Don't bury your head inwarnings: A game-theoretic approach for intelligent allocation of cyber-security alerts

30Citations
Citations of this article
31Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In recent years, there have been a number of successful cyber attacks on enterprise networks by malicious actors. These attacks generate alerts which must be investigated by cyber analysts to determine if they are an attack. Unfortunately, there are magnitude more alerts than cyber analysts - a trend expected to continue into the future creating a need to find optimal assignments of the incoming alerts to analysts in the presence of a strategic adversary. We address this challenge with the four following contributions: (1) a cyber allocation game (CAG) model for the cyber network protection domain, (2) an NP-hardness proof for computing the optimal strategy for the defender, (3) techniques to find the optimal allocation of experts to alerts in CAG in the general case and key special cases, and (4) heuristics to achieve significant scale-up in CAGs with minimal loss in solution quality.

Cite

CITATION STYLE

APA

Schlenker, A., Xu, H., Guirguis, M., Kiekintveld, C., Sinha, A., Tambe, M., … Dunstatter, N. (2017). Don’t bury your head inwarnings: A game-theoretic approach for intelligent allocation of cyber-security alerts. In IJCAI International Joint Conference on Artificial Intelligence (Vol. 0, pp. 381–387). International Joint Conferences on Artificial Intelligence. https://doi.org/10.24963/ijcai.2017/54

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free