论文标题

BASCP:行为决策如何影响网络物理系统的安全性?

BASCPS: How does behavioral decision making impact the security of cyber-physical systems?

论文作者

Abdallah, Mustafa, Woods, Daniel, Naghizadeh, Parinaz, Khalil, Issa, Cason, Timothy, Sundaram, Shreyas, Bagchi, Saurabh

论文摘要

我们研究了由多个相互依赖子系统组成的大规模网络物理系统(CPS)的安全性,每个系统由不同的防御者管理。防守者投资其安全预算的目的是阻止网络攻击对其关键资产的传播。我们将辩护人做出的安全投资决策建模为安全游戏。虽然先前的工作使用安全游戏来分析这种情况,但我们提出了行为安全游戏,其中捍卫者在行为经济学中表现出人类决策的特征,这些特征代表了典型的人类认知偏见。这很重要,因为我们目标系统类别中的许多关键安全决策都是由人类做出的。 我们通过受控的主题实验为我们的行为模型提供了经验证据。然后,我们表明,与非行为决策相比,行为决策会导致资源分配的次优模式。我们说明了使用两个代表性的现实世界相互依存的CPS做出行为决策的影响。特别是,我们确定了防御者的安全预算可用性和分配的影响,辩护人之间的相互依存程度以及协作防御策略对由于行为决策而导致的安全成果的次优度程度。在这种情况下,行为决策的不利影响在中等的国防预算中最严重。此外,随着属于不同防御者的子网之间的相互依赖程度的程度增加了行为次优决策的影响。我们还观察到,自私的防御决策以及行为决策会大大增加安全风险。

We study the security of large-scale cyber-physical systems (CPS) consisting of multiple interdependent subsystems, each managed by a different defender. Defenders invest their security budgets with the goal of thwarting the spread of cyber attacks to their critical assets. We model the security investment decisions made by the defenders as a security game. While prior work has used security games to analyze such scenarios, we propose behavioral security games, in which defenders exhibit characteristics of human decision making that have been identified in behavioral economics as representing typical human cognitive biases. This is important as many of the critical security decisions in our target class of systems are made by humans. We provide empirical evidence for our behavioral model through a controlled subject experiment. We then show that behavioral decision making leads to a suboptimal pattern of resource allocation compared to non-behavioral decision making. We illustrate the effects of behavioral decision making using two representative real-world interdependent CPS. In particular, we identify the effects of the defenders' security budget availability and distribution, the degree of interdependency among defenders, and collaborative defense strategies, on the degree of suboptimality of security outcomes due to behavioral decision making. In this context, the adverse effects of behavioral decision making are most severe with moderate defense budgets. Moreover, the impact of behavioral suboptimal decision making is magnified as the degree of the interdependency between subnetworks belonging to different defenders increases. We also observe that selfish defense decisions together with behavioral decisions significantly increase security risk.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源