Javascript must be enabled to continue!
Modeling the effects of different honeypot proportions in a deception-based security game
View through CrossRef
Cyber-attacks, an intentional effort to steal information or interrupt the network, are growing dramatically. It is of great importance to understand how an adversary’s behavior might impact the detection of threats. Prior research in adversarial cybersecurity has investigated the effect of different honeypot variations on adversarial decisions in a deception-based game experimentally. However, it is unknown how different honeypot variation affects adversarial decisions using cognitive models. The primary objective of this research is to develop the cognitive model using Instance-based learning theory (IBLT) to make predictions for decisions for networks with different honeypot proportions. The experimental study involved the use of a deception game (DG): small, medium, and large. The DG is defined as DG (n, k, γ), where n is the number of servers, k is the number of honeypots, and γ is the number of probes that the opponent makes before attacking the network. The DG had three between-subject conditions, which denoted three different honeypot proportions. Human data in the experimental study was collected by recruiting 60 participants who were randomly assigned one of the three between-subject conditions of the deception game (N = 20 per condition). The results revealed with an increase in the proportion of honeypots, the honeypot and no-attack actions increased significantly. Next, we built two Instance-based Learning (IBL) models, an IBL model with calibrated parameters (IBL-calibrated) and an IBL model with ACT-R parameters (IBL-ACT-R), to account for human decisions in conditions involving different honeypot proportions in a deception-based security game. It was found that both IBL-calibrated and IBL-ACT-R models were able to account for human behavior across different experimental conditions. In addition, results revealed a greater reliance on the recent and frequent occurrence of events among the human participants. We highlight the key importance of our research for the field of cognitive modelling.
Title: Modeling the effects of different honeypot proportions in a deception-based security game
Description:
Cyber-attacks, an intentional effort to steal information or interrupt the network, are growing dramatically.
It is of great importance to understand how an adversary’s behavior might impact the detection of threats.
Prior research in adversarial cybersecurity has investigated the effect of different honeypot variations on adversarial decisions in a deception-based game experimentally.
However, it is unknown how different honeypot variation affects adversarial decisions using cognitive models.
The primary objective of this research is to develop the cognitive model using Instance-based learning theory (IBLT) to make predictions for decisions for networks with different honeypot proportions.
The experimental study involved the use of a deception game (DG): small, medium, and large.
The DG is defined as DG (n, k, γ), where n is the number of servers, k is the number of honeypots, and γ is the number of probes that the opponent makes before attacking the network.
The DG had three between-subject conditions, which denoted three different honeypot proportions.
Human data in the experimental study was collected by recruiting 60 participants who were randomly assigned one of the three between-subject conditions of the deception game (N = 20 per condition).
The results revealed with an increase in the proportion of honeypots, the honeypot and no-attack actions increased significantly.
Next, we built two Instance-based Learning (IBL) models, an IBL model with calibrated parameters (IBL-calibrated) and an IBL model with ACT-R parameters (IBL-ACT-R), to account for human decisions in conditions involving different honeypot proportions in a deception-based security game.
It was found that both IBL-calibrated and IBL-ACT-R models were able to account for human behavior across different experimental conditions.
In addition, results revealed a greater reliance on the recent and frequent occurrence of events among the human participants.
We highlight the key importance of our research for the field of cognitive modelling.
Related Results
Schule und Spiel – mehr als reine Wissensvermittlung
Schule und Spiel – mehr als reine Wissensvermittlung
Die öffentliche Schule Quest to learn in New York City ist eine Modell-Schule, die in ihren Lehrmethoden auf spielbasiertes Lernen, Game Design und den Game Design Prozess setzt. I...
AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
The development of adaptive and intelligent defense mechanisms will require new approaches to defending against
sophisticated cyber threats that can't be fully supported by existin...
Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Dalam era digital yang semakin kompleks ini, keamanan sistem informasi menjadi masalah penting bagi organisasi di berbagai industri. Peningkatan serangan siber serta polanya yang s...
Self-deception
Self-deception
Philosophical work on self-deception revolves around a trio of questions. What is self-deception? Is self-deception possible? How are cases of self-deception to be explained? The e...
Self-deception
Self-deception
Philosophical work on self-deception revolves around a trio of questions. What is self-deception? Is self-deception possible? How are instances of self-deception to be explained? T...
Information Security in Artificial Intelligence: A Study of the possible intersection
Information Security in Artificial Intelligence: A Study of the possible intersection
1. IntroductionArtificial Intelligence or A.I attempts to understand intelligent entities, and strives to build ones. And it is obvious that computers with human-level intelligence...
Studi Deskriptif Perilaku Online Deception pada Mahasiswa Pengguna Instagram
Studi Deskriptif Perilaku Online Deception pada Mahasiswa Pengguna Instagram
Abstract. The development of information and communication technology has changed the social interaction patterns of Indonesian society. Instagram as one of the dominant platforms ...

