Optimal Honeypot Allocation using Core Attack Graph in Cyber Deception Games

Achile Leonel Nguemkam, Ahmed H. Anwar, Vianney Kengne Tchendji, Deepak K. Tosh, Charles Kamhoua · 2023

Honeypots appear today as a defense strategy to trap intelligent cyber attackers who can detect traditional security measures. The scalability of existing algorithms for solving some classes of game theory is very limited due to large-scale networks. This paper opens the door to a new approach to allocate honeypots in the network, to increase attackers’ costs, during the lateral movement of the APT attack. We use the core attack graph that can show the main routes an attacker can take toward the goal. This allows the defender to use a limited number of honeypots focusing its efforts only on critical nodes over the main attacker routes. The effectiveness and scalability of the proposed approach are evaluated over different network topologies, a varying number of honeypots, network size, and density. Numerical results show that the defender reward over the core attack graph is quite similar to that obtained on the original attack graph while significantly reducing the defender’s actions and computation time.

Read the paper · More papers on PaperTik