Counterplanning deceptions to foil cyber-attack plans

20Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Tactics involving deception are important in military strategies. We have been exploring deliberate deception in defensive tactics by information systems under cyber-attack as during information warfare. We have developed a tool to systematically "counterplan" or find ways to foil a particular attack plan. Our approach is to first find all possible atomic "ploys" that can interfere with the plan. Ploys are simple deceits the operating system can do such as lying about the status of a file. We analyze ploys as to the degree of difficulty they cause to the plan wherever they can be applied. We then formulate a "counterplan" by selecting the most cost-effective set of ploys and assign appropriate presentation methods for them, taking into account the likelihood that, if we are not careful, the attacker will realize they are being deceived and will terminate our game with them. The counterplan can be effected by a modified operating system. We have implemented our counterplanner in a tool MECOUNTER that uses multiagent planning coupled with some novel inference methods to efficiently find a best counterplan. We apply the tool to an example of a rootkit-installation plan and discuss the results.

Cite

CITATION STYLE

APA

Rowe, N. C. (2003). Counterplanning deceptions to foil cyber-attack plans. In IEEE Systems, Man and Cybernetics Society Information Assurance Workshop (pp. 221–228). Institute of Electrical and Electronics Engineers Inc. https://doi.org/10.1109/SMCSIA.2003.1232425

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free