Aiming at the problem that the traditional passive response model lags behind the attacks
and false alarms and missed alarms frequently lead to inappropriate responses
an active response decision-making model based on partial Markov game(POMG)is proposed. The model generates the attack state transmission graph according to the invasion processes. During the invasions
the model determines the system's belief states based on the observations of events so that the attacks are mapped to the nodes of the attack state transmission graph
considering the attacker and the uncertainty of system states.The sub-graphs of the attack state transmission graph are created
in which the belief state value of each sub-graph's initial node is over the belief state threshold. The attack and defense strategy sets are determined according to the invasion process of sub-graphs. The model generates the decision of the optimal active response policies according to POMG algorithm in the end. Experimental results show that the response speed of the active response model based on POMG is 67% faster than the map-based model
and the average response efficiency of the proposed model is 24.5% higher than the map-based model.
ZHANG Yongzheng, FANG Binxing, CHI Yue, et al. Risk propagation model for assessing network information systems [J]. Journal of Software, 2007, 18(1): 137-145.
CARVER C, HILL J M, SURDU J R. A methodology for using intelligent agents to provide automated intrusion response [C]∥Proceedings of the 2000 IEEE Workshop on Information Assurance and Security. Los Alamitos, CA,USA: IEEE Computer Society, 2000: 110-116.
RAGSDALE D, CARVER C, HUMPHRIES J, et al. Adaptation techniques for intrusion detection and intrusion response system [C]∥The IEEE International Conf on Systems, Man, and Cybernetics. Los Alamitos, CA,USA: IEEE Computer Society, 2000: 2344-2349.
MUSMAN S, FLESHER P. System of security managers' adaptive response tool [C]∥Proceedings of DARPA Information Survivalability Conference and Exposition. Los Alamitos, CA, USA: IEEE Computer Society, 2000:56-68.
FOO Bingrui, WU Yusung, MAO Yuchun, et al. ADEPTS: adaptive intrusion response using attack graphs in an E-commerce environment [C]∥Proceedings of the 2005 International Conference on Dependable Systems and Networks. Los Alamitos, CA,USA: IEEE Computer Society, 2005:508-517.
WU Yusung, FOO Bingrui, MAO Yuchun, et al. Automated adaptive intrusion containment in systems of interacting services [J]. Computer Networks, 2007, 5(51):1334-1360.
LYE K W, WING M J. Game strategies in network security [J]. International Journal of Information Security, 2005, 4(1/2): 71-86.
LI Xiang, CHEN Xiaoping. A real-time planning system in dynamic nondeterministic environments[J]. Chinese Journal of Computers, 2005, 7(28): 1163-1170.
AN Xifeng, LI Weihua, LIU Zun, et al. Research and implementation of network security cooperative defense system [J]. Journal of Xi'an Jiaotong University, 2008, 42(12): 1495-1499.
HAN Zongfen, TAO Zhifei, YANG Sirui, et al. Cooperative intrusion protection based on security zone [J]. Journal of Huazhong University of Science and Technology:Nature Science Edition, 2006, 12(34): 53-55.
LEE W, FAN W, MILLER M, et al. Toward cost-sensitive modeling for intrusion detection and response [J]. Journal of Computer Security, 2002, 10(1/2): 5-22.
WANG L, ISLAM T, LONG T, et al. An attack graph-based probabilistic security metric [J]. Lecture Notes in Computer Science, 2008(5094): 283-296.