针对网络化环境中高级持续性威胁的可处理防御
Tractable Defense against Advanced Persistent Threats in Networked Settings
- University of Colorado Colorado Springs(科罗拉多大学科罗拉多斯普林斯分校)
- Politecnico di Torino(都灵理工大学)
机构由 AI 辅助整理,请以论文原文为准。
中文总结 AI 辅助
针对网络化环境中高级持续性威胁(APT)的防御决策难题,提出基于平均场分析的启发式价值函数,在熵最大化假设下实现精确计算,并通过数值实验评估其质量。
中文摘要 AI 辅助
最近,布尔动力系统理论被提出用于研究针对高级持续性威胁(APT)的计算机网络防御决策理论。布尔动力系统自然地捕捉了APT的四个第一性原理要素:攻击的隐蔽性、来自入侵检测系统等自动化系统的有限且含噪信息、攻击者渗透进入网络后的横向移动,以及防御者在任何时刻以系统正常运行时间等资源损失为代价保护部分计算机子集的能力。目前,以计算可处理的方式进行最优/启发式控制是不可能的,因为涌现的价值函数在计算上是不可处理的(相对于网络规模而言)。为解决这一问题,我们提出了一种受平均场分析启发的启发式价值函数。我们证明,在底层状态估计分布最大化熵的假设下,我们提出的启发式方法基于价值函数的精确计算。我们通过熵假设被违反的程度作为参数,数值评估了我们的启发式方法的质量。
英文摘要
Recently, the theory of Boolean Dynamical Systems was proposed to study the decision theory surrounding the defense of computer networks against Advanced Persistent Threats (APTs). Boolean Dynamical Systems naturally capture four first principle primitives of APTs: the stealthy nature of attacks, limited and noisy information from automated systems like intrusion detection systems, lateral movement after the attacker penetrates into the network, and the defender's ability to secure a subset of computers at any time at the loss of resources such as system uptime. Currently, doing optimal/heuristic control in a computationally tractable manner is not possible because the emergent value function is computationally intractable (with respect to the network size). To resolve this, we propose a mean-field analysis inspired heuristic value function. We prove that our proposed heuristic is based on an exact computation of the value function under the assumption that the underlying state estimate distribution maximizes entropy. We numerically evaluate the quality of our heuristic as parameterized by the degree to which the entropy assumptions are violated.