English

Toward a Theory of Cyber Attacks

Cryptography and Security 2019-01-08 v1 Computer Science and Game Theory

Abstract

We provide a general methodology for analyzing defender-attacker based "games" in which we model such games as Markov models and introduce a capacity region to analyze how defensive and adversarial strategies impact security. Such a framework allows us to analyze under what kind of conditions we can prove statements (about an attack objective kk) of the form "if the attacker has a time budget TbudT_{bud}, then the probability that the attacker can reach an attack objective k\geq k is at most poly(Tbud)negl(k)poly(T_{bud})negl(k)". We are interested in such rigorous cryptographic security guarantees (that describe worst-case guarantees) as these shed light on the requirements of a defender's strategy for preventing more and more the progress of an attack, in terms of the "learning rate" of a defender's strategy. We explain the damage an attacker can achieve by a "containment parameter" describing the maximally reached attack objective within a specific time window.

Keywords

Cite

@article{arxiv.1901.01598,
  title  = {Toward a Theory of Cyber Attacks},
  author = {Saeed Valizadeh and Marten van Dijk},
  journal= {arXiv preprint arXiv:1901.01598},
  year   = {2019}
}

Comments

This work was funded by NSF grant CNS-1413996 "MACS: A Modular Approach to Cloud Security"

R2 v1 2026-06-23T07:04:14.350Z