Preventive and Reactive Cyber Defense Dynamics Is Globally Stable
@article{Zheng2016PreventiveAR, title={Preventive and Reactive Cyber Defense Dynamics Is Globally Stable}, author={Ren Zheng and Wenlian Lu and Shouhuai Xu}, journal={IEEE Transactions on Network Science and Engineering}, year={2016}, volume={5}, pages={156-170} }
The recently proposed cybersecurity dynamics approach aims to understand cybersecurity from a holistic perspective by modeling the evolution of the global cybersecurity state. These models describe the interactions between the various kinds of cyber attacks and the various kinds of cyber defenses that take place in complex networks. In this paper, we study a particular kind of cybersecurity dynamics caused by the interactions between two classes of attacks (called push-based attacks and pull…
54 Citations
Preventive and Reactive Cyber Defense Dynamics With Ergodic Time-Dependent Parameters is Globally Attractive
- Computer ScienceIEEE Transactions on Network Science and Engineering
- 2021
This paper proves that one kind of cybersecurity dynamics, known as preventive and reactive cyber defense dynamics, which is a family of highly nonlinear system models, is globally attractive when the time-dependent parameters are ergodic, and is (almost) periodic when theTimedependent parameters have the stronger properties of being ( almost) periodic.
Unified Preventive and Reactive Cyber Defense Dynamics Is Still Globally Convergent
- Computer ScienceIEEE/ACM Transactions on Networking
- 2019
This paper unify the aforementioned class of preventive and reactive cyber defense dynamics models and the closely related class of <inline-formula> <tex-math notation="LaTeX">$N$ </tex- Math>-intertwined epidemic models into a single framework and characterize the convergence speed of the unified dynamics.
The Cybersecurity Dynamics Way of Thinking and Landscape
- Computer ScienceMTD@CCS
- 2020
The landscape and way-of-thinking that guide the Cybersecurity Dynamics model are discussed, including two killer applications and the technical barriers that serve as outstanding open problems for future research.
Using Event-Based Method to Estimate Cybersecurity Equilibrium
- Computer ScienceIEEE/CAA Journal of Automatica Sinica
- 2021
An event-based method for estimating cybersecurity equilibrium in the preventive and reactive cyber defense dynamics, which has been proven globally convergent, is presented and it is proved that the estimated equilibrium from the trigger rule indeed converges to the equilibrium of the dynamics.
Metrics Towards Measuring Cyber Agility
- Computer ScienceIEEE Transactions on Information Forensics and Security
- 2019
The first metric framework for measuring cyber agility in terms of the effectiveness of the dynamic evolution of cyber attacks and defenses is proposed, which is generic and applicable to transform any relevant, quantitative, and/or conventional static security metrics into dynamic metrics to capture dynamics of system behaviors.
Security Evaluation of the Cyber Networks Under Advanced Persistent Threats
- Computer ScienceIEEE Access
- 2017
This paper addresses the issue of evaluating the security of the cyber networks under APTs with a dynamic model capturing the APT-based cyber-attack-defense processes and suggests a new security metric known as the equilibrium security.
Cybersecurity Dynamics: A Foundation for the Science of Cybersecurity
- Computer ScienceProactive and Dynamic Network Defense
- 2019
This chapter systematically introduces and review the Cybersecurity Dynamics foundation for the Science of Cybersecurity, and outlines a research roadmap towards the ultimate research goal, and identified technical barriers that poses challenges to reach the goal.
A Heuristic Method for Network Modification Against Cyber Epidemic Attacks
- Computer Science2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/13th IEEE International Conference On Big Data Science And Engineering (TrustCom/BigDataSE)
- 2019
This paper provides a heuristic method for network modification against the cyber epidemic attack based on theoretical security conditions of the cyber dynamical system and demonstrates that the model can effectively resist multiple cyber epidemic attacks.
Proactive Security for Safety and Sustainability of Mission Critical Systems
- Computer ScienceIEEE Transactions on Sustainable Computing
- 2021
This work develops a formal model to proactively ensure safety and sustainability of mission critical systems by deploying a network of observer agents to supervise and generate observation data related to attacks under execution which will be analyzed by a central defense agent.
Quantifying Cybersecurity Effectiveness of Dynamic Network Diversity
- Computer ScienceIEEE Transactions on Dependable and Secure Computing
- 2022
A systematic framework for modeling and quantifying the cybersecurity effectiveness of network diversity, including a suite of cybersecurity metrics is proposed and the surprising result that proactive diversity is effective under very special circumstances, but reactive-adaptive diversity is much more effective in most cases is drawn.
References
SHOWING 1-10 OF 64 REFERENCES
Active cyber defense dynamics exhibiting rich phenomena
- Computer ScienceHotSoS
- 2015
To the best of the knowledge, this is the first study that shows that active cyber defense dynamics (or more generally, cybersecurity dynamics) can exhibit the bifurcation and chaos phenomena.
A Stochastic Model of Active Cyber Defense Dynamics
- Computer ScienceInternet Math.
- 2015
This paper proposes a novel Markov process model that is native to the interaction between cyber attack and active cyber defense, and simplifies it, via mean-field approximation, as a dynamical systemmodel that is amenable to analysis.
Characterizing the power of moving target defense via cyber epidemic dynamics
- Computer ScienceHotSoS '14
- 2014
This paper proposes to use a cyber epidemic dynamics approach to characterize the power of MTD, and defines and investigates two complementary measures that are applicable when the defender aims to deploy MTD to achieve a certain security goal.
A Stochastic Model for Quantitative Security Analyses of Networked Systems
- Computer ScienceIEEE Transactions on Dependable and Secure Computing
- 2011
A stochastic model for quantifying security of networked systems is presented, which captures two aspects of a networked system: the strength of deployed security mechanisms such as intrusion detection systems and the underlying vulnerability graph, which reflects how attacks may proceed.
A new approach to modeling and analyzing security of networked systems
- Computer Science, MathematicsHotSoS '14
- 2014
The approach is inspired by the shock model and random environment techniques in the Theory of Reliability, while accommodating security ingredients, and is the first that can accommodate a certain degree of adaptiveness of attacks.
Global dynamics of epidemic spread over complex networks
- Mathematics52nd IEEE Conference on Decision and Control
- 2013
Conditions under which the second fixed point attracts all non-origin points are given and it is shown that for random Erdös-Rényi graphs this happens with high probability.
A Stochastic Model of Multivirus Dynamics
- Computer ScienceIEEE Transactions on Dependable and Secure Computing
- 2012
This paper proposes and analyzes a general model of multivirus spreading dynamics in arbitrary networks, where multiple viruses attempt to infect computers while possibly combating against each other because, for example, they are controlled by multiple botmasters.
An Extended Stochastic Model for Quantitative Security Analysis of Networked Systems
- Computer Science, MathematicsInternet Math.
- 2012
This paper substantially weaken these assumptions while offering, in addition to the same types of analytical results as in [Li et al. 11], methods for obtaining the desired security quantities in practice.
The N-intertwined SIS epidemic network model
- Computer ScienceComputing
- 2011
The N-intertwined virus spread model of the SIS-type is introduced as a promising and analytically tractable model of which the steady-state behavior is fairly completely determined and much insight can be gained that is hidden in the exact Markov model.
Epidemic thresholds in real networks
- Computer ScienceTSEC
- 2008
A general epidemic threshold condition is proposed for the NLDS system: it is proved that the epidemic threshold for a network is exactly the inverse of the largest eigenvalue of its adjacency matrix, and it is shown that below the epidemic thresholds, infections die out at an exponential rate.