Deakin University
Browse

File(s) under permanent embargo

A risk management approach to defending against the advanced persistent threat

journal contribution
posted on 2020-11-01, 00:00 authored by Luxing YangLuxing Yang, P Li, X Yang, Y Y Tang
IEEE The advanced persistent threat (APT) as a new kind of cyber attack has posed a severe threat to modern organizations. When the APT has been detected, the organization has to deal with the APT response problem, i.e., to allocate the available response resources to fix her insecure hosts so as to mitigate her potential loss. This paper addresses the APT response problem by using the risk management approach. First, we introduce a model characterizing the evolution of the organization's expected state. By analyzing this model, we find the organization's expected state approaches a common limit expected state. Then, we use the organization's expected loss per unit time to measure her potential loss, and we find this measure is determined by the organization's limit expected state. On this basis, we model the APT response problem as a game-theoretic problem (the APT response game) in which the organization seeks a Nash equilibrium. We present a greedy algorithm for solving the game. Comparative experiments show that the algorithm is effective. Therefore, we recommend the response strategy generated by performing the algorithm. These findings contribute to defending against the APT. To our knowledge, this is the first time the APT response problem is addressed.

History

Journal

IEEE transactions on dependable and secure computing

Volume

17

Issue

6

Season

November/December

Pagination

1163 - 1172

Publisher

Institute of Electrical and Electronics Engineers

Location

Piscataway, N.J.

ISSN

1545-5971

eISSN

1941-0018

Language

eng

Publication classification

C1 Refereed article in a scholarly journal

Copyright notice

2018, IEEE