Authors:
Lu Li
1
;
1
;
Guanling Zhao
1
;
Kai Shi
2
and
Fengjun Zhang
2
Affiliations:
1
University of Electronic Science and Technology of China, Chengdu, China
;
2
The 30th Research Institute of China Electronics Technology Group Corporation, Chengdu, China
Keyword(s):
Cloud Platform, Stochastic Game Model, Stochastic Petri Nets, Markov Chains.
Abstract:
The extensive use of virtualization technologies in cloud platforms has caused traditional security measures to partially fail. It was a hard struggle for static protection mechanisms to get work done in time when facing constantly evolving network threats. In this paper, an active defense approach is proposed to address the dynamic and variable security threats in cloud environment. Stochastic game model is introduced to model the cloud platform security elements. An attack-defense payoff function and matrix are also defined based on the features of the cloud platform. To accurately describe the attack action and the corresponding defense action, the overall attack graph and single-point defense graph are optimized. Based on proposed game model and attack-defense graph, the optimal defense strategy algorithm for the cloud platform is designed. The optimal defense strategy is obtained after a multi-stage stochastic game considering the long-term gain. Finally, the model’s reliability
is evaluated using stochastic Petri nets and Markov chains. Experimental simulation demonstrates that the presented model outperforms the existing mainstream game models, such as the evolutionary game model and Bayesian game model, in terms of the optimal strategy, defense success rate, and steady-state availability.
(More)