A Bayesian game decision-making model for uncertain adversary types
Mahsa Emami-Taba, Ladan Tahvildari · Computer Science and Software Engineering · 2016
Adaptive application security involves making decisions under uncertainties such as the time, the power, or the damage of potential attacks. One of the uncertainties that has been largely ignored in the literature is the intention of the adversaries. The majority of research focuses on characteristics of attacks (e.g., their request arrival rates), whereas characteristics of attackers/adversaries (e.g., their intentions and strategies) are neglected. In today's sophisticated attacks, in order to confuse defense systems, adversaries may initiate an attack that exhibits a scenario similar to another attack but has an entirely different malicious goal (e.g., to break down the server or to harm a specific user in the system). In such cases, incorporating uncertainty about the type of adversaries into the decision model helps to choose a proper countermeasure for protecting the software system efficiently. In this paper, we present a Bayesian game model that captures the uncertainty about an adversary's motivation for sending malicious requests. Our game-theoretic model formalizes possible intentions of adversaries along with the security preferences of the software system. In such a novel design, the equilibrium of the modeled game balances the gain from achieving security goals with the loss incurred by mitigating the attack. We provide an extensive analysis of the proposed game-theoretic model in the presence and absence of uncertainty about the adversary type. Moreover, we present a case study to show how such uncertainty can be addressed using the proposed technique in a real-world scenario.