Cost-effective Migration-Based Dynamic Platform Defense Technique: a CTMDP Approach

Zhang Yipin,Chang Xiaolin,Mišić Jelena,Mišić Vojislav B.,Cai Yutong
DOI: https://doi.org/10.1007/s12083-021-01084-8
IF: 3.488
2021-01-01
Peer-to-Peer Networking and Applications
Abstract:The fantastic growth in cybersecurity attack frequency and sophistication over the years advances the development of Moving Target Defense (MTD) technology. Migration-based dynamic platform technique (DPT), one of MTD techniques, is expected to significantly improve cyberspace security by migrating service across multiple platforms according to the predefined policy. However, the existing random migration policies cause unnecessary cost when the service platform is not under attack, which indicates the necessity of combining DPT with traditional detection-based defense mechanism to make migration decision. In this paper, we propose a Continuous-Time Markov Decision Process (CTMDP)-based dynamic platform defense model against multi-stage attacks, which can determine the optimal service migration timing based on the system reward. To maximize the expected total discounted reward of the system, we utilize the value iteration algorithm to determine the optimal policy which defines what action to be taken in a specific state. Experiments are carried out to demonstrate that our CTMDP-based dynamic platform defense model obtains higher expected total discounted reward than using random migration policies. We also investigate the effects of platform numbers and discount factors on the system reward.
What problem does this paper attempt to address?