Source-linked AI summary
A Game-Theoretic Taxonomy and Survey of Defensive Deception for Cybersecurity and Privacy
Jeffrey Pawlick, Edward Colbert, Quanyan Zhu
TL;DR
Cybersecurity and privacy threats persist despite conventional defenses, while defenders often lack understanding of adversaries and users face ubiquitous tracking. The paper surveys game-theoretic defensive-deception research and develops a taxonomy of six deception types, providing a common foundation and models for future work.
Problem
Conventional defenses cannot fully address emerging cybersecurity and privacy threats, while adversaries may gain undetected access and defenders lack sufficient understanding of the threats they face.
Method
The paper surveys game-theoretic defensive-deception research and classifies six types using private information, actors, actions, and duration.
Results
The taxonomy distinguishes perturbation, moving target defense, obfuscation, mixing, honey-x, and attacker engagement, defining them through game-theoretic principles.
Takeaways & Limitations
The taxonomy provides a common language, a scientific foundation, and a menu of game-theoretic models and defensive-deception techniques for future research.
Takeaways & Limitations
Game-theoretic cybersecurity implementations are difficult to identify, and collaboration between security analysts and academic game theorists is challenging.
Abstract
from arXiv · showhide
Cyberattacks on both databases and critical infrastructure have threatened public and private sectors. Ubiquitous tracking and wearable computing have infringed upon privacy. Advocates and engineers have recently proposed using defensive deception as a means to leverage the information asymmetry typically enjoyed by attackers as a tool for defenders. The term deception, however, has been employed broadly and with a variety of meanings. In this paper, we survey 24 articles from 2008-2018 that use game theory to model defensive deception for cybersecurity and privacy. Then we propose a taxonomy that defines six types of deception: perturbation, moving target defense, obfuscation, mixing, honey-x, and attacker engagement. These types are delineated by their information structures, agents, actions, and duration: precisely concepts captured by game theory. Our aims are to rigorously define types of defensive deception, to capture a snapshot of the state of the literature, to provide a menu of models which can be used for applied research, and to identify promising areas for future work. Our taxonomy provides a systematic foundation for understanding different types of defensive deception commonly encountered in cybersecurity and privacy.
1. INTRODUCTION
Deception is presented as a longstanding feature of military combat and adversarial strategic interaction, motivating its study across several disciplines.
- Deception has played an important role in military combat and occurs broadly in adversarial or strategic interactions.The paper connects its motivation to deception research in psychology, criminology, economics, and behavioral sciences.
1.1. Deception Across Disciplines
The paper situates deception across military, cybersecurity, privacy, economics, psychology, and criminology, encompassing both malicious exploitation and benign protection.
- Military deception has received sustained attention, while globalization and communication technologies create additional challenges for mitigating deception.The paper also links increased information availability with greater confusion and discusses state-sponsored advanced persistent threats.
- Psychology and criminology research reports poor human deception-detection ability and studies interview and physiological methods for improving detection.Examples include reverse-order recall, eye contact, unexpected questions, and physiological responses to crime-related items.
- Cybersecurity defenses address malicious deception such as phishing, man-in-the-middle attacks, and forged-identity nodes.The passage also mentions adversarial machine learning and trust management as related defensive areas.
- Privacy technologies use benign deception to obscure digital activity and frustrate ubiquitous tracking.TrackMeNot issues random search queries, while CacheCloak retrieves location services through multiple possible paths.
- Economic research studies strategic communication under unverifiable information and shows that agents may avoid deception despite compatible incentives.Behavioral-economic work identifies lying aversion as one reason agents do not always maximize payoffs through deception.
- Broader economics literature models deception as equilibrium exploitation of vulnerable or uninformed groups across markets and institutions.Examples span politics, pharmaceuticals, finance, advertising, and phishing-like interactions.
1.2. Cybersecurity and Privacy
The paper introduces major data breaches and intrusions into critical infrastructure as evidence that cyberattacks affect both public and private sectors.
- More than 4000 publicized data breaches occurred from 2005 to 2015, alongside intrusions affecting power, nuclear, and water infrastructure.Named incidents include breaches at Home Depot, Anthem, and the U.S. Office of Personnel Management.
1.3. Defensive Deception
Defensive deception addresses attackers’ information advantage, but the field needs finer definitions to distinguish techniques and support purposeful design.
- Firewalls, cryptography, and role-based access control do not fully address emerging cybersecurity and privacy threats.Attackers may obtain insider access and reconnaissance information while defenders lack understanding of the threats they face.
- Defensive deception is motivated as a way to counteract information asymmetry between attackers and defenders.The paper frames deception as intentionally influencing another agent’s beliefs.
- The broad meaning of deception supports diverse applications but limits conceptual depth and complicates technique design.The authors argue that finer-resolution definitions are needed for specific purposes.
- The proposed taxonomy distinguishes terms such as moving target defense, perturbation, and obfuscation whose meanings are not completely clear.One motivating question is how perturbation differs from obfuscation.
1.4. Game-Theoretic Taxonomy
The paper uses game theory as a quantitative framework for distinguishing defensive-deception types by their information structure, actors, actions, and duration. This taxonomy is intended to match models to the essential features of each deception type.
- The paper treats deceptive interactions as strategic confrontations between rational agents suitable for quantitative analysis with game theory.
- Game theory models the information structure, actors, actions, and duration that differentiate defensive-deception types.
- The taxonomy is motivated by the need to identify which features of each deception type game-theoretic models must capture.
1.5. Contributions and Related Work
The paper surveys game-theoretic work on defensive deception and develops a taxonomy grounded in distinctions that support accurate modeling. Its scope is restricted to cybersecurity or privacy, defensive deception, and game-theory studies.
- Contributions: The authors review game-theoretic models commonly used to study cybersecurity and privacy.
- Contributions: They survey 24 articles from 2008–2018 on game-theoretic models of defensive deception.
- Contributions: The taxonomy defines perturbation, moving target defense, mixing, obfuscation, honey-x, and attacker engagement using private information, actors, actions, and duration.
- Contributions: The paper identifies future research areas including mimetic deception, theoretical advances, practical implementations, and interdisciplinary security.
- Scope: The reviewed literature is limited to studies combining cybersecurity or privacy, defensive deception, and game theory, excluding physical-security and malicious-deception research.
- Related Work: Related taxonomies classify deception by visibility, stages, or techniques, whereas this taxonomy uses game-theoretic distinctions to support accurate modeling.
2. REVIEW OF GAME-THEORETIC MODELS
The paper introduces Stackelberg, Nash, and signaling games as models for defensive deception, distinguished by their information structures, actors, actions, and timing. These models capture leader-follower responses, simultaneous strategic commitment, and private-information signaling.
- Game-Theoretic Taxonomy: The framework organizes these game models by their players, available actions, utilities, information, beliefs, and timing, providing the structure for the paper’s deception taxonomy.Table I summarizes game components used to distinguish deception types.
- Stackelberg Game: Stackelberg games model a leader L choosing an action before follower F responds after observing it.Cybersecurity models often represent the defender as leader and attacker as follower.
- Stackelberg Game: Stackelberg games are solved backward using the follower’s best-response function BRF(aL), which maps each leader action to optimal follower actions.The leader selects an action maximizing utility given the follower’s anticipated response.
- Nash Game: Nash games represent prior commitment: players choose strategies simultaneously, without knowing the other player’s action.A Nash equilibrium requires each player’s strategy to be optimal given the other player’s strategy.
- Nash Game: Mixed strategies let Nash-game players randomize actions, supporting randomized allocation of defense assets to avoid leaving predictable vulnerabilities.These strategies are probability distributions over actions.
- Signaling Game: Signaling games model a sender S with private type information sending a message to receiver R, who updates beliefs about that type using Bayes’ law.The sender’s message may not correspond directly to the sender’s type, and equilibrium combines utility maximization with consistent beliefs.
3. LITERATURE SURVEY
The survey reviews game-theoretic models of defensive deception across privacy, moving target defense, obfuscation, and honey-x applications. These models use different game structures to represent strategic interactions, information, configurations, and attacker behavior.
- The survey examines existing game-theoretic approaches to defensive deception for cybersecurity and privacy.
- Privacy: Privacy studies model trade-offs between data utility and privacy using perturbation, differential privacy, distortion privacy, and pseudolocations.Models include Nash and Stackelberg games involving users, analysts, attackers, and location-based services.
- Moving Target Defense: Moving target defense models randomize or dynamically change system configurations, attack surfaces, or intrusion-detection placements.Approaches include mixed-strategy Stackelberg games, Markov decision processes, and combined Markov-Stackelberg models.
- Obfuscation: Obfuscation models add deceptive or irrelevant traffic and data to protect real communications, privacy, or user profiles.Examples include deceptive routing, randomized search queries, and technologies that append irrelevant information to communications.
- Honey-X: Honey-x studies model decoys, honeypots, fake avatars, and deceptive signaling that influence attacker beliefs and actions.The surveyed models use signaling games, attack graphs, and dynamic strategies to represent deception and network hardening.
4. TAXONOMY
The taxonomy distinguishes defensive deception types by their strategic and informational structures. It identifies six types spanning privacy protection, reconnaissance resistance, decoying, unlinkability, honeypots, and sustained attacker manipulation.
- The taxonomy responds to unclear and broad usage of deception terminology in cybersecurity and privacy.
- The paper defines six types: perturbation, moving target defense, obfuscation, mixing, honey-x, and attacker engagement.The types are precisely defined using game-theoretic principles.
- Perturbation: Perturbation uses noise to limit leakage of sensitive information in privacy settings.
- Moving Target Defense: Moving target defense uses randomization and reconfiguration of networks, assets, and defense tools to limit attacker reconnaissance.
- Obfuscation: Obfuscation directs attackers toward decoy targets or reveals useless information alongside real information.
- Mixing: Mixing uses exchange systems such as mix networks and mix zones to prevent linkability.
- Honey-X: Honey-x disguises valuable network assets as honeypots or draws attackers toward specific systems such as honeypots.
- Attacker Engagement: Attacker engagement uses feedback to dynamically influence attackers over an extended period while wasting resources and gathering intelligence.
4.1. Detailed Definition of Each Type of Deception
The taxonomy distinguishes defensive-deception species using game-theoretic differences in private information, players, actions, and time horizon. It separates cryptic deception, which hides reality, from mimetic deception, which presents false or conspicuous objects, and further distinguishes intensive, extensive, static, and dynamic forms.
- Taxonomy principles: The taxonomy uses private information Θ, players P, actions A, and time horizon T as the specific differences separating deception species.These game-theoretic principles define the taxonomy’s fine-grained categories.
- Private information: Cryptic deception hides real information, while mimetic deception presents false information or attracts attention.The paper adopts crypsis for hiding the real and mimesis for showing the false.
- Infimae species: The infimae species include perturbation, moving target defense, obfuscation, mixing, honey-x, and attacker engagement.The taxonomy’s tree diagram organizes these species according to the four game-theoretic differences.
- Actors: Intensive deception modifies the actor or its representation, whereas extensive deception hides an object using other objects in the environment.Adding noise to private data illustrates intensive deception; dynamically changing the data’s location illustrates extensive deception.
- Actions: Within cryptic deception, information-based actions create noise, while motion-based actions modify properties over time or realize them randomly.The distinction concerns whether deception manipulates released data or changes properties through time or randomization.
- Duration: Within mimetic deception, honey-x denotes static honeypots, honeynets, and honeytokens, while attacker engagement denotes dynamic mimetic deception.Static games involve one interaction; dynamic games involve multiple interactions.
4.2. Synthesizing the Taxonomy
The survey maps defensive-deception species to game-theoretic models and finds useful trends without a one-to-one species-to-game correspondence. It overlays promising modeling approaches while preserving alternative possibilities.
- Taxonomy structure: The taxonomy’s species are mutually exclusive because they use mutually exclusive specific differences, and their ordering does not affect classification.This also permits representation as a four-dimensional binary lattice.
- Border cases: Border cases show that obfuscation and perturbation differ by whether noise is external or applied to the valuable information itself.The paper describes these species as having a Hamming distance of one.
- Classification of literature: The literature does not have a one-to-one mapping between deception species and games because models capture different interaction aspects and the field and threat landscape evolve.Most surveyed crypsis papers use Nash or Stackelberg games.
- Observed model trends: Mixing studies use Nash games or related concepts, while user-adversary interactions in perturbation and obfuscation generally use Stackelberg games.The distinction follows from simultaneous participation decisions in mix networks and differing interaction structures.
- Observed model trends: Moving target defense is modeled either with mixed strategies for randomized configurations or Markov decision processes for temporal changes.These approaches represent randomness and explicit evolution of defensive characterizations, respectively.
- Mimetic models: Honey-x uses signaling games or Bayesian Nash games, whereas attacker engagement uses dynamic approaches including multiple-period games and Markov decision processes.The latter models repeated interactions and state information from prior periods.
- Promising modeling approaches: Incomplete-information non-cooperative games suit mimetic deception, with signaling games for honey-x and partially observable stochastic games for attacker engagement.Within cryptic deception, two-player models often suffice for intensive deception, while extensive deception involves multiple defenders.
5. DISCUSSION AND FUTURE DIRECTIONS
The discussion identifies ethical, theoretical, deployment, and interdisciplinary challenges for defensive deception research. It concludes that the taxonomy supplies a common scientific foundation and menu of models for future work.
- 5.1. Mimesis: Cryptic deception predominates in the surveyed literature, while mimetic deception offers further research opportunities but may raise ethical concerns about trustworthiness.The paper links crypsis partly to privacy research and randomization, and mimesis partly to ethical concerns.
- 5.2. Theoretical advances: Most surveyed studies use Stackelberg or Nash games, with few cooperative or dynamic games because advanced and stochastic models are difficult to analyze.The survey identifies model sophistication and analysis difficulty as boundaries of the current literature.
- 5.3. Practical implementations: Game-theoretic concepts have successful physical-security deployments, but successful cybersecurity implementations are difficult to identify and face several deployment challenges.The paper notes that commercial implementations may exist without publication.
- 5.3. Practical implementations: Deceptive mechanisms should be combined with traditional approaches such as cryptography and access control rather than relying only on attacker ignorance.This addresses concerns about security through obscurity.
- 5.4. Interdisciplinary Security: Accurate defensive-deception applications require domain-specific modeling, behavioral analysis, psychology, and criminology, whose relevance may change as attacks become automated.The paper emphasizes that attackers may not follow theoretically optimal strategies.
- 5.5. Conclusion: The taxonomy provides a scientific foundation, common language, and menu of game-theoretic models for future cybersecurity and privacy research.It also summarizes game theory’s contributions to deception species over the preceding decade.
APPENDIX
The appendix documents how the survey’s papers were classified into cryptic and mimetic deception. It provides classification justifications for both groups.
- Cryptic deception: Table III lists the classification justifications for papers in cryptic deception.The appendix uses these justifications to document the cryptic classifications.
- Mimetic deception: Table IV lists the classification justifications for papers in mimetic deception.The appendix separately documents the mimetic classifications.