{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/markov-game-modeling-of-moving-target-defense","title":"Markov Game Modeling of Moving Target Defense for Strategic Detection of Threats in Cloud Networks","arxiv_id":"1812.09660","date":"2018-12-23","proceeding":null,"authors":["Ankur Chowdhary","Sailik Sengupta","Dijiang Huang","Subbarao Kambhampati"],"abstract":"The processing and storage of critical data in large-scale cloud networks\nnecessitate the need for scalable security solutions. It has been shown that\ndeploying all possible security measures incurs a cost on performance by using\nup valuable computing and networking resources which are the primary selling\npoints for cloud service providers. Thus, there has been a recent interest in\ndeveloping Moving Target Defense (MTD) mechanisms that helps one optimize the\njoint objective of maximizing security while ensuring that the impact on\nperformance is minimized. Often, these techniques model the problem of\nmulti-stage attacks by stealthy adversaries as a single-step attack detection\ngame using graph connectivity measures as a heuristic to measure performance,\nthereby (1) losing out on valuable information that is inherently present in\ngraph-theoretic models designed for large cloud networks, and (2) coming up\nwith certain strategies that have asymmetric impacts on performance. In this\nwork, we leverage knowledge in attack graphs of a cloud network in formulating\na zero-sum Markov Game and use the Common Vulnerability Scoring System (CVSS)\nto come up with meaningful utility values for this game. Then, we show that the\noptimal strategy of placing detecting mechanisms against an adversary is\nequivalent to computing the mixed Min-max Equilibrium of the Markov Game. We\ncompare the gains obtained by using our method to other techniques presently\nused in cloud network security, thereby showing its effectiveness. Finally, we\nhighlight how the method was used for a small real-world cloud system.","url_abs":"http://arxiv.org/abs/1812.09660v2","url_pdf":"http://arxiv.org/pdf/1812.09660v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"markov-game-modeling-of-moving-target-defense","repo_url":"https://github.com/sailik1991/MarkovGameSolvers","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null},{"paper_slug":"markov-game-modeling-of-moving-target-defense","repo_url":"https://github.com/facundo-p/Markov-Game-Model","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}