[论文解读] When to Invest in Security? Empirical Evidence and a Game-Theoretic Approach for Time-Based Security
本文提出了一种基于时间的防御安全博弈论模型,整合了保护时间、检测时间和响应时间,以确定最优的防御重置时机。该模型基于VERIS社区数据库的实证数据,确定时间分布,并通过收益函数推导出纳什均衡策略,表明防御者应根据攻击者隐蔽性及系统响应动态来调整重置时机,以最小化风险。
Games of timing aim to determine the optimal defense against a strategic attacker who has the technical capability to breach a system in a stealthy fashion. Key questions arising are when the attack takes place, and when a defensive move should be initiated to reset the system resource to a known safe state. In our work, we study a more complex scenario called Time-Based Security in which we combine three main notions: protection time, detection time, and reaction time. Protection time represents the amount of time the attacker needs to execute the attack successfully. In other words, protection time represents the inherent resilience of the system against an attack. Detection time is the required time for the defender to detect that the system is compromised. Reaction time is the required time for the defender to reset the defense mechanisms in order to recreate a safe system state. In the first part of the paper, we study the VERIS Community Database (VCDB) and screen other data sources to provide insights into the actual timing of security incidents and responses. While we are able to derive distributions for some of the factors regarding the timing of security breaches, we assess the state-of-the-art regarding the collection of timing-related data as insufficient. In the second part of the paper, we propose a two-player game which captures the outlined Time-Based Security scenario in which both players move according to a periodic strategy. We carefully develop the resulting payoff functions, and provide theorems and numerical results to help the defender to calculate the best time to reset the defense mechanism by considering protection time, detection time, and reaction time.
研究动机与目标
- 利用VERIS社区数据库(VCDB)及其他来源,分析真实世界的安全事件与响应的时间数据。
- 识别并建模安全漏洞中的关键时间因素——保护时间、检测时间和响应时间。
- 构建一个双人博弈论框架,以捕捉隐蔽攻击与防御重置中的策略性时间行为。
- 在周期性策略下,推导防御者与攻击者的最佳响应策略,并计算纳什均衡。
- 为防御者提供可操作的见解,明确何时重置安全机制以最小化暴露时间。
提出的方法
- 本文构建了一个双人博弈模型,防御者与攻击者均以周期性方式行动,其行动时机基于保护时间、检测时间和响应时间。
- 基于攻击与防御的成本,以及成功入侵与防御重置的时间点,定义双方的收益函数。
- 防御者的策略涉及选择最优重置间隔以最小化预期损失,而攻击者则选择攻击时机以最大化收益。
- 在成本参数与时间阈值的约束下,解析推导出双方的最佳响应函数。
- 通过数值模拟可视化最佳响应,并通过寻找这些函数的交点来识别纳什均衡。
- 利用VCDB的实证数据,估算针对恶意软件与入侵事件的检测时间分布,并为保护时间与响应时间提供启发式参数。
实验结果
研究问题
- RQ1真实安全事件中,检测时间、保护时间与响应时间的实际分布是什么?
- RQ2保护时间、检测时间与响应时间如何共同影响防御重置的最优时机?
- RQ3对于周期性重置安全机制的防御者而言,其在面对隐蔽攻击时的均衡策略是什么?
- RQ4攻击与防御成本的变化如何影响最优防御行动的时机?
- RQ5防御者与攻击者行动的周期性特征如何塑造安全博弈的结果?
主要发现
- 分析表明,真实世界数据中安全漏洞的检测时间平均超过225天,表明存在显著的隐蔽期。
- VCDB的实证数据表明,恶意软件与入侵事件的检测时间存在可测量的分布,但数据质量和一致性仍有限。
- 在p=3,d=10,r=1,c_k=5,c_D=10,c_A=0.5的数值示例中,模型识别出纳什均衡点为(t_A = 14.9, t_D = 28.9)。
- 在均衡状态下,防御者的最优重置间隔约为28.9个时间单位,而攻击者最佳攻击时机为14.9个单位。
- 攻击者最佳响应在均衡点处表现出不连续性,但双方策略的收益几乎相等,表明存在策略等价性。
- 防御者的最优策略取决于攻击与防御成本的相对大小,防御响应越快,均衡重置时间越靠后。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。