Toward a Theory of Cyber Attacks
Saeed Valizadeh, Marten van Dijk

TL;DR
This paper introduces a formal framework using Markov models to analyze defender-attacker interactions, providing rigorous security guarantees and insights into defense strategies' effectiveness over time.
Contribution
It develops a general methodology for modeling cyber attack games with Markov models and introduces a capacity region for analyzing strategic impacts on security.
Findings
Provides conditions for probabilistic attack success bounds
Defines a containment parameter for attack impact within time windows
Offers insights into defense learning rates and attack containment
Abstract
We provide a general methodology for analyzing defender-attacker based "games" in which we model such games as Markov models and introduce a capacity region to analyze how defensive and adversarial strategies impact security. Such a framework allows us to analyze under what kind of conditions we can prove statements (about an attack objective ) of the form "if the attacker has a time budget , then the probability that the attacker can reach an attack objective is at most ". We are interested in such rigorous cryptographic security guarantees (that describe worst-case guarantees) as these shed light on the requirements of a defender's strategy for preventing more and more the progress of an attack, in terms of the "learning rate" of a defender's strategy. We explain the damage an attacker can achieve by a "containment parameter" describing the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
