基于图的Stackelberg安全博弈用于可信6G解构架构
A Graph-Based Stackelberg Security Game for Trustworthy 6G Disaggregated Architecture
浏览论文内容
中文总结 AI 辅助
本文将6G架构解构建模为基于图的Stackelberg安全博弈,通过部署图和攻击图分析接缝的加固与监控策略,发现选择性监控优于完全集成或最大解构。
中文摘要 AI 辅助
开放、云原生和AI赋能的6G架构使得网络功能更易于部署、观察和替换,这些功能通常以独立的软件模块实现。然而,从网络安全的角度来看,每个显式接口也可能创建入口点、信任转移和横向移动路径。本文将架构解构形式化为用于6G系统安全的基于图的Stackelberg设计博弈。部署图指定了候选的6G系统接缝,而依赖架构的有向攻击图则指定了外部可达的功能和多阶段路径。防御者承诺接缝并分配加固和监控;知情的攻击者随后选择路径和努力程度。由于边遍历和规避因素以乘法方式组合,攻击者的路径响应在对数变换后成为最短路径问题。凸努力成本允许共轭表示,并且对于每个固定架构,防御者的控制问题是凸指数上镜程序,可通过路径生成求解。我们推导出架构比较准则、6G系统中AI转换器的阈值(该阈值同时增加可见性和暴露性),以及攻击者进入和绕过创新的比较静态分析。针对RAN、RIC、核心、云和边缘AI功能的风格化标准锚定O-RAN/6G系统的实验表明,完全集成和最大解构通常都不是最佳选择。不受控制的接缝可能增加风险,而有选择地监控和加固的接缝可以改善Stackelberg目标。我们发现,只有当边界的检测和遏制收益超过其增加的攻击机会和协调成本时,边界才是值得的。
英文摘要
Open, cloud-native, and AI-enabled 6G architectures make network functions easier to deploy, observe, and replace, often implemented with separate software modules. However, each explicit interface can also create an entry point, trust transition, and lateral-movement route from a cybersecurity perspective. This paper formulates architectural disaggregation as a graph-based Stackelberg design game for 6G system security. A deployment graph specifies candidate 6G system seams, while an architecture-dependent directed attack graph specifies externally reachable functions and multistage paths. The defender commits to seams and allocates hardening and monitoring; an informed attacker then chooses a path and effort. Because edge traversal and evasion factors compose multiplicatively, the attacker's path response becomes a shortest-path problem after a logarithmic transformation. Convex effort costs admit a conjugate representation, and, for each fixed architecture, the defender's control problem is a convex exponential-epigraph program solvable by path generation. We derive an architecture-comparison criterion, a threshold for AI transducers within 6G systems that jointly add visibility and exposure, and comparative statics for attacker entry and bypass innovation. Experiments with stylized standards-anchored O-RAN/6G systems over RAN, RIC, core, cloud, and edge-AI functions show that neither full integration nor maximal disaggregation is generally best. Uncontrolled seams can increase risk, whereas selectively monitored and hardened seams can improve the Stackelberg objective. We find a boundary is worthwhile only when its detection and containment gains exceed its added attack opportunities and coordination cost.
发表机构
- AI Innovation Institute, Stony Brook University(石溪大学人工智能创新研究所)
- University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)
机构由 AI 辅助整理,请以论文原文为准。