Cyber Situation Awareness: Modeling Detection of Cyber Attacks With Instance-Based Learning Theory

被引:51
作者
Dutt, Varun [1 ,2 ]
Ahn, Young-Suk [3 ]
Gonzalez, Cleotilde [4 ]
机构
[1] Indian Inst Technol, Sch Comp & Elect Engn, Mandi 175001, HP, India
[2] Indian Inst Technol, Sch Humanities & Social Sci, Mandi 175001, HP, India
[3] Carnegie Mellon Univ, Sch Comp Sci, Pittsburgh, PA 15213 USA
[4] Carnegie Mellon Univ, Dept Social & Decis Sci, Dynam Decis Making Lab, Pittsburgh, PA 15213 USA
关键词
cyber situation awareness; Instance-Based Learning Theory; defender; adversarial behavior; experiences; tolerance; RISK-TAKING; DECISIONS;
D O I
10.1177/0018720812464045
中图分类号
B84 [心理学]; C [社会科学总论]; Q98 [人类学];
学科分类号
03 ; 0303 ; 030303 ; 04 ; 0402 ;
摘要
Objective: To determine the effects of an adversary's behavior on the defender's accurate and timely detection of network threats. Background: Cyber attacks cause major work disruption. It is important to understand how a defender's behavior (experience and tolerance to threats), as well as adversarial behavior (attack strategy), might impact the detection of threats. In this article, we use cognitive modeling to make predictions regarding these factors. Method: Different model types representing a defender, based on Instance-Based Learning Theory (IBLT), faced different adversarial behaviors. A defender's model was defined by experience of threats: threat-prone (90% threats and 10% nonthreats) and nonthreat-prone (10% threats and 90% nonthreats); and different tolerance levels to threats: risk-averse (model declares a cyber attack after perceiving one threat out of eight total) and risk-seeking (model declares a cyber attack after perceiving seven threats out of eight total). Adversarial behavior is simulated by considering different attack strategies: patient (threats occur late) and impatient (threats occur early). Results: For an impatient strategy, risk-averse models with threat-prone experiences show improved detection compared with risk-seeking models with nonthreat-prone experiences; however, the same is not true for a patient strategy. Conclusions: Based upon model predictions, a defender's prior threat experiences and his or her tolerance to threats are likely to predict detection accuracy; but considering the nature of adversarial behavior is also important. Application: Decision-support tools that consider the role of a defender's experience and tolerance to threats along with the nature of adversarial behavior are likely to improve a defender's overall threat detection.
引用
收藏
页码:605 / 618
页数:14
相关论文
共 35 条
[1]  
Albanese M, 2011, LECT NOTES COMPUT SC, V6879, P416, DOI 10.1007/978-3-642-23822-2_23
[2]  
Anderson J.R., 1998, The Atomic Components of Thought
[3]   The Newell Test for a theory of cognition [J].
Anderson, JR ;
Lebiere, C .
BEHAVIORAL AND BRAIN SCIENCES, 2003, 26 (05) :587-+
[4]  
[Anonymous], 1998, Proceedings of the 1998 workshop on New security paradigms, DOI DOI 10.1145/310889.310900
[5]  
[Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, CCS'02, DOI DOI 10.1145/586110.586144
[6]  
[Anonymous], 2001, Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection, RAID'00, DOI 10.1007/3-540-45474-86
[7]  
Blais AR, 2006, JUDGM DECIS MAK, V1, P33
[9]  
Dutt Varun, 2011, 2011 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support (CogSIMA 2011), P82, DOI 10.1109/COGSIMA.2011.5753758
[10]  
Dutt V., SITUATIONAL AWARENES