4.7 Article

Defense Against Advanced Persistent Threat Through Data Backup and Recovery

期刊

出版社

IEEE COMPUTER SOC
DOI: 10.1109/TNSE.2020.3040247

关键词

Security; Organizations; Investment; Servers; Nash equilibrium; Maintenance engineering; Loss measurement; Advanced persistent threat; DBAR-based APT defense mechanism; DBARS problem; data backup and recovery; differential game; nash equilibrium; software-defined networking

资金

  1. National Natural Science Foundation of China [61 572 006]
  2. Chongqing Basic Research and Front Exploration Project [cstc2018jcyjA3093]
  3. Chongqing Key Laboratory of Mobile Communications Technology [cqupt-mct-201901]
  4. Australian Research Council [LP170100458]

向作者/读者索取更多资源

The paper introduces a novel APT defense mechanism based on DBAR techniques, aiming to address the shortcomings of the conventional DAR-based APT defense mechanism and demonstrate efficiency in practical implementation.
Advanced persistent threat (APT) as a generic highly sophisticated cyber attack poses a severe threat to organizational data security. Since the conventional detection and repair (DAR)-based APT defense mechanism has several conspicuous drawbacks, it is imperative to develop a more effective and efficient APT defense mechanism. Based on the data backup and recovery (DBAR) techniques developed in the field of disaster recovery, we propose a novel APT defense mechanism referred to as DBAR-based APT defense mechanism, which can overcome the main drawbacks of the DAR-based APT defense mechanism and is expected to be implementable efficiently in the software-defined networking (SDN) paradigm. Under the new mechanism, we study the problem of finding a cost-effective DBAR strategy. Based on a novel dynamic model characterizing the evolution of the expected security status of the organizational network, we reduce the problem to a differential game-theoretic problem, which is aimed to seek a cost-effective DBAR strategy in terms of the Nash equilibrium solution concept. Next, we derive the optimality system of the problem. Extensive comparative experiments show that the DBAR strategy obtained from the optimality system is cost-effective in the sense of Nash equilibrium solution concept.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据