Cyber-security in Critical Infrastructures: A Game-theoretic Approach
Book information
Description
This book presents a compendium of selected game- and decision-theoretic models to achieve and assess the security of critical infrastructures. Given contemporary reports on security incidents of various kinds, we can see a paradigm shift to attacks of an increasingly heterogeneous nature, combining different techniques into what we know as an advanced persistent threat. Security precautions must match these diverse threat patterns in an equally diverse manner; in response, this book provides a wealth of techniques for protection and mitigation. Much traditional security research has a narrow focus on specific attack scenarios or applications, and strives to make an attack practically impossible. A more recent approach to security views it as a scenario in which the cost of an attack exceeds the potential reward. This does not rule out the possibility of an attack but minimizes its likelihood to the least possible risk. The book follows this economic definition of security, offering a management scientific view that seeks a balance between security investments and their resulting benefits. It focuses on optimization of resources in light of threats such as terrorism and advanced persistent threats. Drawing on the authors experience and inspired by real case studies, the book provides a systematic approach to critical infrastructure security and resilience. Presenting a mixture of theoretical work and practical success stories, the book is chiefly intended for students and practitioners seeking an introduction to game- and decision-theoretic techniques for security. The required mathematical concepts are self-contained, rigorously introduced, and illustrated by case studies. The book also provides software tools that help guide readers in the practical use of the scientific models and computational frameworks. Contents Part I Introduction 1 Introduction 1.1 What are Critical Infrastructures? 1.2 Security Challenges for Critical Infrastructures 1.2.1 Natural and Physical Threats 1.2.1.1 Natural Disasters 1.2.1.2 Technical Failures 1.2.1.3 Disruptions and Outages 1.2.2 Cyber Threats 1.2.2.1 Distributed Denial of Service 1.2.2.2 Malware and Ransomware 1.2.2.3 Spear Phishing Attacks 1.2.2.4 Social Engineering 1.3 Advanced Persistent Threats (APT) 1.3.1 Characteristics 1.3.2 Life-Cycle 1.3.2.1 Step 1: Reconnaissance 1.3.2.2 Step 2: Initial Compromise 1.3.2.3 Step 3: Establish Foothold 1.3.2.4 Step 4: Escalate Privileges 1.3.2.5 Step 5: Internal Reconnaissance 1.3.2.6 Step 6: Move Laterally 1.3.2.7 Step 7: Maintain Presence 1.3.2.8 Step 8: Complete Mission 1.3.2.9 Step 9: Cover Tracks 1.4 Selected Real-Life Incidents 1.4.1 The Blackout in Italy (2003) 1.4.2 The Transportation Gridlock in Switzerland (2005) 1.4.3 The Attack on the Ukrainian Power Grid (2015) 1.4.4 The WannaCry and NotPetya Malware Infections(2017) 1.4.5 The Blackout in Venezuela (2019) References 2 Critical Infrastructures 2.1 Examples and Definitions of Critical Infrastructures 2.1.1 What Makes an Infrastructure ``Critical''? 2.1.2 Threats 2.2 Cyber Security 2.2.1 Hacking 2.2.2 Malware and Ransomware 2.3 Physical Security of Critical Infrastructures 2.3.1 Eavesdropping 2.3.2 Jamming 2.3.3 Terrorist Attacks 2.4 Cyber-Physical Security of Critical Infrastructures 2.5 Simulation of Effects of Security Incidents 2.5.1 Network Models 2.5.1.1 Graph-Based Models 2.5.1.2 Interdependent Network Models 2.5.2 Stochastic Models 2.5.2.1 Markov Chain Models 2.5.2.2 Branching Process Models 2.5.2.3 High-Level Stochastic Models 2.5.3 Dynamic Simulation Models 2.5.4 Agent-Based Models 2.5.5 Economy Based Methods 2.5.5.1 Input-Output Models 2.5.5.2 Computable General Equilibrium Models 2.6 Viewing Security as a Control Problem References 3 Mathematical Decision Making 3.1 Preference and Ordering Relations 3.2 Optimization 3.3 Multiple Goal Optimization 3.4 Decision Theory 3.4.1 Bayesian Decisions 3.4.2 Minimax-Decisions 3.5 Game Theory 3.5.1 Normal Form Games 3.5.2 Zero-Sum Games 3.5.3 Extensive Form Games 3.6 Extended Concepts: Modeling Goal Interdependence References 4 Types of Games 4.1 Overview 4.2 Stackelberg Game 4.3 Nash Game 4.4 Signaling Game 4.5 Games Over Stochastic Orders References 5 Bounded Rationality 5.1 Utility Maximization and Rationality 5.2 The Fundamental Principles of Decision Making 5.3 Violations of the Invariance Axiom 5.4 Decision Weights 5.5 Rank-Dependence and Prospect Theory 5.6 Violations of Transitivity and Regret Theory 5.7 Border Effects 5.8 Procedural Theories References Part II Security Games 6 Risk Management 6.1 Steps in a Risk Management Process 6.2 Resilience Analysis 6.3 Quantifying Security 6.4 Adversarial Risk Analysis 6.4.1 Assessment of Utilities and Chances 6.4.2 Assessment of Action Spaces References 7 Insurance 7.1 Why Cyber-Insurance? 7.2 Background 7.3 Three-Person Game Framework for Cyber Insurance 7.3.1 Attack-Aware Cyber Insurance 7.3.2 Insurer's Problem 7.4 Disappointment Rates References 8 Patrolling and Surveillance Games 8.1 The General Setting 8.2 The Art Gallery Theorem 8.3 From Art Galleries to Patrolling Games 8.4 A Simple Matrix Game Model 8.5 Graph Traversal Games 8.6 Strategy Reduction Techniques 8.6.1 Decomposition 8.6.2 Contraction 8.6.3 Symmetrization 8.7 Further Variations of Patrolling Games 8.7.1 Patrolling in Continuous Time 8.7.2 Accumulation Games 8.7.3 Covering Games 8.8 Surveillance Games References 9 Optimal Inspection Plans 9.1 Repeated, Independent Inspections 9.1.1 Solving the Non-detection Game 9.1.2 Solving the Inspection Game 9.2 Sequential and Dependent Inspections 9.3 Inspections Against Stealthy Takeover 9.3.1 Periodic Inspections 9.3.2 Leading Defender and Following Attacker 9.3.3 Inspections at Random Times 9.4 Inspections Against Stealthy Intrusions 9.4.1 Setting up the Game 9.4.1.1 Step 1: Preparing the Battlefield 9.4.1.2 Step 2: Inspection Strategies 9.4.1.3 Step 3: Payoff Assessment 9.4.2 Inspections at Random Times 9.4.3 Probabilistic Success on Spot Checks 9.4.4 Probabilistic Success on Exploits 9.4.5 Security Strategy Computation References 10 Defense-in-Depth-Games 10.1 The Need for Cross-Layer Security 10.2 Socio-Cyber-Physical Security Threats 10.2.1 Cyber-Physical Threats 10.2.2 Security Economics 10.3 Multi-layer Framework for Defense in Depth 10.4 Multi-layer Games for Strategic Defense in Depth References 11 Cryptographic Games 11.1 Rational Cryptography 11.1.1 Game-Based Security and Negligible Functions 11.1.2 Honesty and Rationality 11.1.3 Rational Interactive Proofs 11.2 Communication Games 11.2.1 Confidential Transmission Games 11.2.2 Authentication Games 11.2.3 Practical Implementations 11.2.4 On Network Design Using Game Theory 11.3 Critical Remarks References 12 Practicalities 12.1 Data Science and Choice of Model Parameters 12.1.1 Probability Parameters 12.1.2 Learning Parameters Over Time 12.2 Risk and Loss Parameters 12.2.1 General Parameters Derived from Statistical Models 12.3 Analytic Solutions for Special Games 12.3.1 Equilibria and Security Strategies 12.3.2 22-Games 12.3.3 Diagonal Games 12.3.4 Fictitious Play 12.4 Software Support 12.4.1 Solving Extensive-Form Games 12.4.2 Solving Normal-Form Games 12.4.3 Solving Distribution-Valued Games 12.5 Cost of Playing Equilibria 12.6 Making the Most Out of Uncertainty 12.6.1 Including Disappointment in Finite Games 12.6.2 Risks for Zero-Day Exploits 12.6.2.1 A Posteriori Mitigation of Zero-Day Exploits 12.6.2.2 Heuristic Modeling of Zero-Day Risks References Acronyms Glossary List of Symbols Index
Similar books
Cyber-Security in Critical Infrastructures: A Game-Theoretic Approach
2020 · PDF
Cyber-Security in Critical Infrastructures: A Game-Theoretic Approach (Advanced Sciences and Technologies for Security Applications)
2020 · EPUB
Game Theory for Security and Risk Management
2018 · PDF
Game Theory for Cyber Deception: From Theory to Applications (Static & Dynamic Game Theory: Foundations & Applications)
2021 · PDF
Cognitive Security: A System-Scientific Approach (SpringerBriefs in Computer Science)
2023 · EPUB
Cognitive Security: A System-Scientific Approach
2023 · PDF
Quantum Key Distribution Networks. A Quality of Service Perspective
2022 · PDF
Cyber-Security Threats and Response Models in Nuclear Power Plants
2022 · PDF