An empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System shows that QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations.
Abstract
Stackelberg Security Games (SSG) assume that an attacker observes the defender's strategy and chooses the target that maximizes their expected utility perfectly. In most realistic applications this is not plausible, and in the case of cyber deception (e.g., using decoys) the purpose of the game is to induce uncertainty and mistakes. Quantal response is a common way to represent noise and mistakes in decision-making; here it replaces perfect best-response with a logit choice with rationality parameter $\lambda$ and results in a generalized Quantal Stackelberg Equilibrium (QSE), which recovers the classical solution exactly as $\lambda \rightarrow \infty$. We conduct a deeper analysis of how QSE can function as a generalized form of insurance against a variety of forms of model specification error/uncertainty; our analysis shows that QSE provides a practical way to address the important role of tie-breaking rules and model uncertainty in SSG from both a theoretical and practical perspective. We conduct an empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System (CVSS). QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations, with gains of 46\% to 175\% showing a substantial advantage in a wide variety of realistic cases.
A polynomial-time approximation scheme for SSG with mixed quantal response attackers, where the follower population consists of multiple discrete attacker types, each following a type-specific QR model, is developed based on an exponential cone programming formulation combined with a carefully designed Branch-and-Bound...
Hoang Giang Pham, Tien Mai, Thuy Anh Ta et al.· Proceedings of the Thirty-Fi...· 0 citations
It is demonstrated that under certain initial conditions, the Attackers can mislead the Defender into making suboptimal decisions through a slow-speed deception strategy, achieving superior payoffs compared to the complete information game.
Xiang-Kai Wu, Shaolin Tan, Wei Wang et al.· 0 citations
A five-stage Bayesian Stackelberg security game with five stage-specific actions per player is formulated, which examines whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known.
A deployable mechanism combining history-dependent challenges, reputation-weighted slashing, and stake vesting is proposed, which restores infinite-horizon subgame-perfect incentive compatibility against stationary mixed-strategy deviations above an explicit discount-factor threshold without per-query cryptographic ver...
We model insider threat detection as a dynamic Bayesian game in which a platform coordinates a committee of strategic certifiers to sustain equilibrium among honest users and detect malicious deviations before exfiltration. Certifiers and users operate under a Bayesian Temporal Correlated Equilibrium (BTCE), where a se...
Javed M Shah, Ian A. Kash, Natalie Parde· 0 citations
Interconnected systems can suffer infectious attacks, where the compromise of one node exposes neighboring nodes and may trigger cascading loss. Existing Stackelberg and network-defense models usually address only part of this setting: a centralized defender, independent targets, or no post-attack resource transfer. Th...
Lei Cui, Yifan Li, Shuhan Qi et al.· Journal of King Saud Univers...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.