This paper explores coordinated deception strategies by synchronizing defenses across coupled cyber and physical systems to mislead attackers and strengthen defense mechanisms. We introduce a Stackelberg game framework to model the strategic interaction between defenders and attackers, where the defender leverages CVSS-based exploit probabilities and real-world vulnerability data from the National Vulnerability Database (NVD) to guide the deployment of deception. Cyber and physical replicas are used to disrupt attacker reconnaissance and enhance defensive effectiveness. We propose a CVE-based utility function to identify the most critical vulnerabilities and demonstrate that coordinated multilayer deception outperforms single-layer and baseline strategies in improving defender utility across both CVSS versions.
翻译:本文探讨通过同步耦合网络与物理系统的防御,以误导攻击者并强化防御机制的协同欺骗策略。我们引入Stackelberg博弈框架来建模防御者与攻击者之间的策略互动,其中防御者利用基于CVSS的漏洞利用概率及来自美国国家漏洞数据库(NVD)的真实漏洞数据来指导欺骗部署。网络与物理副本被用于干扰攻击者侦察并提升防御效能。我们提出一种基于CVE的效用函数以识别最关键的漏洞,并证明在提升防御者效用方面,协同多层欺骗策略在CVSS两个版本中均优于单层及基线策略。