Optimal Network Defense Resource Allocation Against Advanced Persistent Threats

Jinying Jiang,Xiaofeng Jiang,Jian Yang,Qi Zhang,Yifeng Liu
DOI: https://doi.org/10.1109/imcec46724.2019.8983999
2019-01-01
Abstract:Advanced persistent threats (APT) has brought a huge threat to the cyber network. In order to protect the network from APT attacks or reduce the loss caused by APT attacks, the reasonable allocation of defense resources can greatly improve the security of the network system. We consider two kinds of defense resources: 1) preventive resources able to defend nodes against internal infection or the external attack, such as these computing power resources that are spent on APT attack detection; 2) recovery resources able to recover the node after it has infected, such as these human resources that are spent on recovery operations when a host is infected. We study the following problem: give a fixed total security budget, find the optimal protected resources allocation scheme for network under APT to reach the security state at maximal rate. Different from the previous relevant work, we take the influence of external attack into consideration. We show that the optimal resource allocation problem for the network under APT can be solved in polynomial time using geometric programming. Finally, we validate the allocation scheme of preventive and recovery resource that we proposed greatly improves the security of the network system under APT.
What problem does this paper attempt to address?