A Reinforcement Learning Approach for Dynamic Information Flow Tracking Games for Detecting Advanced Persistent Threats
Dinuka Sahabandu, Shana Moothedath, Joey Allen, Linda Bushnell, Wenke, Lee, and Radha Poovendran

TL;DR
This paper introduces a game-theoretic, resource-efficient model for Dynamic Information Flow Tracking (DIFT) to improve detection of Advanced Persistent Threats (APTs) while reducing resource overhead, validated on real-world ransomware data.
Contribution
It develops a novel game-theoretic framework and a learning algorithm to balance detection effectiveness and resource efficiency in DIFT for APT detection.
Findings
The model effectively balances resource use and detection accuracy.
The learning algorithm converges to a Nash equilibrium.
Validated on real ransomware data, showing practical applicability.
Abstract
Advanced Persistent Threats (APTs) are stealthy attacks that threaten the security and privacy of sensitive information. Interactions of APTs with victim system introduce information flows that are recorded in the system logs. Dynamic Information Flow Tracking (DIFT) is a promising detection mechanism for detecting APTs. DIFT taints information flows originating at system entities that are susceptible to an attack, tracks the propagation of the tainted flows, and authenticates the tainted flows at certain system components according to a pre-defined security policy. Deployment of DIFT to defend against APTs in cyber systems is limited by the heavy resource and performance overhead associated with DIFT. In this paper, we propose a resource-efficient model for DIFT by incorporating the security costs, false-positives, and false-negatives associated with DIFT. Specifically, we develop a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Information and Cyber Security
