-The strategy of data fusion has been applied in threat prediction and situation awareness and the terminology has been standardized by the Joint Directors of Laboratories (JDL) in the form of a socalled JDL Data Fusion Model, which currently called DFIG model. Higher levels of the DFIG model call for prediction of future development and awareness of the development of a situation. It is known that Bayesian Network is an insightful approach to determine optimal strategies against asymmetric adversarial opponent. However, it lacks the essential adversarial decision processes perspective.In this paper, a highly innovative data-fusion framework for asymmetricthreat detection and prediction based on advanced knowledge infrastructure and stochastic (Markov) game theory is proposed. In particular, asymmetric and adaptive threats are detected and grouped by intelligent agent and Hierarchical Entity Aggregation in Level 2 and their intents are predicted by a decentralized Markov (stochastic) game model with deception in Level 3. We have verified that our proposed algorithms are scalable, stable, and perform satisfactorily according to the situation awareness performance metric.
This paper proposes an innovative data-fusion/ data-mining game theoretic situation awareness and impact assessment approach for cyber network defense. Alerts generated by Intrusion Detection Sensors (IDSs) or Intrusion Prevention Sensors (IPSs) are fed into the data refinement (Level 0) and object assessment (L1) data fusion components. High-level situation/threat assessment (L2/L3) data fusion based on Markov game model and Hierarchical Entity Aggregation (HEA) are proposed to refine the primitive prediction generated by adaptive feature/pattern recognition and capture new unknown features. A Markov (Stochastic) game method is used to estimate the belief of each possible cyber attack pattern. Game theory captures the nature of cyber conflicts: determination of the attacking-force strategies is tightly coupled to determination of the defense-force strategies and vice versa. Also, Markov game theory deals with uncertainty and incompleteness of available information. A software tool is developed to demonstrate the performance of the high level information fusion for cyber network defense situation and a simulation example shows the enhanced understating of cyber-network defense.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.