Abstract
It has been argued that systems that are comprised of similar components (i.e., a monoculture) are more prone to attacks than a system that exhibits diversity. But it is not currently clear how much diversity is needed and how to leverage the underlying diversity in the design space. In this paper, we present a game theoretic model to analyze strategic attack-defense scenarios as well as present our research and development effort to develop a software tool that facilitates analysis of strategic use of redundancy and diversity techniques for cyber survivability and recoverability by leveraging the developed game theoretic model. The simulator shows the potential of using game theoretic approaches for exploiting diversity for cyber survivability. The game theoretic model illustrates how the concept of the Nash Equilibrium provides a theoretical framework for designing strategic security solutions and how the mixed strategy solution space provides a conceptual basis for defining optimal randomization techniques that can exploit the underlying diversity. The simulator provides capabilities to simulate various attack-defense scenarios, analyze defense tactics, and provide feasible security solutions to help adopt appropriate defense strategies.
Original language | English (US) |
---|---|
Title of host publication | Proceedings of IEEE International Symposium on High Assurance Systems Engineering |
Publisher | IEEE Computer Society |
Pages | 110-113 |
Number of pages | 4 |
Volume | 2016-March |
ISBN (Print) | 9781467399128 |
DOIs | |
State | Published - Mar 1 2016 |
Event | 17th IEEE International Symposium on High Assurance Systems Engineering, HASE 2016 - Orlando, United States Duration: Jan 7 2016 → Jan 9 2016 |
Other
Other | 17th IEEE International Symposium on High Assurance Systems Engineering, HASE 2016 |
---|---|
Country/Territory | United States |
City | Orlando |
Period | 1/7/16 → 1/9/16 |
Keywords
- Cyber-security simulation
- Diversity
- Game Theory
ASJC Scopus subject areas
- Software
- Safety, Risk, Reliability and Quality