پدافند الکترونیکی و سایبری

پدافند الکترونیکی و سایبری

بررسی و امکان‌سنجی بازی جنگ سایبری با استفاده از نظریه بازی‌ها

نوع مقاله : مقاله پژوهشی

نویسندگان
1 پژوهشگر، دانشگاه عالی دفاع ملی،تهران ، ایران
2 استادیار ، دانشگاه عالی دفاع ملی، تهران،ایران
چکیده
این مقاله به امنیت سایبری از دریچه بازی‌های جنگ سایبری می‌پردازد و یک الگوریتم دفاع - حمله با تعامل پویا را بین مهاجمان و مدافعان هوشمند پیشنهاد می‌کند. در این رویکرد، هر دو طرف به‌صورت پویا استراتژی‌های خود را بر اساس اقدامات حریف تنظیم می‌کنند تا به پیروزی دست یابند. باتوجه‌به وجود پدیده «جنگ سایبری» در اغلب حوادث واقعی امنیت سایبری، ابتدا یک چارچوب نظری بازی پویا غیر همکاری مجموع صفر برای تحلیل این تعاملات بررسی می‌شود. مدل‌سازی بر اساس هزینه یا سود تصمیمات مهاجمان/مدافعان برای اعمال سطوح مختلف حمله/دفاع صورت می‌گیرد. ایده اولیه تعمیم داده شده و حالت‌های پیچیده‌تری از جمله بازی جنگ سایبری پویای سه‌جانبه و بازی جنگ سایبری پویای آستانه‌ای (T,p) مورد بررسی قرار می‌گیرند. همچنین برای سنجش اثربخشی، یک سناریوی شبیه‌سازی بر مبنای مدل‌های پیشنهادی ارائه شده و نتایج شبیه‌سازی بر اساس معیارهایی چون نرخ موفقیت در دفاع و میزان انرژی کل سیستم تحلیل می‌گردد. در نهایت، اثربخشی مدل پیشنهادی با استفاده از یک سناریوی حمله سایبری به زیرساخت‌های وزارت راه مورد سنجش و گزارش قرار می‌گیرد.
کلیدواژه‌ها
موضوعات

عنوان مقاله English

Investigating and feasibility of cyber war game using game theory

نویسندگان English

Reza Roohi-Seraji 1
Nasibollah Doustimotlagh 2
1 Researcher, Supreme National Defense university, Tehran, Iran
2 Assistant Professor, Supreme National Defense University, Tehran, Iran
چکیده English

This paper focuses on the study of cybersecurity based on a cyberwar game by proposing a dynamic attack-defense algorithm for the interaction between attackers and defenders, where both parties are intelligent and dynamically adjust their attack or defense strategies according to the opponent's actions to achieve victory. The phenomenon of "cyberwar" exists in most real-world cybersecurity incidents, which requires special research and analysis. First, a theoretical framework of a zero-sum non-cooperative dynamic game is reviewed for data analysis, and then several different modes are generalized and examined, and finally a simulated scenario is presented based on it, and the results are analyzed in terms of the success rate of defense and the energy of the entire system. The decisions of attackers/defenders to have different attack/defense levels based on cost or benefit are modeled. An attempt is made to generalize the initial idea, and a three-sided dynamic cyberwar game is examined. A dynamic threshold cyberwar game (T,p) is presented. Finally, a cyberattack scenario on the infrastructure of the Ministry of Roads is addressed and the effectiveness of the proposed model is reported.

کلیدواژه‌ها English

Cyber Wargame
Game Theory
ynamic Cyber Wargame
Nash Equilibrium Point
Cyber Security

Smiley face

 

[1]     Y. Wang, Y. Wang, J. Liu, Z. Huang, and P. Xie, “A survey of game theoretic methods for cyber security,” in IEEE First International Conference on Data Science in Cyberspace (DSC), June 2016.
[2]     .S. Roy, C. Ellis, S. Shiva, D. Dasgupta, V. Shandilya, and Q. Wu, “A survey of game theory as applied to network security,” in 43rd Hawaii International Conference on System Sciences, pp. 1–10, Jan 2010.
[3]     A. E. Chukwudi and I. C. Eze Udoka, “Game theory basics and its application in cyber security,” Advances in Wireless Communications and Networks, vol. 3, no. 4, pp. 45–49, 2017.
[4]     M. H. Manshaei, Q. Zhu, T. Alpcan, T. Bacs¸ar, and J.-P. Hubaux, “Game theory meets network security and privacy,” ACM Computing Surveys (CSUR), vol. 45, no. 3, p. 25, 2013.
[5]     M. Fallah, “A puzzle-based defense strategy against flooding attacks using game theory,” IEEE Transactions on Dependable and Secure Computing, vol. 7, pp. 5–19, Jan 2010.
[6]     Y. Liu, C. Comaniciu, and H. Man, “A bayesian game approach for intrusion detection in wireless ad hoc networks,” in Proceeding from the 2006 workshop on Game theory for communications and networks, p. 4, ACM, 2006.
[7]     M. Mohi, A. Movaghar, and P. M. Zadeh, “A bayesian game approach for preventing dos attacks in wireless sensor networks,” in Communications and Mobile Computing, 2009. CMC’09. WRI International Conference on, vol. 3, pp. 507–511, IEEE, 2009.
[8]     D. Fudenberg and J. Tirole, “Game theory. 1991,” Cambridge, Massachusetts, vol. 393, 1991.
[9]     V. P. Singh, S. Jain, and J. Singhai, “Hello flood attack and its countermeasures in wireless sensor networks,” IJCSI International Journal of Computer Science Issues, vol. 7, no. 11, pp. 23–27, 2010.
[10]  A. Dubey, D. Meena, and S. Gaur, “A survey in hello flood attack in wireless sensor networks,” Int. J. Eng. Res. Technol, vol. 3, 2014.
[11]  M. S. Haghighi and K. Mohamedpour, “Securing wireless sensor networks against broadcast attacks,” in Telecommunications, 2008. IST 2008. International Symposium on, pp. 49–54, IEEE, 2008.
[12]  R. Singh, D. J. Singh, and D. R. Singh, “Hello flood attack countermeasures in wireless sensor networks,” 2016.
[13]    R. S. Hassoubah, S. M. Solaiman, and M. A. Abdullah, “Intrusion detection of hello flood attack in wsns using location verification scheme,” International Journal of Computer and Communication Engineering, vol. 4, no. 3, p. 156, 2015.
[14]  R. Rehman, G. Hazarika, and G. Chetia, “Malware threats and mitigation strategies: a survey,” Journal of Theoretical and Applied Information Technology, vol. 29, no. 2, pp. 69–73, 2011.
[15]  I. You and K. Yim, “Malware obfuscation techniques: A brief survey,” in 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, pp. 297–300, Nov 2010.
[16]  A. Sharma and S. K. Sahay, “Evolution and detection of polymorphic and metamorphic malwares: A survey,” arXiv preprint arXiv:1406.7061, 2014.
[17]  J. Kim, S. Lee, J. M. Youn, and H. Choi, “A study of simple classification of malware based on the dynamic api call counts,” in International Conference on Computer Science and its Applications, pp. 944–949, Springer, 2016.
[18]  M. Egele, T. Scholte, E. Kirda, and C. Kruegel, “A survey on automated dynamic malware-analysis techniques and tools,” ACM computing surveys (CSUR), vol. 44, no. 2, p. 6, 2012.
[19]  O. Nakhila and C. Zou, “Parallel active dictionary attack on ieee 802.11 enterprise networks,” in MILCOM IEEE Military Communications Conference, pp. 265–270, Nov 2016.
[20]  V. Goyal, V. Kumar, M. Singh, A. Abraham, and S. Sanyal, “Compchall: addressing password guessing attacks,” in Information Technology: Coding and Computing, ITCC. International Conference on, vol. 1, pp. 739–744, IEEE, 2005.
[21]  Q. Xu, R. Zheng, W. Saad, and Z. Han, “Device fingerprinting in wireless networks: Challenges and opportunities,” IEEE Communications Surveys Tutorials, vol. 18, pp. 94–104, Firstquarter 2016.
[22]  A. Attiah, M. Chatterjee and C. C. Zou, "A Game Theoretic Approach to Model Cyber Attack and Defense Strategies," 2018 IEEE International Conference on Communications (ICC), Kansas City, MO,USA,2018,pp.17,doi:10.1109/ICC.2018.8422719
[23]  A. Sinha, J. Fu, Q. Zhu, T. Zhang, “Decision and Game Theory for Security” 15th International Conference, GameSec, New York City, NY, USA, October 16–18, 2024, Proceedings. Doi: https://doi.org/10.1007/978-3-031-74835-6, 2024
[24]  Groce, P.,: Using Game Theory to Advance the Quest for Autonomous Cyber Threat Hunting. Carnegie Mellon University, Software Engineering Institute's Insights (blog), Accessed June 3, 2025, https://insights.sei.cmu.edu/blog/Using-Game Theory -to-Advance-Cyber-Threat-Hunting
[25]  Hui Ge, Lei Zhao, Dong Yue, Xiangpeng Xie, Linghai Xie, Sergey Gorbachev, Iakov Korovin, Yuan Ge, "A game theory based optimal allocation strategy for defense resources of smart grid under cyber-attack", Information Sciences, Volume 652, 19759, ISSN 0020-0255, https://doi.org/10.1016/j.ins.2023.119759. 2024.

  • تاریخ دریافت 14 دی 1404
  • تاریخ بازنگری 01 اسفند 1404
  • تاریخ پذیرش 06 اسفند 1404
  • تاریخ انتشار 01 خرداد 1405