• Home
  • Search
  • Multi-stage Dynamic Information Flow Tracking Game
  • Cite Icon14
  • https://doi.org/10.1007/978-3-030-01554-1_5Copy DOI Icon

Multi-stage Dynamic Information Flow Tracking Game

  • Jan 1, 2018
  • Shana Moothedath +5 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Advanced persistent threats (APTs) consist of multiple attack stages between entry and exit points of the attack. In each stage of the attack, the adversary gathers more privileges, resources, and information about the system and uses this information to gain access to the targeted data of the next stage to reach the final goal. APTs are not only persistent but also stealthy and hence difficult to detect. The persistent nature of APTs, however, creates information flows in the system that can be monitored. One monitoring mechanism is Dynamic Information Flow Tracking (DIFT), which taints and tracks malicious information flows through a system and inspects the flows at designated traps. Since tainting all flows in the system will incur prohibitive resource costs, efficient tagging policies are needed to decide which flows to tag in order to maximize the probability of APT detection while minimizing resource overhead. At present such an analytical model for DIFT for multi-stage APT detection does not exist. In this paper, we propose a game theoretic framework modeling real-time detection of multi-stage APTs via DIFT. We formulate a two-player (APT vs DIFT) nonzero-sum stochastic game with incomplete information to obtain an optimal tagging policy. Our game model consists of a sequence of stages, where each stage of the game corresponds to a stage in the attack. At each stage, the goal of the APT is to reach a particular destination, corresponding to a targeted resource or privilege, while the goal of the defender is to detect the APT. We first derive an efficient algorithm to find locally optimal strategies for both players. We then characterize the best responses of both players and present algorithms to find the best responses. Finally, we validate our results on a real-world attack data set obtained using the Refinable Attack INvestigation (RAIN) framework for a ScreenGrab attack.

Similar Papers
  • Conference Article
  • Citations1

Dynamic Defense against Adaptive and Persistent Adversaries

  • Jan 15, 2018
  • Radha Poovendran
  • Conference Article
  • Citations3

Quickest Detection of Advanced Persistent Threats: A Semi-Markov Game Approach

  • Apr 01, 2020
  • Dinuka Sahabandu +5
  • Conference Article
  • Citations6

A small and adaptive coprocessor for information flow tracking in ARM SoCs

  • Nov 06, 2018
  • Muhammad Abdul Wahab +6
  • Conference Article

Advanced Persistent Threat (APT) Detection Using Context-Aware Machine Learning Models

  • Jun 19, 2025
  • R N Bhavanavika +1
  • PDF
  • Research Article
  • Citations78

Hidden Markov Models and Alert Correlations for the Prediction of Advanced Persistent Threats

  • Jan 01, 2019
  • IEEE Access
  • Ibrahim Ghafir +6
  • Book Chapter
  • Citations2

Detection and Defense Methods of Cyber Attacks

  • Jan 01, 2021
  • Kai Xing +3
  • Research Article

Cyber Guardian : Intelligent Threat Surveillance

  • Feb 08, 2024
  • International Journal of Advanced Research in Science, Communication and Technology
  • Aditi H R +2
  • PDF
  • Research Article
  • Citations24

Machine Learning for APT Detection

  • Sep 16, 2023
  • Sustainability
  • Abdullah Said Al-Aamri +5
  • Conference Article
  • Citations16

WHISK: An uncore architecture for Dynamic Information Flow Tracking in heterogeneous embedded SoCs

  • Sep 01, 2013
  • Joel Porquet +1
  • Research Article
  • Citations5

Detecting APT-Exploited Processes through Semantic Fusion and Interaction Prediction

  • Jan 01, 2024
  • Computers, Materials & Continua
  • Bin Luo +3
  • Research Article
  • Citations286

Detection of advanced persistent threat using machine-learning correlation analysis

  • Jul 06, 2018
  • Future Generation Computer Systems
  • Ibrahim Ghafir +6
  • PDF
  • Research Article
  • Citations14

ConGraph: Advanced Persistent Threat Detection Method Based on Provenance Graph Combined with Process Context in Cyber-Physical System Environment

  • Feb 29, 2024
  • Electronics
  • Linrui Li +1
  • Research Article
  • Citations128

Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency

  • Feb 04, 2020
  • IEEE Transactions on Dependable and Secure Computing
  • Chunlin Xiong +8
  • Research Article
  • Citations50

A Hierarchical Approach for Advanced Persistent Threat Detection with Attention-Based Graph Neural Networks

  • May 04, 2021
  • Security and Communication Networks
  • Zitong Li +4
  • Conference Article
  • Citations1

ARMHEx: A framework for efficient DIFT in real-world SoCs

  • Jul 07, 2017
  • Muhammad Abdul Wahab +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.