The use of partially observable Markov decision processes to optimally implement moving target defense

dc.contributor.authorMcabee, Ashley
dc.contributor.authorTummala, Murali
dc.contributor.authorMceachen, John
dc.date.accessioned2020-12-24T20:27:27Z
dc.date.available2020-12-24T20:27:27Z
dc.date.issued2021-01-05
dc.description.abstractFor moving target defense (MTD) to shift advantage away from cyber attackers, we need techniques which render systems unpredictable but still manageable. We formulate a partially observable Markov decision process (POMDP) which facilitates optimized MTD capable of thwarting cyber attacks without excess overhead. This paper describes POMDP formulation including the use of an absorbing final state and attack penalty scaling factor to abstract defender-defined priorities into the model. An autonomous agent leverages the POMDP to select the optimal defense based on assessed cyber-attack phase. We offer an example formulation wherein attack suppression of greater than 99% and system availability of greater than 94% were maintained even as probability of detection of attack phase dropped to 74%.
dc.format.extent10 pages
dc.identifier.doihttps://doi.org/10.24251/HICSS.2021.840
dc.identifier.isbn978-0-9981331-4-0
dc.identifier.urihttp://hdl.handle.net/10125/71461
dc.language.isoEnglish
dc.relation.ispartofProceedings of the 54th Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCybersecurity and Software Assurance
dc.subjectcybersecurity
dc.subjectmarkov models
dc.subjectmoving target
dc.titleThe use of partially observable Markov decision processes to optimally implement moving target defense
prism.startingpage6986

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0683.pdf
Size:
464.2 KB
Format:
Adobe Portable Document Format