paper-with-me

홈 › Papers

Catch Me if You Can: Effective Honeypot Placement in Dynamic AD Attack Graphs

2023-12-28 · Huy Quang Ngo, Mingyu Guo, Hung Nguyen

We study a Stackelberg game between an attacker and a defender on large Active Directory (AD) attack graphs where the defender employs a set of honeypots to stop the attacker from reaching high-value targets. Contrary to existing works that focus on small and static attack graphs, AD graphs typically contain hundreds of thousands of nodes and edges and constantly change over time. We consider two types of attackers: a simple attacker who cannot observe honeypots and a competent attacker who can. To jointly solve the game, we propose a mixed-integer programming (MIP) formulation. We observed that the optimal blocking plan for static graphs performs poorly in dynamic graphs. To solve the dynamic graph problem, we re-design the mixed-integer programming formulation by combining m MIP (dyMIP(m)) instances to produce a near-optimal blocking plan. Furthermore, to handle a large number of dynamic graph instances, we use a clustering algorithm to efficiently find the m-most representative graph instances for a constant m (dyMIP(m)). We prove a lower bound on the optimal blocking strategy for dynamic graphs and show that our dyMIP(m) algorithms produce close to optimal results for a range of AD graphs under realistic conditions.

📄 PDF Abstract BibTeX arXiv:2312.16820

Code (0)

등록된 구현이 없습니다.

Tasks

Blocking

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically
Focus 설명 없음

Similar Papers 제목 키워드 기반

A Partial Break of the Honeypots Defense to Catch Adversarial Attacks

2020-09-23 · Nicholas Carlini

A recent defense proposes to inject "honeypots" into neural networks in order to detect adversarial attacks. We break the baseline version of this defense by reducing the detection true positive rate to 0\% and the detec…

Gotta Catch 'Em All: Using Honeypots to Catch Adversarial Attacks on Neural Networks

2019-04-18 · Shawn Shan, Emily Wenger, Bolun Wang, Bo Li 외

Deep neural networks (DNN) are known to be vulnerable to adversarial attacks. Numerous efforts either try to patch weaknesses in trained models, or try to make it difficult or costly to compute adversarial examples that …

Adversarial AttackAdversarial Attack DetectionAdversarial DefenseAll+3

A Sweet Rabbit Hole by DARCY: Using Honeypots to Detect Universal Trigger's Adversarial Attacks

2020-11-20 · ACL 2021 5 · Thai Le, Noseong Park, Dongwon Lee

The Universal Trigger (UniTrigger) is a recently-proposed powerful adversarial textual attack method. Utilizing a learning-based mechanism, UniTrigger generates a fixed phrase that, when added to any benign inputs, can d…

Adversarial Attack

LLM in the Shell: Generative Honeypots

2023-08-31 · Muris Sladić, Veronica Valeros, Carlos Catania, Sebastian Garcia

Honeypots are essential tools in cybersecurity for early detection, threat intelligence gathering, and analysis of attacker's behavior. However, most of them lack the required realism to engage and fool human attackers l…

Security Orchestration, Automation, and Response Engine for Deployment of Behavioural Honeypots

2022-01-14 · Upendra Bartwal, Subhasis Mukhopadhyay, Rohit Negi, Sandeep Shukla

Cyber Security is a critical topic for organizations with IT/OT networks as they are always susceptible to attack, whether insider or outsider. Since the cyber landscape is an ever-evolving scenario, one must keep upgrad…

Intrusion DetectionManagement