Network connectivity exposes the network infrastructure and assets to vulnerabilities that attackers can exploit. Protecting network assets against attacks requires the application of security countermeasures. Nevertheless, employing countermeasures incurs costs, such as monetary costs, along with time and energy to prepare and deploy the countermeasures. Thus, an Intrusion Response System (IRS) shall consider security and QoS costs when dynamically selecting the countermeasures to address the detected attacks. This has motivated us to formulate a joint Security-vs-QoS optimization problem to select the best countermeasures in an IRS. The problem is then transformed into a matching game-theoretical model. Considering the monetary costs and attack coverage constraints, we first derive the theoretical upper bound for the problem and later propose stable matching-based solutions to address the trade-off. The performance of the proposed solution, considering different settings, is validated over a series of simulations.
翻译:网络连通性使网络基础设施和资产暴露于攻击者可以利用的脆弱性之下。保护网络资产免受攻击需要采用安全对策。然而,采取反措施需要成本,如货币成本,同时需要时间和精力来准备和部署反措施。因此,入侵反应系统(IRS)在动态选择应对所发现攻击的反措施时,应考虑安全和QOS成本。这促使我们制定一个联合安全-vs-Qos优化问题,以便在IRS中选择最佳的对策。然后将问题转变为一个匹配的游戏理论模型。考虑到货币成本和攻击覆盖范围的限制,我们首先从理论上得出问题的上限,然后提出稳定的匹配解决方案来解决权衡问题。考虑到不同的环境,拟议解决方案的绩效通过一系列模拟得到验证。</s>