An optimal defensive deception framework for the container‐based cloud with deep reinforcement learning. (27th November 2021)
- Record Type:
- Journal Article
- Title:
- An optimal defensive deception framework for the container‐based cloud with deep reinforcement learning. (27th November 2021)
- Main Title:
- An optimal defensive deception framework for the container‐based cloud with deep reinforcement learning
- Authors:
- Li, Huanruo
Guo, Yunfei
Sun, Penghao
Wang, Yawen
Huo, Shumin - Abstract:
- Abstract: Defensive deception is emerging to reveal stealthy attackers by presenting intentionally falsified information. To implement it in the increasing dynamic and complex cloud, major concerns remain about the establishment of precise adversarial model and the adaptive decoy placement strategy. However, existing studies do not fulfil both issues because of (1) the insufficiency on extracting potential threats in virtualisation technique, (2) the inadequate learning on the agility of target environment, and (3) the lack of measurement for placement strategy. In this study, an optimal defensive deception framework is proposed for the container based‐cloud. The System Risk Graph (SRG) is formalised to depict an updatable adversarial model with the automatic orchestration platform. Afterwards, a Deep Reinforcement Learning (DRL) model is trained based on SRG. The well‐trained DRL agent generates optimal placement strategies for the orchestration platform to distribute decoys and deceptive routings. Lastly, the coefficient of deception, C, is defined to evaluate the effectiveness of placement strategy. Simulation results show that the proposed method increases C by 30.22%, and increase the detection ratio on the random walker attacker and persistent attacker by 30.69% and 51.10%, respectively.
- Is Part Of:
- IET information security. Volume 16:Number 3(2022)
- Journal:
- IET information security
- Issue:
- Volume 16:Number 3(2022)
- Issue Display:
- Volume 16, Issue 3 (2022)
- Year:
- 2022
- Volume:
- 16
- Issue:
- 3
- Issue Sort Value:
- 2022-0016-0003-0000
- Page Start:
- 178
- Page End:
- 192
- Publication Date:
- 2021-11-27
- Subjects:
- artificial intelligence -- cloud security -- computer network security -- cyber deception defence -- decoy placement strategy -- deep reinforcement learning
Computer security -- Periodicals
Cryptography -- Periodicals
Computer networks -- Security measures -- Periodicals
Database security -- Periodicals
005.8 - Journal URLs:
- https://ietresearch.onlinelibrary.wiley.com/journal/17518717 ↗
http://digital-library.theiet.org/content/journals/iet-ifs ↗
http://www.ietdl.org/IET-IFS ↗
http://www.theiet.org/ ↗ - DOI:
- 10.1049/ise2.12050 ↗
- Languages:
- English
- ISSNs:
- 1751-8709
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4363.252660
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 21226.xml