TY - GEN
T1 - Prospect theoretic study of cloud storage defense against advanced persistent threats
AU - Xu, Dongjin
AU - Li, Yanda
AU - Xiao, Liang
AU - Mandayam, Narayan B.
AU - Poor, H. Vincent
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016
Y1 - 2016
N2 - Cloud storage is vulnerable to Advanced Persistent Threats (APTs), which are stealthy, continuous, well funded and targeted. In this paper, prospect theory is applied to study the interactions between a subjective cloud storage defender and a subjective APT attacker. Two subjective APT games are formulated, in which the defender chooses its interval to scan the storage device and the attacker decides its duration between launching two attacks under uncertain APT attack durations and action of the opponent, respectively. The Nash equilibria of the static subjective APT games are derived. We also study the dynamic APT game and propose a Q-learning based APT defense strategy for cloud storage. Simulation results show that the APT defense benefits from the subjective view of the attacker and the proposed defense strategy can improve detection performance with a higher utility.
AB - Cloud storage is vulnerable to Advanced Persistent Threats (APTs), which are stealthy, continuous, well funded and targeted. In this paper, prospect theory is applied to study the interactions between a subjective cloud storage defender and a subjective APT attacker. Two subjective APT games are formulated, in which the defender chooses its interval to scan the storage device and the attacker decides its duration between launching two attacks under uncertain APT attack durations and action of the opponent, respectively. The Nash equilibria of the static subjective APT games are derived. We also study the dynamic APT game and propose a Q-learning based APT defense strategy for cloud storage. Simulation results show that the APT defense benefits from the subjective view of the attacker and the proposed defense strategy can improve detection performance with a higher utility.
UR - http://www.scopus.com/inward/record.url?scp=85015372718&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=85015372718&partnerID=8YFLogxK
U2 - 10.1109/GLOCOM.2016.7842178
DO - 10.1109/GLOCOM.2016.7842178
M3 - Conference contribution
AN - SCOPUS:85015372718
T3 - 2016 IEEE Global Communications Conference, GLOBECOM 2016 - Proceedings
BT - 2016 IEEE Global Communications Conference, GLOBECOM 2016 - Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 59th IEEE Global Communications Conference, GLOBECOM 2016
Y2 - 4 December 2016 through 8 December 2016
ER -