Zelin Wan

dblp:270/8309 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2024
0000-0001-5293-0363ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 4 first-author · 6 since 2021
YearPublicationVenuePosition
2024 Optimizing Effectiveness and Defense of Drone Surveillance Missions via Honey Drones
abstract
This work aims to develop a surveillance mission system using unmanned aerial vehicles (UAVs) or drones when Denial-of-Service (DoS) attacks are present to disrupt normal operations for mission systems. In particular, we introduce the concept of cyber deception using honey drones (HDs) to protect the mission system from DoS attacks. HDs exhibit fake vulnerabilities and employ stronger signal strengths to lure DoS attacks, unlike the legitimate drones called mission drones (MDs) deployed for mission execution. This research formulates an optimization problem to identify an optimal set of signal strengths of HDs and MDs to best prevent the system from DoS attacks while maximizing mission performance under the resource constraints of UAVs. To solve this optimization problem, we leverage deep reinforcement learning (DRL) to achieve these multiple objectives of the mission system concerning system security and performance. Particularly, for efficient and effective parallel processing in DRL, we utilize a DRL algorithm called the Asynchronous Advantage Actor-Critic (A3C) algorithm to model attack-defense interactions. We employ a physical engine-based simulation testbed to consider realistic scenarios and demonstrate valid findings from the realistic testbed. The extensive experiments proved that our HD-based approach could achieve up to a 32% increase in mission completion, a 20% reduction in energy consumption, and a 62% decrease in attack success rates compared to existing defense strategies.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
ACM Trans. Internet Techn.1
2023 Deception in Drone Surveillance Missions: Strategic vs. Learning Approaches
abstract
Unmanned Aerial Vehicles (UAVs) have been used for surveillance operations, search and rescue missions, and delivery services. Given their importance and versatility, they naturally become targets for cyberattacks. Denial-of-Service (DoS) attacks are commonly considered to exhaust their resources or crash UAVs (or drones). This work proposes a unique proactive defense using honey drones (HD) for UAVs during surveillance operations. These HDs use lightweight virtual machines to lure and redirect potential DoS attacks. Both the choice of target by the attacker and the HD's deceptive tactics are influenced by the strength of the radio signal. However, a critical trade-off exists in that stronger signals can deplete battery life, while weaker signals can negatively affect the connectivity of a drone fleet network. To address this, we formulate an optimization problem to select the best strategies for an attacker or defender in selecting their signal strength level. We propose a novel HD-based defense to identify the optimal setting using deep reinforcement learning (DRL) or game theory and compare their performance with that of non-HD-based methods, such as Intrusion Detection Systems and ContainerDrone. Our experiments demonstrate the unique benefits and superior efficacy of each HD-based defense across various attack scenarios.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
MobiHoc1
2023 Resisting Multiple Advanced Persistent Threats via Hypergame-Theoretic Defensive Deception
abstract
Existing defensive deception (DD) approaches apply game theory, assuming that an attacker and defender play the same, full game with all possible strategies. However, in deceptive settings, players may have different beliefs about the game itself. Such structural uncertainty is not naturally handled in traditional game theory. In this work, we formulate an attackdefense hypergame where multiple advanced persistent threat (APT) attackers and a single defender play a repeated game with different perceptions. The hypergame model systematically evaluates how various DD strategies can defend proactively against APT attacks. We present an adaptive method to select an optimal defense strategy using hypergame theory for strategic defense as well as machine learning for adaptive defense. We conducted in-depth experiments to analyze the performance of the eight schemes including ours, baselines, and existing counterparts. We found the DD strategies showed their highest advantages when the hypergame and machine learning are considered in terms of reduced false positives and negatives of the NIDS, system lifetime, and players’ perceived uncertainties and utilities. We also analyze the Hyper Nash Equilibrium of given hypergames and discuss the key findings and insights behind them.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.1
2022 Honeypot-Based Cyber Deception Against Malicious Reconnaissance via Hypergame Theory
abstract
Malicious reconnaissance is a critical step for attackers to collect sufficient network knowledge and choose valuable targets for intrusion. Defensive deception (DD) is an essential strategy against threats by misleading attackers' observations and beliefs. Honeypots are widely used for cyber deception that aims to confuse attackers and waste their resources and efforts. Defenders may use low-interaction honeypots or high-interaction honeypots. In this paper, we consider a hybrid honeypot system that balances the use of the two levels of honeypot complexity, where high-interaction honeypots are more capable of deceiving skilled attackers than low-interaction honeypots. We present a two-player hypergame model that characterizes how a defender should deploy low and high-interaction honeypots to defend the network against malicious reconnaissance activities. We model the tradeoff of each player and characterize their best strategies within a hypergame framework that considers the imperfect knowledge of each player toward their opponent. Finally, our numerical results validate the effectiveness of the proposed honeypot system.
Ahmed H. Anwar, Zelin Wan, Jin-Hee Cho, Charles A. Kamhoua, Munindar P. Singh
GLOBECOM3
2022 Foureye: Defensive Deception Against Advanced Persistent Threats via Hypergame Theory
abstract
Defensive deception techniques have emerged as a promising proactive defense mechanism to mislead an attacker and thereby achieve attack failure. However, most game-theoretic defensive deception approaches have assumed that players maintain consistent views under uncertainty. They do not consider players’ possible, subjective beliefs formed due to asymmetric information given to them. In this work, we formulate a hypergame between an attacker and a defender where they can interpret the same game differently and accordingly choose their best strategy based on their respective beliefs. This gives a chance for defensive deception strategies to manipulate an attacker’s belief, which is the key to the attacker’s decision-making. We consider advanced persistent threat (APT) attacks, which perform multiple attacks in the stages of the cyber kill chain (CKC) where both the attacker and the defender aim to select optimal strategies based on their beliefs. Through extensive simulation experiments, we demonstrated how effectively the defender can leverage defensive deception techniques while dealing with multi-staged APT attacks in a hypergame in which the imperfect information is reflected based on perceived uncertainty, cost, and expected utilities of both the attacker and defender, the system lifetime (i.e., mean time to security failure), and improved false-positive rates of intrusion detection.
Zelin Wan, Jin-Hee Cho, Ahmed H. Anwar, Charles A. Kamhoua, Munindar P. Singh
IEEE Trans. Netw. Serv. Manag.1
2022 Diversity-by-Design for Dependable and Secure Cyber-Physical Systems: A Survey
abstract
Diversity-based security approaches have been studied for several decades since the 1970s. The concept ofdiversity-by-designemerged in the 1980s. Since then, diversity-based system design research has been explored to provide more secure and dependable services in cyber-physical systems (CPSs). In this work, we are particularly interested in providing an in-depth, comprehensive survey of existing diversity-based approaches, their insights, and associated future work directions for building secure and dependable CPSs. This will allow us to provide promising ways of providing quality network and services based on key diversity-by-design principles for those who want to conduct research on developing secure and dependable CPSs using diversity as a system design feature. This survey paper mainly provides: (i) The common concept of diversity based on its multidisciplinary nature along with the historical evolution of the concept of diversity-by-design for providing secure and dependable services; (ii) the key diversity-by-design principles; (iii) the key benefits and caveats of using the diversity-by-design; (iv) the main concerns of CPS environments utilizing the diversity-by-design; (v) an extensive survey and discussions of existing diversity-based approaches based on five different classifications; (vi) the types of attacks considered by diversity-based approaches; (vii) the overall trends of evaluation methodologies used for diversity-based approaches, in terms of metrics, datasets, and testbeds; and (viii) the insights, lessons, and gaps identified from this extensive survey and future work directions.
Qisheng Zhang, Abdullah Zubair Mohammed, Zelin Wan, Jin-Hee Cho, Terrence J. Moore
IEEE Trans. Netw. Serv. Manag.3