A five-stage Bayesian Stackelberg security game with five stage-specific actions per player is formulated, which examines whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known.
Abstract
We examine whether simulated attack-action evidence can inform a defender that they must commit before an attacker’s type is known. We formulate a five-stage Bayesian Stackelberg security game with five stage-specific actions per player. A Monte Carlo predictor produces type-conditioned action likelihoods on an enterprise graph, while prediction confidence weights the next Bayesian update. The defender strategy is computed by exact follower-response enumeration and linear programming. Evaluation used a simulated 10-node enterprise network, 30 paired trials, bootstrap confidence intervals, and Holm-adjusted Wilcoxon tests. Against a fixed-prior Bayesian Strong Stackelberg Equilibrium, mean gross defense utility increased from 2.141 to 2.197. Mean attack success decreased from 0.691 to 0.686. The paired differences remained significant after multiplicity correction. Outcomes did not differ significantly from an equilibrium updated with coarse reference likelihoods, and the simulation cost reduced net utility by 0.08. Maximum follower regret and constraint violation remained at the specified numerical tolerance. Runtime remained near 0.39 s across networks of 10–100 nodes. An action/type experiment showed rapid growth as follower-response profiles increased. Exact commitment and sequential updating were feasible in the abstraction; simulation was not automatically cost-effective when a usable reference model was available.
We model insider threat detection as a dynamic Bayesian game in which a platform coordinates a committee of strategic certifiers to sustain equilibrium among honest users and detect malicious deviations before exfiltration. Certifiers and users operate under a Bayesian Temporal Correlated Equilibrium (BTCE), where a se...
Javed M Shah, Ian A. Kash, Natalie Parde· 0 citations
An empirical evaluation in a cybersecurity case study with two networks and real vulnerabilities drawn from CVE and scored using the Common Vulnerability Scoring System shows that QSE beats Stackelberg in realized defender utility spanning 144 scenarios with specification errors and 25 parameter configurations.
Asif Rahman, Md Abu Sayed, Ahmed Ann Noor Ryen et al.· 0 citations
Modern Security Operations Centers struggle with delayed manual incident response, enabling adversaries to advance through the Cyber Kill Chain during early stage reconnaissance. While classical game theoretic defense models optimize strategic resource allocation, they rely on static utility matrices that fail to adapt...
Interconnected systems can suffer infectious attacks, where the compromise of one node exposes neighboring nodes and may trigger cascading loss. Existing Stackelberg and network-defense models usually address only part of this setting: a centralized defender, independent targets, or no post-attack resource transfer. Th...
Lei Cui, Yifan Li, Shuhan Qi et al.· Journal of King Saud Univers...· 0 citations
The model uses an aggregated representation of system components as an aggregation of an attack graph built with the Meta Attack Language together with a stochastic initialization of initial conditions, which reduces the dimensionality of the state space and ensures the computational tractability of the analysis.
We study state-adversarial Markov decision processes (SA-MDPs) as games of observation-space attacks: at each step, an agent selects an action from a received observation while an adversary$\unicode{x2014}$who knows the true state the agent is in$\unicode{x2014}$chooses a perturbed observation within a state-dependent...