Optimal Security Response to Network Intrusions in IT Systems
Kim Hammar

TL;DR
This paper develops a practical methodology for optimal security response in IT systems by combining emulation, game-theoretic modeling, and stochastic optimization to bridge the gap between theory and operational performance.
Contribution
It introduces a novel integrated approach using emulation and simulation to derive and validate optimal security response strategies against network intrusions.
Findings
Proven structural properties of optimal response strategies
Efficient algorithms for computing optimal responses
Demonstrated optimal security response on IT infrastructure
Abstract
Cybersecurity is one of the most pressing technological challenges of our time and requires measures from all sectors of society. A key measure is automated security response, which enables automated mitigation and recovery from cyber attacks. Significant strides toward such automation have been made due to the development of rule-based response systems. However, these systems have a critical drawback: they depend on domain experts to configure the rules, a process that is both error-prone and inefficient. Framing security response as an optimal control problem shows promise in addressing this limitation but introduces new challenges. Chief among them is bridging the gap between theoretical optimality and operational performance. Current response systems with theoretical optimality guarantees have only been validated analytically or in simulation, leaving their practical utility…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Smart Grid Security and Resilience · Cybersecurity and Information Systems
