A Game Theoretical Model for Anticipating Email Spear-Phishing Strategies

Franklin Tchakounte,Virgile Sime Nyassi,Duplex Elvis Houpa Danga,Kalum Priyanath Udagepola,Marcellin Atemkeng
DOI: https://doi.org/10.4108/eai.26-5-2020.166354
2018-01-01
ICST Transactions on Scalable Information Systems
Abstract:A solution to help victims against phishing is anticipating and leveraging impacts related to phisher actions.In this regard, this work reshapes game theoretical logic between Intrusion Detection System (IDS) agents andinsiders to email spear-phishing interactions. The email spear-phishing attack is designed as a non-cooperativeand repeated game between opponents. Additionally, this work relies on Quantal Response Equilibrium (QRE)to build a game theoretical approach to predict the phisher’s future intent based on past actions of bothplayers. This approach is coupled with a recommendation strategy of appropriate allocation of resources toinvest to strengthen user protection. Simulations on spear-phishing scenarios demonstrate the ability of thefinal system to intuitively guess the most likely phisher decisions. This work provides intelligence to spear-phishing detectors and humans such that they can anticipate next phisher actions.
What problem does this paper attempt to address?