• DocumentCode
    1963253
  • Title

    A Game Theoretical Attack-Defense Model Oriented to Network Security Risk Assessment

  • Author

    Wei He ; Chunhe Xia ; Haiquan Wang ; Cheng Zhang ; Yi Ji

  • Author_Institution
    Sch. of Comput. Sci. & Eng., Beihang Univ., Beijing
  • Volume
    3
  • fYear
    2008
  • fDate
    12-14 Dec. 2008
  • Firstpage
    1097
  • Lastpage
    1103
  • Abstract
    How to quantify the threat probability in network security risk assessment is an important problem to be solved. Most of the existing methods tend to consider the attacker and defender separately. However, the decision to perform the attack is a trade-off between the gain from a successful attack and the possible consequences of detection; meanwhile, the defenderpsilas security strategy depends mostly on the knowledge of the intentions of the attacker. Therefore, ignoring the connections between the attacker and defenderpsilas decisions does not correspond to reality. Game theory is the study of the ways in which strategic interactions among rational players produce outcomes with respect to the utilities of those players. In this paper, a novel game theoretical attack-defense model (GTADM) which quantifies the probability of threats is proposed in order to construct a risk assessment framework. According to the cost-benefit analysis, we define the method of formulating the payoff matrix; the equilibrium of the model is also analyzed. In the end, a simple scenario is presented to illustrate the usage of GTADM in the risk assessment framework to show its efficiency.
  • Keywords
    computer networks; game theory; probability; risk management; telecommunication security; cost-benefit analysis; game theoretical attack-defense model; network security risk assessment; payoff matrix; probability; Application software; Computer networks; Computer science; Computer security; Game theory; Information security; Intrusion detection; Risk management; Software engineering; Stochastic processes; GTADM; Game Theory; framework; risk assessment;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Science and Software Engineering, 2008 International Conference on
  • Conference_Location
    Wuhan, Hubei
  • Print_ISBN
    978-0-7695-3336-0
  • Type

    conf

  • DOI
    10.1109/CSSE.2008.1062
  • Filename
    4722533