arrow
Return

A Learning-Based Approach to Reactive Security

delete2012-07-01
delete14
delete
OA
AI
A
Adam Barth *
B
Benjamin I. P. Rubinstein
M
Mukund Sundararajan
J
John C. Mitchell
D
Dawn Song
P
Peter L. Bartlett
DOI:10.1109/TDSC.2011.42delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Despite the conventional wisdom that proactive security is superior to reactive security, we show that reactive security can be competitive with proactive security as long as the reactive defender learns from past attacks instead of myopically overreacting to the last attack. Our game-theoretic model follows common practice in the security literature by making worst case assumptions about the attacker: we grant the attacker complete knowledge of the defender's strategy and do not require the attacker to act rationally. In this model, we bound the competitive ratio between a reactive defense algorithm (which is inspired by online learning theory) and the best fixed proactive defense. Additionally, we show that, unlike proactive defenses, this reactive strategy is robust to a lack of information about the attacker's incentives and knowledge.
Keywords:
Reactive security
risk management
attack graphs
online learning
adversarial learning
game theory

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

S
Stanford University
Scholars:
9.6W
Papers: 8.2W
Citations: 17.0W
University of California System cover
University of California System
Scholars:
37.5W
Papers: 33.7W
Citations: 6.6K
M
Microsoft
Scholars:
3.0K
Papers: 2.7K
Citations: 7
G
Google Incorporated
Scholars:
3.5K
Papers: 1.8K
Citations: 8
researcher View more organizations