Defensive Strategy Selection based on Attack-Defense Game Model in Network Security

Volume 14, Number 11, November 2018, pp. 2633-2642
DOI: 10.23940/ijpe.18.11.p9.26332642

Ningbin Zhang

School of Information Engineering of Xian University, Xian, 710062, China

(Submitted on August 2, 2018; Revised on September 15, 2018; Accepted on October 11, 2018)


Security analysis and attack-defense modeling are effective methods to identify the vulnerabilities of information systems for proactive defense. The attack graph model reflects only attack actions and system state changes, without considering the perspective of the defenders. To assess the network information system and comprehensively show attack and defense strategies and their cost, a defense graph model is proposed. Compared with the attack graph, the model makes some improvements. The defense graph will be mapped to the attack and defense game model, in order to provide a basis for active defense policy decision. Moreover, a generation algorithm of defense graph is proposed. A representative example is provided to illustrate our models and demonstrate the high efficiency of the algorithm.


