...
首页> 外文期刊>IEEE Journal on Selected Areas in Communications >Cloud Storage Defense Against Advanced Persistent Threats: A Prospect Theoretic Study
【24h】

Cloud Storage Defense Against Advanced Persistent Threats: A Prospect Theoretic Study

机译:针对高级持久性威胁的云存储防御:前景理论研究

获取原文
获取原文并翻译 | 示例
           

摘要

Cloud storage is vulnerable to advanced persistent threats (APTs), in which an attacker launches stealthy, continuous, and targeted attacks on storage devices. In this paper, prospect theory (PT) is applied to formulate the interaction between the defender of a cloud storage system and an APT attacker who makes subjective decisions that sometimes deviate from the results of expected utility theory, which is a basis of traditional game theory. In the PT-based cloud storage defense game with pure strategy, the defender chooses a scan interval for each storage device and the subjective APT attacker chooses his or her interval of attack against each device. A mixed-strategy subjective storage defense game is also investigated, in which each subjective defender and APT attacker acts under uncertainty about the action of its opponent. The Nash equilibria (NEs) of both games are derived, showing that the subjective view of an APT attacker can improve the utility of the defender. A Q-learning-based APT defense scheme that the storage defender can apply without being aware of the APT attack model or the subjectivity model of the attacker in the dynamic APT defense game is also proposed. Simulation results show that the proposed defense scheme suppresses the attack motivation of subjective APT attackers and improves the utility of the defender, compared with the benchmark greedy defense strategy.
机译:云存储易受高级持久性威胁(APT)的攻击,攻击者在这种持久性威胁中对存储设备发起隐匿,连续和针对性的攻击。本文采用前景理论(PT)来制定云存储系统的防御者与APT攻击者之间的交互关系,后者做出的主观决策有时会偏离预期效用理论的结果,而后者是传统博弈论的基础。在具有纯策略的基于PT的云存储防御游戏中,防御者为每个存储设备选择扫描间隔,而主观APT攻击者则为每个设备选择攻击间隔。还研究了混合策略的主观存储防御游戏,其中每个主观防御者和APT攻击者在不确定其对手行动的情况下行动。得出了两场比赛的纳什均衡(NE),这表明APT攻击者的主观观点可以提高防御者的效用。还提出了一种基于Q学习的APT防御方案,存储防御者可以在动态APT防御游戏中不了解APT攻击模型或攻击者的主观模型的情况下应用。仿真结果表明,与基准贪婪防御策略相比,该防御方案能够抑制主观APT攻击者的攻击动机,提高防御者的效用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号