A Game-Theoretical Approach for Finding Optimal Strategies in a Botnet Defense Model
نویسندگان
چکیده
Botnets are networks of computers infected with malicious programs that allow cybercriminals/botnet herders to control the infected machines remotely without the user’s knowledge. In many cases, botnet herders are motivated by economic incentives and try to significantly profit from illegal botnet activity while causing significant economic damage to society. To analyze the economic aspects of botnet activity and suggest feasible defensive strategies, we provide a comprehensive game theoretical framework that models the interaction between the botnet herder and the defender group (network/computer users). In our framework, a botnet herder’s goal is to intensify his intrusion in a network of computers for pursuing economic profits whereas the defender group’s goal is to defend botnet herder’s intrusion. The percentage of infected computers in the network evolves according to a modified SIS (susceptible-infectious-susceptible) epidemic model. For a given level of network defense, we define the strategy of the botnet herder as the solution of a control problem and obtain the optimal strategy as a feedback on the rate of infection. In addition, using a differential game model, we obtain two possible closed-loop Nash equilibrium solutions. They depend on the effectiveness of available defense strategies and control/strategy switching thresholds, specified as rates of infection. The two equilibria are either (1) the defender group defends at maximum level while the botnet herder exerts an intermediate constant intensity attack effort or (2) the defender group applies an intermediate constant intensity defense effort while the botnet herder attacks at full power.
منابع مشابه
Application of Stochastic Optimal Control, Game Theory and Information Fusion for Cyber Defense Modelling
The present paper addresses an effective cyber defense model by applying information fusion based game theoretical approaches. In the present paper, we are trying to improve previous models by applying stochastic optimal control and robust optimization techniques. Jump processes are applied to model different and complex situations in cyber games. Applying jump processes we propose some m...
متن کاملA game theoretical approach for pricing in a two-level supply chain considering advertising and servicing
This paper considers the advertising, pricing, and service decisions simultaneously to coordinate the supply chain with a manufacturer and a retailer. The amount of market demand is influenced by advertising, pricing and service decisions. In this paper, three well-known approaches to the game theory, including the Nash, the Stackelberg-retailer, and the cooperative game are exploited to study ...
متن کاملA Stackelberg Game Model for Botnet Data Exfiltration
Cyber-criminals can distribute malware to control computers on a networked system and leverage these compromised computers to perform their malicious activities inside the network. Botnet-detection mechanisms, based on a detailed analysis of network traffic characteristics, provide a basis for defense against botnet attacks. We formulate the botnet defense problem as a zero-sum Stackelberg secu...
متن کاملA Game Theoretical Approach to Optimize Policies of Government Under the Cartel of Two Green and Non-green Supply Chains
In this research, firms aim at maximizing two purposes of social welfare (environment) and profitability in the supply chain system. It is assumed that there are two supply chains, a green and an ordinary, each consists of a manufacturer and a supplier; in which the manufacturer generates profit through franchises. The green and the ordinary manufacturers form a cartel on the market of a certai...
متن کاملOptimal Attack Strategies in a Dynamic Botnet Defense Model
Since the number of compromised computers, or botnet, continues to grow, the cyber security problem has become increasingly important and challenging to both academic researchers and industry practitioners. A respect to combat botnet propagation is to understand the attacker’s behaviors based on the whole operation of a system that can be modeled with population models used in epidemiological s...
متن کامل