Robust Defense Strategy for Network Security Against Unknown Attack Models

Armita Kazeminajafabadi, Mahdi Imani · 2025

Network security plays an increasingly vital role across various domains, particularly in sensitive areas such as aerospace systems. Examples include computer networks controlling flight systems and computers securely transmitting classified data. Several security approaches have been developed in recent years. This paper models network security as a Bayesian attack graph (BAG), a powerful model to capture the penetration and propagation of attacks in the network. Most existing defense policies for BAGs are designed for networks with known vulnerabilities and threats, denoted by a known BAG. However, in practice, the network vulnerabilities or threats could be presented by a set of BAGs. As attackers become more intelligent and dynamic, they utilize their resources to execute new or hard-to-detect attacks, posing uncertainty in network models. Given the uncertainty in the threat model, developing a robust defense strategy to ensure network security is crucial. This paper formulates an optimal robust defense policy that maximizes expected accumulated security reward under worst-case conditions (i.e., against the most aggressive threat model). We provide proof of convergence for the proposed policy, demonstrating that the optimal policy is computable for any network with any type of vulnerability. Furthermore, we introduce an efficient matrix-based computation of the optimal policy through an offline process, which enables real-time implementation during system operation. Numerical experiments demonstrate the robustness and accuracy of the proposed policy under various conditions.

Read the paper · More papers on PaperTik