Probabilistic modelling of deception-based security framework using markov decision process. Issue 115 (April 2022)
- Record Type:
- Journal Article
- Title:
- Probabilistic modelling of deception-based security framework using markov decision process. Issue 115 (April 2022)
- Main Title:
- Probabilistic modelling of deception-based security framework using markov decision process
- Authors:
- Haseeb, Junaid
Malik, Saif Ur Rehman
Mansoori, Masood
Welch, Ian - Abstract:
- Highlights: A deception-based security framework to plan and integrate deception. A model to understand attackers behaviours on failed actions. Quantification metrics to measure attackers and defenders performance. IoT attacks are modelled as MDP and probabilistic properties verified using PRISM. Abstract: Existing studies using deception are ad-hoc attempts and few theoretical models have been designed to plan and integrate deception. We theorise that a pre-planning stage should be a fundamental part to obtain information about the attackers' behaviours and the attack process by analysing known attacks. This will help plan and take defence actions by actively interacting with the attackers and predicting their actions using a probabilistic approach. This paper proposes a framework that provides a theoretical understanding to plan and integrate deception systematically and strategically. We also present probabilistic modelling to predict attack actions by formalising a real case of attacks captured on simulated Internet of Things devices as an Markov Decision Process (MDP) and verifying related properties using Probabilistic Symbolic Model Checker (PRISM). MDP's properties verification results reveal that the associated cost for defence actions can be decreased by successfully predicting attackers' probable actions. Moreover, we identify several quantification metrics (e.g. cost, reward, trust, incentive and penalty) to evaluate the performance of actions performed byHighlights: A deception-based security framework to plan and integrate deception. A model to understand attackers behaviours on failed actions. Quantification metrics to measure attackers and defenders performance. IoT attacks are modelled as MDP and probabilistic properties verified using PRISM. Abstract: Existing studies using deception are ad-hoc attempts and few theoretical models have been designed to plan and integrate deception. We theorise that a pre-planning stage should be a fundamental part to obtain information about the attackers' behaviours and the attack process by analysing known attacks. This will help plan and take defence actions by actively interacting with the attackers and predicting their actions using a probabilistic approach. This paper proposes a framework that provides a theoretical understanding to plan and integrate deception systematically and strategically. We also present probabilistic modelling to predict attack actions by formalising a real case of attacks captured on simulated Internet of Things devices as an Markov Decision Process (MDP) and verifying related properties using Probabilistic Symbolic Model Checker (PRISM). MDP's properties verification results reveal that the associated cost for defence actions can be decreased by successfully predicting attackers' probable actions. Moreover, we identify several quantification metrics (e.g. cost, reward, trust, incentive and penalty) to evaluate the performance of actions performed by attackers and defenders. … (more)
- Is Part Of:
- Computers & security. Issue 115(2022)
- Journal:
- Computers & security
- Issue:
- Issue 115(2022)
- Issue Display:
- Volume 115, Issue 115 (2022)
- Year:
- 2022
- Volume:
- 115
- Issue:
- 115
- Issue Sort Value:
- 2022-0115-0115-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-04
- Subjects:
- Deception -- Security framework -- Probabilistic model checking -- IoT attacks -- Markov decision process
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102599 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 20856.xml