Variations of the Flip-It game have been applied to model network cyber operations. While Flip-It can accurately express uncertainty and loss of control, it imposes no essential resource constraints for operations. Capture the flag (CTF) style competitive games, such as Flip-It , entail uncertainties and loss of control, but also impose realistic constraints on resource use. As such, they bear a closer resemblance to actual cyber operations. We formalize a dynamical network control game for CTF competitions and detail the static game for each time step. The static game can be reformulated as instances of a novel optimization problem called Adversarial Knapsack (AK) or Dueling Knapsack (DK) when there are only two players. We define the Adversarial Knapsack optimization problems as a system of interacting Weighted Knapsack problems, and illustrate its applications to general scenarios involving multiple agents with conflicting optimization goals, e.g., cyber operations and CTF games in particular. Common awareness of the scenario, rewards, and costs will set the stage for a non-cooperative game. Critically, rational players may second guess that their AK solution -- with a better response and higher reward -- is possible if opponents predictably play their AK optimal solutions. Thus, secondary reasoning which such as belief modeling of opponents play can be anticipated for rational players and will introduce a type of non-stability where players maneuver for slight reward differentials. To analyze this, we provide the best-response algorithms and simulation software to consider how rational agents may heuristically search for maneuvers. We further summarize insights offered by the game model by predicting that metrics such as Common Vulnerability Scoring System (CVSS) may intensify the secondary reasoning in cyber operations.
翻译:Flip-It游戏的变体已被应用于网络行动建模。虽然Flip-It能准确表达不确定性和控制权损失,但未对行动施加本质资源约束。夺旗赛(CTF)类竞争性游戏(如Flip-It)同样包含不确定性与控制权丧失,但同时对资源使用施加了现实约束,因此更接近实际网络行动。我们为CTF竞赛形式化了一个动态网络控制博弈模型,并详细描述了每个时间步的静态博弈。该静态博弈可重构为一种新型优化问题——对抗性背包问题(AK)或双人情形下的决斗背包问题(DK)。我们将对抗性背包优化问题定义为相互作用的加权背包问题系统,并阐明其在涉及多智能体且优化目标冲突的通用场景(特别是网络行动与CTF游戏)中的应用。对场景、奖励和成本的共同认知将奠定非合作博弈的基础。关键在于,理性参与者可能预判:若对手可预测地执行AK最优解,则其自身通过更优响应获取更高奖励的AK解是可能的。因此,对理性参与者而言,可预期其将采用对手行为信念建模等次级推理,从而引发一种非稳定性——参与者为微小奖励差异展开博弈。为分析此现象,我们提供最优响应算法与仿真软件,研究理性智能体如何通过启发式搜索寻找机动策略。我们进一步总结博弈模型揭示的洞见,预测通用漏洞评分系统(CVSS)等指标可能加剧网络行动中的次级推理。