlipIt博弈)与设备信任信号(信号博弈)相结合。
  • 定义一种新的均衡概念——整体均衡(Gestalt equilibrium),以解决在先验承诺条件下两个博弈之间的循环依赖问题。
  • 通过无人车辆控制的案例研究,展示该框架的适用性。

提出的方法

  • 使用FlipIt博弈建模云被攻破的过程,其中防御者与攻击者交替以一定成本获得对云的控制权。
  • 使用信号博弈建模云与设备之间的交互,设备根据观察到的信号选择是否信任云的指令。
  • 在先验承诺下整合两个博弈,假设策略选择时彼此未知,从而产生循环依赖。
  • 将整体均衡定义为一个固定点解,将信号博弈的均衡策略映射到FlipIt博弈的控制概率上。
  • 使用差异阈值τ来分类云指令:若其与设备自身控制信号的偏差显著,则判定为“高风险”。
  • 将该框架应用于无人车辆动力学的线性化模型,比较在云信任控制与自主控制下的性能表现。

实验结果

研究问题

  • RQ1在何种条件下,设备最优地选择信任或拒绝可能被APT攻破的云所发出的指令?
  • RQ2FlipIt博弈中防御者与攻击者的策略如何影响云与设备之间信号博弈的均衡?
  • RQ3当策略预先承诺时,为解决信号博弈与FlipIt博弈之间的循环依赖,需要何种均衡概念?
  • RQ4用于高风险指令检测的阈值τ如何影响设备的信任决策与系统稳定性?
  • RQ5所提出的框架能否应用于真实世界的网络物理系统(如受云控制的无人车辆)?

主要发现

  • 整体均衡被定义为一个固定点解,将信号博弈的均衡策略与FlipIt博弈中的控制概率相联系,从而解决了两个博弈之间的相互依赖性。
  • 在案例研究中,设备通过依赖自身的机载控制系统,拒绝偏离阈值τ的高风险云指令,从而获得收益。
  • 在云控制与自主控制两种情况下,无人车辆的闭环动力学均保持稳定,且在云被攻破时,自主控制展现出更强的鲁棒性。
  • 该框架使设备能够智能地在云访问带来的性能增益与恶意指令风险之间取得平衡,尤其在隐蔽的APTs攻击下表现突出。
  • 在特定参数范围内,解表明设备的最优策略取决于攻击成本与恢复成本的相对大小,以及指令偏差的阈值τ。
  • 本文建立了整体均衡存在且可计算的条件,为未来基于学习的收敛算法奠定了基础。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。