Scalable Algorithms for Identifying Stealthy Attackers in a Game‐Theoretic Framework Using Deception
Anjon Basak, Charles Kamhoua, Sridhar Venkatesan, Marcus Gutierrez, Ahmed H. Anwar, Christopher D. Kiekintveld · 2021
Identifying an attacker in as much detail as possible (e.g., what their goals, capabilities, and tactics are) can lead to better defensive strategies for the defender and may eventually help with the attribution of attacks. On the other hand, attackers try to avoid both detection and identification, blending in or appearing to be a different type of attacker. However, the algorithm does not scale very well for large network instances. Next, we present a scalable version of the algorithm by reducing the action space considering domain knowledge and other heuristics. Our initial experiments show that the scalable version performs reasonably well compared to the nonscalable version.