Game Theory Meets Information Security Management

نویسندگان

  • Andrew Fielder
  • Emmanouil A. Panaousis
  • Pasquale Malacaria
  • Chris Hankin
  • Fabrizio Smeraldi
چکیده

This work addresses the challenge “how do we make better security decisions?” and it develops techniques to support human decision making and algorithms which enable well-founded cyber security decisions to be made. In this paper we propose a game theoretic model which optimally allocates cyber security resources such as administrators’ time across different tasks. We first model the interactions between an omnipresent attacker and a team of system administrators seen as the defender, and we have derived the mixed Nash Equilibria (NE) in such games. We have formulated general-sum games that represent our cyber security environment, and we have proven that the defender’s Nash strategy is also minimax. This result guarantees that independently from the attacker’s strategy the defender’s solution is optimal. We also propose Singular Value Decomposition (SVD) as an efficient technique to compute approximate equilibria in our games. By implementing and evaluating a minimax solver with SVD, we have thoroughly investigated the improvement that Nash defense introduces compared to other strategies chosen by common sense decision algorithms. Our key finding is that a particular NE, which we call weighted NE, provides the most effective defense strategy. In order to validate this model we have used real-life statistics from Hackmageddon, the Verizon 2013 Data Breach Investigation report, and the Ponemon report of 2011. We finally compare the game theoretic defense method with a method which implements a stochastic optimization algorithm.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Interdependent Security Game Design over Constrained Linear Influence Networks

In today's highly interconnected networks, security of the entities are often interdependent. This means security decisions of the agents are not only influenced by their own costs and constraints, but also are affected by their neighbors’ decisions. Game theory provides a rich set of tools to analyze such influence networks. In the game model, players try to maximize their utilities through se...

متن کامل

Policy Capacity Meets Politics; Comment on “Health Reform Requires Policy Capacity”

It is difficult to disagree with the general argument that successful health reform requires a significant degree of policy capacity or that all players in the policy game need to move beyond self-interested advocacy. However, an overly broad definition of policy capacity is a problem. More important perhaps, health reform inevitably requires not just policy capacity but political leadership an...

متن کامل

Improvising Routing and Security in MANET with Game Theory

Data throughput is spectacularly increasing by using MIMO and CR utilizes the existing wireless spectrum opportunistically. The emerging technologies tackle the problem of limited available spectrum. Combination of ad hoc networks with MIMO and cognitive radios greatly ready to merge with the networking and communication technology of decentralized architecture. Adhoc in nature the networks mee...

متن کامل

Application of Stochastic Optimal Control, Game Theory and Information Fusion for Cyber Defense Modelling

The present paper addresses an effective cyber defense model by applying information fusion based game theoretical approaches‎. ‎In the present paper, we are trying to improve previous models by applying stochastic optimal control and robust optimization techniques‎. ‎Jump processes are applied to model different and complex situations in cyber games‎. ‎Applying jump processes we propose some m...

متن کامل

The competitive advantages analysis of pharmaceutical industry strategic behaviors by game theory

Game theory is the study of mathematical models and cooperation between intelligent rational decision-makers. This paper provides a flexible model to calculate pay-off matrix based on several importance factors. This model is adapted by cooperative game and developed for some competitive advantages sections in pharmaceutical industry. An optimum solution is derived by considering Nash equilibri...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2014