• Home
  • Search
  • Game Theoretic Models for Cyber Deception
  • Open Access IconOpen Access
  • Cite Icon2
  • https://doi.org/10.1145/3474370.3485656Copy DOI Icon

Game Theoretic Models for Cyber Deception

  • Nov 15, 2021
  • Fei Fang
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Cyber deception has great potential in thwarting cyberattacks [1, 4, 8]. A defender (e.g., network administrator) can use deceptive cyber artifacts such as honeypots and faking services to confuse attackers (e.g., hackers) and thus reduce the success rate and effectiveness of attacks. However, the attackers are often diverse and some attackers may be aware of the deception and adapt to the defender's strategy. Therefore, when the defender designs the deception strategy, he needs to take into account the attacker's strategic response. Game theory is suitable for such strategic interaction between the defender and the attacker. Building upon our previous work on security games,[2, 3] we developed a series of game-theoretic models for cyber deception, as well as algorithms to compute the equilibrium or the optimal defender strategy in the games. The first model we proposed is the Cyber Deception Game, a zero-sum Stackelberg game between the defender and an adversary. In this game, the defender is tasked to protect a set of targets, where each target corresponds to a system or a node in a network. Each target has a true configuration, which consists of a set of attributes, e.g., an operating system, services hosted, etc. The defender can choose an observed configuration for each target when responding to probes and scans that may be launched by the attacker. The observed configuration can be different from the true configuration and thus the deception. The attacker, after collecting information about the observed configuration, chooses which target to attack. We show that finding the defender's optimal strategy is NP-hard and provides mixed-integer linear programming (MILP)-based algorithms to compute the optimal deception scheme, and also several heuristic algorithms. In a follow-up work,[7] we extended this game model to a general-sum one, which captures the fact that the cost for the defender may not always be equal to the gain of the attacker. The general-sum nature of this new game model leads to new computational challenges. We provided a Fully Polynomial Time Approximation Scheme (FPTAS) for solving the game and designed a MILP-based algorithm together with several techniques to speed up the computation. In a recent work,[5] we proposed a new attack graph-based Stackelberg security game model and analyze the optimal deception strategy the defender can use. In contrast to previous models, the attacker in this new game can take sequential actions to reach the targets, which is modeled as taking a path on the attack graph. The defender can strategically manipulate the attack graph through deceptive actions in addition to allocating defensive resources to protect important targets from attackers. We provided a MILP-based solution for a special class of attack graphs and a neural architecture search-based method for general directed acyclic attack graphs. We empirically demonstrated the benefit of deception in all these game models and the scalability of the algorithms. This talk features an introduction to these models and algorithms, together with a discussion on future research directions for game theory-based cyber deception.

Similar Papers
  • Conference Article
  • Citations4

Cyber Deception for Wireless Network Virtualization Using Stackelberg Game Theory

  • Jan 09, 2021
  • Abdulhamid A Adebayo +1
  • Conference Article

Computing optimal strategy against quantal response in security games

  • Jun 04, 2012
  • Rong Yang +2
  • Conference Article
  • Citations1

An attrition game with multiple start and destination points

  • Nov 01, 2017
  • Ryusuke Hohzaki +2
  • Book Chapter
  • Citations4

Honeypot Allocation Games over Attack Graphs for Cyber Deception

  • Sep 12, 2021
  • Ahmed H Anwar +3
  • Conference Article
  • Citations3

Broken Signals in Security Games: Coordinating Patrollers and Sensors in the Real World

  • May 08, 2019
  • Elizabeth Bondi +5
  • Research Article
  • Citations8

Optimal Network Defense Strategy Selection Based on Markov Bayesian Game

  • Nov 30, 2019
  • KSII Transactions on Internet and Information Systems
  • Zengguang Wang +3
  • Conference Article

Security games with partial surveillance

  • May 05, 2014
  • Fengli Wang +1
  • Book Chapter

Proactive Network Defense with Game Theory

  • Jan 01, 2019
  • Sinong Wang +1
  • Research Article
  • Citations7

Research on the game of network security attack‐defense confrontation through the optimal defense strategy

  • Nov 17, 2020
  • SECURITY AND PRIVACY
  • Fei Liu +2
  • PDF
  • Research Article
  • Citations6

Optimal defense strategy for AC/DC hybrid power grid cascading failures based on game theory and deep reinforcement learning

  • Mar 31, 2023
  • Frontiers in Energy Research
  • Xiangli Deng +4
  • Conference Article
  • Citations2

Towards Reconstructing Multi-Step Cyber Attacks in Modern Cloud Environments with Tripwires

  • Nov 18, 2020
  • Mario Kahlhofer +2
  • Research Article
  • Citations34

Intelligence and impact contests in systems with redundancy, false targets, and partial protection

  • Jun 30, 2009
  • Reliability Engineering & System Safety
  • Gregory Levitin +1
  • Research Article

Evaluating Synthetic Cyber Deception Strategies Under Uncertainty via Game Theory Approach: Linking Information Leakage and Game Outcomes in Cyber Deception.

  • Mar 10, 2026
  • Sensors (Basel, Switzerland)
  • Mohammad Shahin +2
  • Research Article
  • Citations19

On repeated stackelberg security game with the cooperative human behavior model for wildlife protection

  • Oct 13, 2018
  • Applied Intelligence
  • Binru Wang +3
  • Single Report

Faster EPTAS for Scheduling on Uniform Machines

  • Oct 01, 2025
  • Klaus Jansen +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.