Asymptotic Security using Bayesian Defense Mechanism with Application to Cyber Deception
2024 (English)In: IEEE Transactions on Automatic Control, ISSN 0018-9286, E-ISSN 1558-2523, Vol. 69, no 8, p. 5004-5019Article in journal (Refereed) Published
Abstract [en]
This paper addresses the question whether model knowledge can guide a defender to appropriate decisions, or not, when an attacker intrudes into control systems. The model-based defense scheme considered in this study, namely Bayesian defense mechanism, chooses reasonable reactions through observation of the system's behavior using models of the system's stochastic dynamics, the vulnerability to be exploited, and the attacker's objective. On the other hand, rational attackers take deceptive strategies for misleading the defender into making inappropriate decisions. In this paper, their dynamic decision making is formulated as a stochastic signaling game. It is shown that the belief of the true scenario has a limit in a stochastic sense at an equilibrium based on martingale analysis. This fact implies that there are only two possible cases: the defender asymptotically detects the attack with a firm belief, or the attacker takes actions such that the system's behavior becomes nominal after a finite number of time steps. Consequently, if different scenarios result in different stochastic behaviors, the Bayesian defense mechanism guarantees the system to be secure in an asymptotic manner provided that effective countermeasures are implemented. As an application of the finding, a defensive deception utilizing asymmetric recognition of vulnerabilities exploited by the attacker is analyzed. It is shown that the attacker possibly withdraws even if the defender is unaware of the exploited vulnerabilities, as long as the defender's unawareness is concealed by the defensive deception.
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE) , 2024. Vol. 69, no 8, p. 5004-5019
Keywords [en]
Analytical models, Bayes methods, Bayesian methods, Behavioral sciences, Control systems, game theory, Games, intrusion detection, Numerical models, security, Security, stochastic systems
National Category
Control Engineering
Identifiers
URN: urn:nbn:se:kth:diva-350177DOI: 10.1109/TAC.2023.3340978ISI: 001293894600056Scopus ID: 2-s2.0-85179806383OAI: oai:DiVA.org:kth-350177DiVA, id: diva2:1883158
Note
QC 20240709
2024-07-092024-07-092025-01-31Bibliographically approved