The Experts below are selected from a list of 78 Experts worldwide ranked by ideXlab platform
Mahantesh Halappanavar - One of the best experts on this subject based on the ideXlab platform.
-
FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
-
ICDCS - FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
Sudip Saha - One of the best experts on this subject based on the ideXlab platform.
-
FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
-
ICDCS - FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
Edward A. Mcbean - One of the best experts on this subject based on the ideXlab platform.
-
Diminishing Marginal Returns for sensor networks in a water distribution system
Journal of Water Supply Research and Technology-aqua, 2011Co-Authors: Hailiang Shen, Edward A. McbeanAbstract:With increasing interest in the implementation/functionality of a contaminant warning system for water distribution systems, questions exist over the application to a real distribution system. A methodology is described to assess the impacts of changes in the numbers of sensors, on the time delay required to detect a contaminant intrusion event and to maximize sensor detection redundancy as protection against false positives. The methodology is used to explore the point of Diminishing Marginal Return of detection likelihood, and the average time delay of detected intrusion events. Pareto front performance improvement with increasing numbers of sensors (from 2 through 50) is characterized through a case study application to the City of Guelph water distribution system (WDS). The results provide a methodology for utilities to employ for decisions on the number of sensors to use for a system. Within the two scenarios applied, five and four sensors are shown to be the point of Diminishing Marginal Return for Guelph WDS in terms of the Pareto front performance improvement, detection likelihood, and the average time delay for the case study. Nevertheless, given that the timeframe to detect a contamination event may be lengthy, placing more sensors than the point of Diminishing Marginal Return may be appropriate.
-
Pareto Optimality for Sensor Placements in a Water Distribution System
Journal of Water Resources Planning and Management, 2011Co-Authors: Hailiang Shen, Edward A. McbeanAbstract:As society looks to provide the most effective identification of possible intrusion events, issues of sensor placement in water distribution systems are drawing increased attention. A multiple objective optimization problem with two competitive objectives is formulated herein: (1) minimize time delay, and (2) maximize sensor detection redundancy. The two objectives are evaluated, based on a prebuilt database containing the array of potential intrusion events and detection information. Pareto fronts are developed to assess impacts of increasing numbers of sensors by nondominated genetic algorithm-II (NSGA-II). Further, Pareto front performance improvement of increasing numbers of sensors is quantified by average normalized Euclidean distance to identify the point of Diminishing Marginal Return aiming to provide rationale for estimating the number of sensors needed for a water distribution system. A case study is conducted for the City of Guelph water distribution system. It is observed that increasing the ...
Anil Vullikanti - One of the best experts on this subject based on the ideXlab platform.
-
FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
-
ICDCS - FlipNet: Modeling Covert and Persistent Attacks on Networked Resources
2017 IEEE 37th International Conference on Distributed Computing Systems (ICDCS), 2017Co-Authors: Sudip Saha, Anil Vullikanti, Mahantesh HalappanavarAbstract:Persistent and zero-day attacks have increased considerably in the recent past in terms of scale and impact. Security experts can no longer rely only on known defenses and thereby protect their resources permanently. It is increasingly common now to observe attackers being able to repeatedly break systems exploiting new vulnerabilities and defenders hardening systems with new measures. To model this phenomenon of the repeated takeover of the computing resources by system administrators and malicious attackers, a novel game framework, FlipIt, has been proposed by (Van Dijk et al. 2013) for a system consisting of a single resource. In this paper, we extend this and develop FlipNet, which is a repeated game framework for a networked system of multiple resources. This game involves two players-a defender and an attacker. Each player's objective is to maximize its gain (i.e., its control over the nodes in the network with stealthy moves), while minimizing the cost for making those moves. This leads to a novel and natural game formulation, with a very complex strategy space, that depends on the network structure. We show that finding the best response strategy for both the defender and attacker is NP-hard. In a key result in this study, we show that the attacker's gain for an instance of the game has a type of Diminishing Marginal Return property, which leads to a near-optimal algorithm for maximizingthe attacker's gain. We examine the impact of network structure on the strategy space using simulations.
Jeffrey S Rosenschein - One of the best experts on this subject based on the ideXlab platform.
-
distributed multiagent resource allocation in Diminishing Marginal Return domains
Adaptive Agents and Multi-Agents Systems, 2008Co-Authors: Yoram Bachrach, Jeffrey S RosenscheinAbstract:We consider a multiagent resource allocation domain where the Marginal production of each resource is Diminishing. A set of identical, self-interested agents requires access to sharable resources in the domain. We present a distributed and random allocation procedure, and demonstrate that the allocation converges to the optimal in terms of utilitarian social welfare. The procedure is based on direct interaction among the agents and resource owners (without the use of a central authority). We then consider potential strategic behavior of the self-interested agents and resource owners, and show that when both act rationally and the domain is highly competitive for the resource owners, the convergence result still holds. The optimal allocation is arrived at quickly; given a setting with k resources and n agents, we demonstrate that the expected number of timesteps to convergence is O(k ln n), even in the worst case, where the optimal allocation is extremely unbalanced. Our allocation procedure has advantages over a mechanism design approach based on Vickrey-Clarke-Groves (VCG) mechanisms: it does not require the existence of a central trusted authority, and it fully distributes the utility obtained by the agents and resource owners (i.e., it is strongly budget balanced).
-
AAMAS (2) - Distributed multiagent resource allocation in Diminishing Marginal Return domains
2008Co-Authors: Yoram Bachrach, Jeffrey S RosenscheinAbstract:We consider a multiagent resource allocation domain where the Marginal production of each resource is Diminishing. A set of identical, self-interested agents requires access to sharable resources in the domain. We present a distributed and random allocation procedure, and demonstrate that the allocation converges to the optimal in terms of utilitarian social welfare. The procedure is based on direct interaction among the agents and resource owners (without the use of a central authority). We then consider potential strategic behavior of the self-interested agents and resource owners, and show that when both act rationally and the domain is highly competitive for the resource owners, the convergence result still holds. The optimal allocation is arrived at quickly; given a setting with k resources and n agents, we demonstrate that the expected number of timesteps to convergence is O(k ln n), even in the worst case, where the optimal allocation is extremely unbalanced. Our allocation procedure has advantages over a mechanism design approach based on Vickrey-Clarke-Groves (VCG) mechanisms: it does not require the existence of a central trusted authority, and it fully distributes the utility obtained by the agents and resource owners (i.e., it is strongly budget balanced).