Dynamic Cyber Deception Using Partially Observable Monte‐Carlo Planning Framework
Md Ali Reza Al Amin, Sachin S. Shetty, Laurent Njilla, Deepak K. Tosh, Charles Kamhoua · 2020
Cyber deception is an approach where a network administrator can deploy a network of decoy assets with the aim to expend adversaries' resources and time and gather information about the adversaries' strategies, tactics, capabilities, and intent. The key challenge of this cyber-deception approach is the design and placement of network decoys to ensure maximal information uncertainty for the attacker. State-of-the-art approaches to addressing this design and placement problem assume a static environment and a priori strategies are taken by the attacker. In this chapter, we propose the design and placement of network decoys considering scenarios where defender actions influence an attacker to change their strategies and tactics during lateral propagation while maintaining the trade-off between availability and security. A defender maintains a belief consisting of the security state and the resultant actions are cast as partially observable Markov decision process (POMDP). Our simulation results illustrate the defender's ability to influence the attacker's attack path only comprises of fake nodes and networks.