The Evolution from Physical Protection to Cyber Defense

Authors

  • Pavan Navandar Cybersecurity SAP Security Engineer, Tata Consultancy Services, USA Author

DOI:

https://doi.org/10.15680/IJCTECE.2022.0505003

Keywords:

Cyber Defense Evolution, Physical Security, Security Games, Stackelberg Game Theory, Adversarial Modeling, Uncertainty in Cybersecurity, Resource Optimization

Abstract

No security organization, whether it guards an airport terminal or a corporate network, ever has enough resources to watch everything at once. The defining question of protection work is therefore not whether to leave gaps, but where to leave them — and how to keep an intelligent adversary from predicting where those gaps will be. Over the past two decades, this allocation question has been given rigorous mathematical footing through the framework of Stackelberg security games, in which a defender commits publicly to a randomized protection strategy and an attacker selects a best response after observing it. What began as an academic model has matured into deployed scheduling systems guarding airports, seaports, air routes, transit networks, and protected wildlife areas. This paper traces that maturation and then asks what happens when the same reasoning is carried from the physical world into the cyber domain, where the fundamental structure of the game shifts: targets multiply beyond enumeration, attacks unfold at machine speed, both players operate under deep informational uncertainty, and deception becomes a firstclass defensive instrument rather than a novelty. We review the core model, survey the algorithmic advances that made real deployments possible — in scalability, uncertainty handling, and modeling of human adversaries — and examine how each of those advances must be reinterpreted for network defense problems such as packet inspection, honeypot placement, and audit scheduling. Our central argument is that the transition from physical protection to cyber defense is not a change of application but a change of game, and that recognizing this distinction is what separates productive uses of security games in cybersecurity from naive ones.

References

1. Von Stackelberg, H. (1934). Marktform und Gleichgewicht. Vienna: Springer.

2. Kiekintveld, C., Jain, M., Tsai, J., et al. (2009). Computing optimal randomized resource allocations for massive security games. In Proceedings of the 8th International Conference on Autonomous Agents and Multiagent Systems (AAMAS), 689–696. Richland, SC: IFAAMAS.

3. Leitmann, G. (1978). On generalized Stackelberg strategies. Journal of Optimization Theory and Applications, 26, 637–643.

4. Breton, M., Alj, A., & Haurie, A. (1988). Sequential Stackelberg equilibria in two person games. Journal of Optimization Theory and Applications, 59, 71–97.

5. Conitzer, V., & Sandholm, T. (2006). Computing the optimal strategy to commit to. In Proceedings of the ACM Conference on Electronic Commerce (ACMEC), 82–90.

6. Paruchuri, P., Pearce, J. P., Marecki, J., et al. (2008). Playing games with security: An efficient exact algorithm for Bayesian Stackelberg games. In Proceedings of the 7th International Conference on Autonomous Agents and Multiagent Systems (AAMAS), 895–902. Richland, SC: IFAAMAS.

7. Korzhyk, D., Conitzer, V., & Parr, R. (2010). Complexity of computing optimal Stackelberg strategies in security resource allocation games. In Proceedings of the 24th AAAI Conference on Artificial Intelligence, 805–810.

8. Jain, M., Kardes, E., Kiekintveld, C., et al. (2010). Security games with arbitrary schedules: A branchandprice approach. In Proceedings of the 24th AAAI Conference on Artificial Intelligence, 792–797.

9. Yin, Z., Jain, M., Tambe, M., et al. (2011). Riskaverse strategies for security games with execution and observational uncertainty. In Proceedings of the 25th AAAI Conference on Artificial Intelligence, 758–763.

10. An, B., Tambe, M., Ordonez, F., et al. (2011). Refinement of strong Stackelberg equilibria in security games. In Proceedings of the 25th Conference on Artificial Intelligence, 587–593.

11. Pita, J., John, R., Maheswaran, R., et al. (2012). A robust approach to addressing human adversaries in security games. In European Conference on Artificial Intelligence (ECAI). Amsterdam: IOS Press.

12. Yin, Z., Jain, M., et al. (2012). Game theoretic resource allocation for malicious packet detection in computer networks. In Proceedings of the 11th International Conference on Autonomous Agents and Multiagent Systems (AAMAS). Richland, SC: IFAAMAS.

13. Blocki, J., Christin, N., Datta, A., et al. (2013). Audit games. In Proceedings of the 23rd International Joint Conference on Artificial Intelligence (IJCAI).

14. Blocki, J., Christin, N., Datta, A., et al. (2015). Audit games with multiple defender resources. In AAAI Conference on Artificial Intelligence (AAAI). Palo Alto, CA: AAAI Press.

15. Navandar, P. (2018). Enhancing Cybersecurity in Airline Operations through ERP Integration: A Comprehensive Approach. Journal of Scientific and Engineering Research, 5(4), 457–462.

16. Navandar, P. (2019). Segregation of Duties (SoD) Risks in SAP Security: Mitigation Strategies and Best Practices. Journal of Scientific and Engineering Research, 6(9), 206–208.

17. Durkota, K., Lisy, V., Kiekintveld, C., et al. (2015). Game theoretic algorithms for optimal network security hardening using attack graphs. In Proceedings of the International Conference on Autonomous Agents and Multiagent Systems (AAMAS '15). Richland, SC: IFAAMAS.

18. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture. NIST Special Publication 800207. Gaithersburg, MD: National Institute of Standards and Technology.

Downloads

Published

2022-09-03

How to Cite

The Evolution from Physical Protection to Cyber Defense. (2022). International Journal of Computer Technology and Electronics Communication, 5(5), 5730-5752. https://doi.org/10.15680/IJCTECE.2022.0505003