arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.36485cs.GTcs.CRcs.SYeess.SY

从侦察到响应:现代企业攻击中的定量风险参数化与博弈论遏制

From Reconnaissance to Response: Quantitative Risk Parameterization and Game Theoretic Containment in Modern Enterprise Attack

发表机构Shadeeb工程实验室研究部 · 卡皮托尔理工大学工程学院
查看机构详情
  • Research Division, Shadeeb Engineering Lab(Shadeeb工程实验室研究部)
  • Capitol Technology University, Department of Engineering(卡皮托尔理工大学工程学院)

机构由 AI 辅助整理,请以论文原文为准。

Shadeeb Hossain

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出一种集成决策引擎,将定量风险参数化与博弈论相结合,实现企业攻击的亚分钟级自动化遏制,并在真实事件数据上验证了有效性。

中文摘要 AI 辅助

现代安全运营中心因手动事件响应延迟而陷入困境,使攻击者能够在早期侦察阶段沿网络杀伤链推进。虽然经典博弈论防御模型优化了战略资源分配,但它们依赖静态效用矩阵,无法适应动态遥测数据。本文提出一个集成的、指标驱动的决策引擎,将定量风险参数化与连续自动化响应时间相衔接。通用漏洞评分系统的可利用性参数被映射为攻击者成功概率,并通过信息风险因素分析蒙特卡洛模拟评估防御者日志分布。实时SIEM日志流被建模为泊松过程到达率,通过序贯贝叶斯滤波动态更新防御者后验威胁信念。通过将交互建模为动态贝叶斯Stackelberg博弈,推导出闭式阈值,其中预期未缓解风险超过主动遏制成本。基于2023年MGM Resorts和Caesars Entertainment网络事件的经验数据进行参数化,仿真结果表明,该引擎抑制瞬态背景噪声,并在对抗性探测的几秒内触发自动化SOAR网络隔离。多参数敏感性分析证实,决策边界动态适应实时边界漏洞,为亚分钟级自动化威胁遏制提供了控制理论基础。

英文摘要

Modern Security Operations Centers struggle with delayed manual incident response, enabling adversaries to advance through the Cyber Kill Chain during early stage reconnaissance. While classical game theoretic defense models optimize strategic resource allocation, they rely on static utility matrices that fail to adapt to dynamic telemetry. This paper presents an integrated, metrics driven decision engine that bridges quantitative risk parameterization and continuous automated response time. Common Vulnerability Scoring Systems exploitability parameters are mapped to attacker success probabilities and evaluate defender log distributions via Factor Analysis of Information Risk Monte Carlo simulations. Real time SIEM logs streams are modeled as Poisson process arrival rates, dynamically updating defender posterior threat belief through sequential Bayesian filtering. A closed form threshold is derived by framing the interaction as a dynamic Bayesian Stackelberg game, where the expected unmitigated risk exceeds proactive containment cost. Parameterized against empirical data from the 2023 MGM Resorts and Caesars Entertainment cyber incident, simulation results demonstrate that the engine suppresses transient background noise while triggering automated SOAR network isolation within seconds of adversarial probing. Multi parameter sensitivity analysis confirms that the decision boundary dynamically adjusts to live perimeter vulnerability, offering a control theoretic foundation for sub minute automated threat containment.

补充信息

↑