• DocumentCode
    2009944
  • Title

    RRE: A game-theoretic intrusion Response and Recovery Engine for process control applications

  • Author

    Sanders, William H.

  • Author_Institution
    Coordinated Sci. Lab., Univ. of Illinois at Urbana-Champaign, Urbana, IL
  • fYear
    2009
  • fDate
    March 27 2009-April 30 2009
  • Firstpage
    1
  • Lastpage
    1
  • Abstract
    Preserving the availability and integrity of process control systems in the face of fast-spreading intrusions requires advances not only in detection algorithms, but also in automated response techniques. In this presentation, we propose a new approach to automated response called the response and recovery engine (RRE). Our engine employs a game-theoretic response strategy against adversaries modeled as opponents in a two-player Stackelberg stochastic game. RRE applies attack-response trees to analyze undesired security events and their countermeasures using Boolean logic to combine lower-level attack consequences. In addition, RRE accounts for uncertainties in intrusion detection alert notications. RRE then chooses optimal response actions by solving a partially observable competitive Markov decision process that is automatically derived from attack-response trees. Experimental results show that RRE, using Snort´s alerts, can protect large networks for which attack-response trees have more than 500 nodes.
  • Keywords
    Boolean functions; Markov processes; game theory; security of data; trees (mathematics); Boolean logic; RRE; Snort alerts; attack-response trees; automated response techniques; competitive Markov decision process; fast-spreading intrusions; game-theoretic intrusion response; process control systems; response-and-recovery engine; two-player Stackelberg stochastic game; Boolean functions; Detection algorithms; Engines; Face detection; Intrusion detection; Process control; Protection; Security; Stochastic processes; Uncertainty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Critical Infrastructures, 2009. CRIS 2009. Fourth International Conference on
  • Conference_Location
    Linkoping
  • Print_ISBN
    978-1-4244-4636-0
  • Type

    conf

  • DOI
    10.1109/CRIS.2009.5071485
  • Filename
    5071485