Toward a Theory of Cyber Attacks
Abstract
We provide a general methodology for analyzing defender-attacker based "games" in which we model such games as Markov models and introduce a capacity region to analyze how defensive and adversarial strategies impact security. Such a framework allows us to analyze under what kind of conditions we can prove statements (about an attack objective ) of the form "if the attacker has a time budget , then the probability that the attacker can reach an attack objective is at most ". We are interested in such rigorous cryptographic security guarantees (that describe worst-case guarantees) as these shed light on the requirements of a defender's strategy for preventing more and more the progress of an attack, in terms of the "learning rate" of a defender's strategy. We explain the damage an attacker can achieve by a "containment parameter" describing the maximally reached attack objective within a specific time window.
Keywords
Cite
@article{arxiv.1901.01598,
title = {Toward a Theory of Cyber Attacks},
author = {Saeed Valizadeh and Marten van Dijk},
journal= {arXiv preprint arXiv:1901.01598},
year = {2019}
}
Comments
This work was funded by NSF grant CNS-1413996 "MACS: A Modular Approach to Cloud Security"