A Cloudified Dynamic Defense Framework for Cyber Deception as a Service
Yan Liu, Sujie Shao, Chao Yang, Shao-Yong Guo, Zhibin Zang, Yu Song
Abstract
Current Cyber Deception as a Service (CDaaS) offerings force a trade-off between low-cost, low-fidelity services and expensive, high-fidelity on-premise deployments. To break this impasse, this study proposes DDCA (Dynamic Deception Cloudification Architecture), a novel cloudified defense framework. DDCA leverages a programmable data plane to construct a high-fidelity cloud deception environment with dynamic topology and controllable characteristics, enabling physically static deception resources to exhibit dynamic behaviors, thus confounding protected services and decoys at the network layer. We first built the DDCA attack-defense theoretical model capable of quantifying attacker's cognitive uncertainty relying on partially observable data. Furthermore, we designed a deception orchestration engine based on Deep Reinforcement Learning (DRL) that transforms defensive constraints into executable strategies of DDCA, jointly optimizing the attack surface hopping, topology reconfiguration, and obfuscated characteristic injection. Experiments conducted on a prototype platform demonstrated that the DDCA can significantly increase expected attack costs at an acceptable expense while effectively countering advanced reconnaissance, providing a more economical systematic solution for CDaaS.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9d117b8e-a25e-4dda-8f25-0e0ec1e2ed73Related papers
- Automating Cloud Deployment for Deep Learning Inference of Real-time Online ServicesYang Li, Zhenhua Han, Quanlu Zhang, Zhenhua Li et al.INFOCOM 2020 · 48 citations
- SoK: The Pitfalls of Deep Reinforcement Learning for CybersecurityShae McFadden, Myles Foley, Elizabeth Bates, Ilias Tsingenopoulos et al.USENIX Security 2026 · 7 citations
- Storage Efficient and Dynamic Flexible Runtime Channel Pruning via Deep Reinforcement LearningJianda Chen, Shangyu Chen, Sinno Jialin PanNeurIPS 2020 · 31 citations
- Demeter: Fine-grained Function Orchestration for Geo-distributed Serverless AnalyticsXiaofei Yue, Song Yang, Liehuang Zhu, Stojan Trajanovski et al.INFOCOM 2024 · 13 citations
- Finding Needles in a Moving Haystack: Prioritizing Alerts with Adversarial Reinforcement LearningLiang Tong, Aron Laszka, Chao Yan, Ning Zhang et al.AAAI 2020 · 27 citations
