{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/moving-target-defense-for-web-applications","title":"Moving Target Defense for Web Applications using Bayesian Stackelberg Games","arxiv_id":"1602.07024","date":"2016-02-23","proceeding":null,"authors":["Sailik Sengupta","Satya Gautam Vadlamudi","Subbarao Kambhampati","Marthony Taguinod","Adam Doupé","Ziming Zhao","Gail-Joon Ahn"],"abstract":"The present complexity in designing web applications makes software security\na difficult goal to achieve. An attacker can explore a deployed service on the\nweb and attack at his/her own leisure. Moving Target Defense (MTD) in web\napplications is an effective mechanism to nullify this advantage of their\nreconnaissance but the framework demands a good switching strategy when\nswitching between multiple configurations for its web-stack. To address this\nissue, we propose modeling of a real-world MTD web application as a repeated\nBayesian game. We then formulate an optimization problem that generates an\neffective switching strategy while considering the cost of switching between\ndifferent web-stack configurations. To incorporate this model into a developed\nMTD system, we develop an automated system for generating attack sets of Common\nVulnerabilities and Exposures (CVEs) for input attacker types with predefined\ncapabilities. Our framework obtains realistic reward values for the players\n(defenders and attackers) in this game by using security domain expertise on\nCVEs obtained from the National Vulnerability Database (NVD). We also address\nthe issue of prioritizing vulnerabilities that when fixed, improves the\nsecurity of the MTD system. Lastly, we demonstrate the robustness of our\nproposed model by evaluating its performance when there is uncertainty about\ninput attacker information.","url_abs":"http://arxiv.org/abs/1602.07024v3","url_pdf":"http://arxiv.org/pdf/1602.07024v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"moving-target-defense-for-web-applications","repo_url":"https://github.com/sailik1991/StackelbergEquilibribumSolvers","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":{"status":"unanswered"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}