DocumentCode :
2009944
Title :
RRE: A game-theoretic intrusion Response and Recovery Engine for process control applications
Author :
Sanders, William H.
Author_Institution :
Coordinated Sci. Lab., Univ. of Illinois at Urbana-Champaign, Urbana, IL
fYear :
2009
fDate :
March 27 2009-April 30 2009
Firstpage :
1
Lastpage :
1
Abstract :
Preserving the availability and integrity of process control systems in the face of fast-spreading intrusions requires advances not only in detection algorithms, but also in automated response techniques. In this presentation, we propose a new approach to automated response called the response and recovery engine (RRE). Our engine employs a game-theoretic response strategy against adversaries modeled as opponents in a two-player Stackelberg stochastic game. RRE applies attack-response trees to analyze undesired security events and their countermeasures using Boolean logic to combine lower-level attack consequences. In addition, RRE accounts for uncertainties in intrusion detection alert notications. RRE then chooses optimal response actions by solving a partially observable competitive Markov decision process that is automatically derived from attack-response trees. Experimental results show that RRE, using Snort´s alerts, can protect large networks for which attack-response trees have more than 500 nodes.
Keywords :
Boolean functions; Markov processes; game theory; security of data; trees (mathematics); Boolean logic; RRE; Snort alerts; attack-response trees; automated response techniques; competitive Markov decision process; fast-spreading intrusions; game-theoretic intrusion response; process control systems; response-and-recovery engine; two-player Stackelberg stochastic game; Boolean functions; Detection algorithms; Engines; Face detection; Intrusion detection; Process control; Protection; Security; Stochastic processes; Uncertainty;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Critical Infrastructures, 2009. CRIS 2009. Fourth International Conference on
Conference_Location :
Linkoping
Print_ISBN :
978-1-4244-4636-0
Type :
conf
DOI :
10.1109/CRIS.2009.5071485
Filename :
5071485
Link To Document :
بازگشت