<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Design of security protection and management systems based on game theory ⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Serhii Toliupa</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhii Buchyk</string-name>
          <email>buchyk@knu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Volodymyr Nakonechnyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mykola Brailovskyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhii Shtanenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CPITS-II 2024: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Military Institute of Telecommunication and Information Technologies named after the Heroes of Kruty</institution>
          ,
          <addr-line>45/1 Knyaziv Ostrozkyh str., 01011 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>60 Volodymyrska str., 01601 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>334</fpage>
      <lpage>341</lpage>
      <abstract>
        <p>Currently, much attention is paid to the issues of information security. Telecommunication systems, which have been actively developing recently, are the arteries of modern global information systems. The information circulating in such systems is of significant value and is therefore vulnerable to various violations and abuses. The development of network technologies is accompanied by increased requirements for information security and the choice of the optimal level of protection systems. Many researchers propose to use the game theory framework as a mathematical basis for designing, building, and analyzing information security systems. Game theory is a formal approach designed to analyze the interaction between several participants in a process that have different interests and make decisions. The use of game theory in modeling decision-making processes has various approaches that are currently not systematic and sometimes contradict each other. Therefore, there is a need to develop methods of rapid (adaptive) information security management, depending on the availability of a priori information about the possibility of attacks by an attacker and the strategy implemented by him to create unauthorized access to an information resource. Game theory allows us to offer recommendations for creating a strategy for managing the operation of security and intrusion prevention systems.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;information security</kwd>
        <kwd>game theory</kwd>
        <kwd>optimal strategy</kwd>
        <kwd>system security</kwd>
        <kwd>offender system</kwd>
        <kwd>decision-making</kwd>
        <kwd>intrusion detection system</kwd>
        <kwd>attack 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>In this paper, we will consider two approaches to the
application of game theory: the use of game theory methods
to optimize the choice of information security and security
management. In many situations, while doing the design of
information security systems there can be a need for the
development and implementation of decisions in conditions
of uncertainty. Uncertainty may have a different nature. So,
uncertain is the planned actions of the hackers which aim
to decrease the efficiency of protection systems; uncertainty
can refer to situations of risk in which the information
network management system, which makes decisions on
the implementation of the protection system, can establish
not only all possible outcomes of decisions but the
probability of possible conditions of their appearance.
Design conditions affect the decision-making
subconsciously, regardless of the actions of the subject that
makes a decision. When aware of all the consequences of
possible solutions, but without knowing their accuracy, it is
clear that decisions are made in conditions of uncertainty.
The basic perspective of the analysis theory of the
decisionmaking processes at the design stage of information
protection systems is game theory. The application of game
theory in modeling the decision-making processes has
different approaches, which currently are not systematic
and sometimes collide between themselves. Therefore, the
study of this subject is an actual scientific issue.</p>
    </sec>
    <sec id="sec-2">
      <title>2. The main part</title>
      <p>
        Despite significant advances in information security, there
are still difficulties in preventing intrusions into the
information system. An analysis of network attacks shows
that protection actions are most often taken after the service
performance has already been affected. This is due to the
difficulty of assessing the future scale of the attack and
applying the appropriate defense measure [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ].
      </p>
      <p>
        To increase the accuracy of attack prediction and
detection, an intrusion detection system must collect
heterogeneous information about the protected system, as
well as store and process a large amount of data. Using a
filtering system in the absence of an attack results in a
decrease in server performance and possible false filter
triggering. Quite often, the creation of an effective
protection system is faced with insufficient computing
power. Thus, the task of optimizing the resources spent on
maintaining the performance of the system of protection
against network attacks at a high level arises [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ].
      </p>
      <p>One of the solutions to this problem is to minimize the
resources spent on maintaining information security at
times when the activity of the attacker is insignificant. To
this end, an intrusion detection system should use dynamic
methods that allow for prompt detection and prevention of
security breaches, i.e., the information security system
should use a mathematical model that allows for the
selection of the necessary set of security tools at any given
time, providing reliable protection and at the same time
requiring a minimum amount of resources.</p>
      <p>
        In recent years, domestic and foreign works have shown
a tendency to expand the existing mathematical approaches
to the selection of information security system parameters.
For example, various authors propose the following
mathematical methods for analyzing and optimizing an
information security system [
        <xref ref-type="bibr" rid="ref5 ref6">5, 6</xref>
        ]: methods of mathematical
statistics; methods based on the use of Petri nets;
mathematical apparatus of the theory of random processes;
methods based on the theory of automata; methods based
on the theory of fuzzy sets; methods based on the use of
neural networks; methods of expert systems; mathematical
apparatus of game theory [
        <xref ref-type="bibr" rid="ref7 ref8">7, 8</xref>
        ].
      </p>
      <p>
        Statistical intrusion detection methods apply a
wellproven mathematical statistics apparatus to the behavior of
the subjects of the analyzed system. First, statistical profiles
are formed for all subjects. The components of such a profile
may include various parameters, such as total traffic per
unit of time, the number of denials of service, the ratio of
incoming traffic to outgoing traffic, the number of unique
requests to the system, etc. Any deviation from the
reference profile is considered a security breach. The main
disadvantages of this approach are the following. First,
intrusion detection systems based on statistical methods are
not sensitive to the order of events in the protected system:
in some situations, the same events, depending on the order
of their occurrence, may be characteristic of abnormal or
normal activity. Secondly, in some cases, it can be difficult
to set thresholds for the monitored characteristics to
identify anomalous activity. Underestimating the threshold
leads to false positives, and overestimating it leads to missed
intrusions. In addition, the attacker often uses individual
approaches for each defense system, which makes the use
of statistical methods less effective [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
2.1. Design of security protection
Any information processing system consisting of various
hardware and software tools can be viewed as a unique
complex with its characteristics. The complexity of the
effective dynamic formation of observation parameters lies
in the fact that the size of the search area exponentially
depends on the power of the initial set of observed
parameters.
      </p>
      <p>Various intelligent methods can be used in intrusion
detection systems to generate a set of observed parameters.</p>
      <p>Many researchers propose to use the game theory
framework as a mathematical basis for designing, building,
and analyzing information security systems. Game theory is
a formal approach designed to analyze the interaction
between several participants in a process that have different
interests and make decisions.</p>
      <p>
        Any information security system involves two parties:
the attacking party and the defending party (information
security system), which have opposing interests. In [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], it is
proposed to use the mathematical apparatus of game theory
to solve the problem of choosing means of protection
against unauthorized access to information in an automated
system. The mathematical formulation of the problem in the
form of a linear programming problem with Boolean
variables is also performed there. In the mathematical
formulation, the cost of protection means is introduced. The
constraints of the task take into account the requirements
of the classes of protection against unauthorized access in
automated systems.
      </p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], an overview of theoretical game methods used in
solving information security problems is given. The paper
considers an approach to designing intrusion detection
systems using the mathematical apparatus of matrix games
for two players. The proposed model takes into account the
cost of system resources for organizing protection.
      </p>
      <p>
        Paper [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ] considers the possibilities of using multi-step
games with incomplete information in building systems of
protection against DoS attacks. It is proposed to present the
problem in the form of a game of two parties: the defending
party (A) and the attacking party (B). The task of the
defending party is to minimize its losses due to the actions
of the attacking party. The task of party B is to maximize
profit. The paper points out that the main feature of such a
game is that functions describing the behavior of the parties
in the short term are used as strategies. It is proposed to
select a variety of functions for each task individually, based
on statistical data, external constraints, and common sense.
      </p>
      <p>
        When analyzing the issues of protection against various
security threats, it is advisable to consider the actions of two
parties: the defense (information system) and the offender.
The entirety of security threats can be considered as an
intruder: the actions of individuals with different goals,
large-scale planned attacks, and accidental impacts on the
system. Such models, where there are two or more opposing
parties, are typical of game theory [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. If the options of
actions (strategies) of each party are known, as well as the
gain (or loss) from each of the options, it is possible to
formulate a mathematical model of the situation in the form
of a model of a non-coalition antagonistic game (for
example, a matrix game). Based on the formulated task, it is
possible to obtain optimal strategies for the attacking and
defending parties that require a minimum of resources [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>Consider the interaction between an intrusion detection
system and an attacker as a non-coalition endgame. Suppose
that the defense party A and the attacker B have a finite
number of strategies  and  , which corresponds to
reality, since the defense party always has a limitation on
the number of possible response options, and the attacker
has a limitation on the number of options for organizing an
attack.

player winnings are defined on a variety of
security system does not incur the cost of additional
,
system.
where 
and</p>
      <p>
        are many possible situations of players A
and B, respectively, 
is the function of the information
methods described in [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>
        For example, in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], it is proposed to use strategies for
defense
(“ignore
suspicious
activity”,
“increase
monitoring”); and for the attacker, many strategies can be
considered (“complete the attack”, “continue
without
pause”, “pause the attack”). A set of player strategies  =
( ,  ), where 
∈  , 
∈ 
set of situations. Functions
situations  =
      </p>
      <p>×  .</p>
      <p>
        The solution to a non-coalition game is an equilibrium
situation, but not necessarily in pure strategies. It is known
that every finite antagonistic game has at least one
equilibrium situation in mixed strategies. When analyzing
information security systems, it makes sense to consider
mixed strategies under the assumption that the system’s
operation lasts for a considerable time, i.e., attack and
defense iterations are repeated many times [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. In this case,
the strategies are used by the parties with some
nondeterministic regularity and the costs/income accumulate
over time. The mixed strategy of players A and B is the full
set of probabilities of using their pure strategies:


= 
= 
, 
, 
, … , 
, … , 
,
.
      </p>
      <p>In a non-coalition game, each player uses his or her pure
strategies independently of the other, so in a mixed situation
 = ( ,  } probability  ( ) of the emergence of a
situation  = ( ,  ) is equal to the product of the
probabilities of both players using their pure strategies, i.e.
 ( ) =  ( ,  ).</p>
      <p>Let’s find the average win (loss) of players. In the case
of the mathematical expectation of player A win in a mixed
situation  = ( ,  } is defined as follows:</p>
      <p>WA ( p)  wA (PA , PB )   wA (s) p(s) </p>
      <p>sS
wA (s1, s2 ) pA (sA )( pB (sB ))

</p>
      <p>
s1SA s2SB
security system’s gain (or, in fact, loss or cost) if the
information security system has chosen a strategy s1, and the
offender—the strategy  .</p>
      <p>The player’s (information security system violator’s)
winnings are generally determined in the same way.</p>
      <p>
        How can you determine the winnings of players in this
case? The intrusion detection system provides a lot of
parameters at any given time using sensors [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Each attack
can be represented as a sequence of iterations. After each
step, the intrusion detection system tries to “predict” the
next steps of the intruder. Each step of the intruder
generates a certain type of activity that can be detected by
the system’s sensors. If the analysis unit recognizes the
activity as suspicious, the set of basic observed parameters
must be expanded. Let the set of additional monitoring
parameters be
      </p>
      <p>= { ,  , … ,  }, and the cost of
additional resources spent on monitoring them over time
 −  ( ). Let’s assume that the cost of observation is
directly proportional to the time of observation. If the
monitoring of an extended set of parameters is carried out
during the time  , then the cost of additional observation
costs will be
where n is the number of additional monitoring parameters,
ci is the cost of monitoring the ith parameter. When making
a decision to ignore a possible attack, the information
monitoring.</p>
      <p>Let’s estimate the costs of the information security
system violator. If the decision is made to terminate the
attack, the attacker does not incur additional costs, and if
the decision is made to continue the attack, the attacker’s
costs depend on the number  of generated requests to the
protected system 
one request.</p>
      <p>=  , where  is the cost of generating</p>
      <p>In case of a successful attack, the information security
system suffers losses  ∗, and the offender wins  ∗ . The costs
of the protection system when implementing each of the
possible strategies consist of the costs of organizing
protection</p>
      <p>CA (t)   c t</p>
      <p>i m
n
i1
and losses from possible
security breaches  ∗. Similarly, the gain of the infringer
consists of the gain from the breach of the information
security system  ∗ and because of the cost of conducting
attacks  .</p>
      <p>For the analyzed intrusion detection system, it is
assumed that with the increase of additional monitoring
parameters, the probability of detecting an attack increases.
However, determining the exact dependence of successful
attack detection on the number and set of monitoring
parameters, as well as on the monitoring time, requires an
experimental study for each type of information security</p>
      <p>As noted, every finite non-coalition game has at least
one equilibrium
situation in
mixed
strategies.</p>
      <p>The
equilibrium situation can be found by standard game theory</p>
      <p>
        It should also be borne in mind that. The peculiarity of
the information conflict of the information security
operational management system and the peculiarity of the
offender trying to carry out unauthorized access (UA) is that
the opposing parties, who have several ways of acting, can
apply them repeatedly, choosing the best way [
        <xref ref-type="bibr" rid="ref14 ref15">14, 15</xref>
        ].
Based on information about the actions of the opposing
party.
      </p>
      <p>
        At each step of conflict resolution is not a final state but
some payment function. Traditional game approach to the
analysis of the violator’s actions fails to take into account
multiple steps of conflict and does not reflect the
dependence of the modes of action of the parties from the
opposite direction, and the known conflict approach based
on the calculation of the final probability of system stay in
a state of winning to a given point in time does not reflect
the multiplicity of actions of the parties and unqualified
finality of the conflict at each step [
        <xref ref-type="bibr" rid="ref16 ref17">16, 17</xref>
        ].
2.2. Information security management
      </p>
      <sec id="sec-2-1">
        <title>Therefore, there is a need to develop methods for rapid</title>
        <p>(adaptive) management of information security depending
on the availability of a priori information about the
possibility of attacks from the intruder and the strategy of
creating the UA implemented by him.</p>
        <p>To describe the current status of the conflict let’s use the
indicator of the security of the system аij = Рsec while
implementing in it the ith, iІ={1,2,...,n}, strategy (way) of
protection and the application of the jth, jJ={1,2,..., m}
strategy (way) of creating a safety contour, m and n are
the number of security strategies and creation of security
measure implemented in the SS (security system) and the
system of the intruder (SoI) accordingly.</p>
        <p>
          Let’s name the subsystem of operational management of
the information protection as Party A and the system to
counteract this protection as Party B, and the aij—the win of
Party A (the loss of Party B) in a situation (i, j). The
traditional gaming approach to the analysis of security
systems assumes that the parties are aware of the matrix of
the game and the finite set of strategies of the violator, but
it is unknown which strategy is implemented in a particular
situation. In this case, a matrix game can be formalized in
the situation of a choice of protection strategies under
conditions of uncertainty. However, this approach does not
reflect the dynamics of conflict and the possibility of a
purposeful selection of protection strategies at each step
depending on information about the system action of the
offender [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. Therefore, it is proposed to describe the
conflict using the model of a stepper matrix game with lag
and errors in the awareness of the parties about the actions
of the offender (matrix-game process). Let us note: ТPS (ТSoI)
time of a single implementation of its pure strategy by the
party A(B); tPS (tSoI) is reaction time of the party A(B), which
is equal to the time interval from the start of implementation
of the strategy by the party B(A) to the moment of
implementation of appropriate strategy by the party A(B).
        </p>
        <p>We assume that parties are aware of: the matrix game
А  (аij ) nm , the set of active strategies І, J, and the
assessment of the values of ТPS (ТSoI) and tPS (tSoI); the matrix
of game A is average new and has the solution value of the
game v and the optimal vectors of mixed strategies of the
parties</p>
        <p>A - P*  (P1*, P2*, ..., P³*, ..., Pn*)</p>
        <p>and</p>
        <p>B - Q*  (Q1*, Q2*, ...,Q*j , ...,Qm*)
during the time of the game T there is no aftereffect, and the
sets І, J are unchanged.</p>
        <p>
          The method was designed for adaptive changes of
parameters and operating modes of the SS according to the
game algorithm, depending on the availability of a priori
information about the system settings of the offender and
strategies for the creation of its attacks on information
system (IS) [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ].
        </p>
        <p>The essence of the game control algorithm is to compare
a large number of possible in these conditions qualitatively
different solutions, determining the optimal or best with all
the limitations solution and the formation of the
corresponding team.</p>
        <p>To improve the efficiency in solving the dynamic games
the forecasting method is used.</p>
        <p>One of the possible solutions for games in mixed
strategies is, as noted above, the increase in the reaction rate
(rate of adaptation) of one of the parties, which improves
the efficiency of the strategies.</p>
        <p>
          A common method of solving a matrix game in mixed
strategies, i.e., methods of linear programming becomes
much more complicated for matrixes of large dimension.
The usage of decomposition methods is not always possible,
and iterative solution methods, such as the method of
Brown-Robinson, often have a high enough rate of
convergence. As an alternative, one can use the method of
dynamic programming using the results of short-term and
long-term forecasting [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
        </p>
        <p>Let’s take a look at the algorithm for solving matrix
games using dynamic programming. In respect of cases
examined long-term forecasting allows with a fairly high
degree of reliability to limit the number of possible
strategies for the system of the offender and reduce the
game matrix. The solution of matrix games in keeping with
the principle of forecasting based on the Markov approach
is to optimize the conditional strategy of SS for N cycles
forward through the predictable strategy of the intruder’s
system. It is obvious that with increasing N, the accuracy of
the prediction decreases. In this regard, consider the case
when N = 1. It is possible to allocate three stages of the
algorithm for forming the optimal strategy of the SS.</p>
        <p>The system diagram of the game management of the
security system is shown in Fig. 1.
The method of security system management based on the
methods of game theory, a block diagram of the algorithm
implementation consist of the following stages (Fig. 2).</p>
        <p>The initial data input. You enter the parameters of
security measures and channel decision-making  = {i},
and the value of the permissible probability of incorrect
decision Per per.</p>
        <p>Obtaining information about the actions of the offender’s
system. Using one of the methods of monitoring the status
of the security system we can determine the strategy or
recognize the fact of the system exposure by the intruder.</p>
        <p>Determining the version number of the current strategy of
the SS. Based on the parameters obtained in the design phase
of SS, the initial strategy of the SS according to the
characteristics of the remedies is determined.</p>
        <p>Determination of the optimal strategy of SS. The problem
of optimization of functioning algorithms of the SS is to
determine an optimal strategy à* À*, which provides
the maximum efficiency of functioning of SS within the
required time functioning. To improve the efficiency in
solving dynamic games the forecasting method is used.
One of the possible solutions for games in mixed strategies
is, as noted above, the increase in the reaction rate (rate of
adaptation) of one of the parties, which improves the
efficiency of the strategies.</p>
        <p>The adoption rate of the SS depends on the ratio
TSS / TSoI and the value TSS , TSoI —from the durations of
time regulation and change operating modes of protection,
which depend on their position at the previous cycle. The
duration of the transition of SS from the state of Нn to the
state of Нm on regulation stages (Нn and Нm are the vectors
of state remedies) is known in advance by a square transit
time matrix of any possible (taken from the definition field)
state toanother possible one:</p>
        <p>R(reg)nm N  M , n  1, N , m  1, M .</p>
        <p>The elements of a matrix will be TSrSegnm included in the
TSНS at the stage of regulation parameters, changing modes
of operation of the system. Then the process of transition
from Нn to Нm, taking into account possible intermediate
states can be described by a unit of homogeneous Markov
chains with discrete states in discrete time. The transition
from Нn(t) to Н m ( t + 1 ) is an appropriate strategy
ai  SSS. The same offender’s system status in the
transition is defined as НPSn (t) and Н PSm (t  1) .</p>
        <p>Therefore, the task of conditional optimization of time
of adaptation on the phase of adjustment consists of
choosing such a strategy a* at cycle (t+1), in which:
TSS ((t 1), а*)  minTSS (Нn (t),
 аiSSS
Нm (t 1), аi );

TSS ((t  2), а*)  maxTSS (НSSn (t 1),
 аiSSS
НSSm (t  2), аi )
considering that TSS  TPS this happens in the process of
the game solving through the introduction of ka in the
calculation of the matrix elements.</p>
        <p>The numerical accuracy of the intended value of a win
function is set to some ratio of the prediction error
kpr (t 1t) 
Фˆ(t 1)
ФRL (t 1)
,
where Ф RL (t  1) is calculated when reaching (t+1) as a
result of monitoring. So, in the case of an unchanged SoI
strategy with Ф(t) for several cycles, the correction is Ф(t+1)
due to k pr (t  1 t ) that is a part of the coefficient βm(t+1).
This eliminates a systematic error in the calculation of the
values of Ф(t) and somehow influences the choice of a*(t+1)
while solving matrix games.</p>
        <p>Since the coefficient prediction error is inverse to the
factor of awareness k iаnf , the function is
f (kiаnf )  kpr(t 1t) 1 . In this case, we have the following
problem of conditional optimization: kiànf  max, where
à S
max kinf  kinf with the limitation:
k pr (t  1 t )  1   er ,
8</p>
        <p>N = N + 1
3
4
5
6
9</p>
      </sec>
      <sec id="sec-2-2">
        <title>1 Input of initial</title>
        <p>data
( = {i})
2
Testing of the security
system
Assessment of
protective
equipment</p>
        <p>Determining the
number of the initial
strategy а(t)
Changing
the strategy
of SS?</p>
        <p>No
Correction
kпр(t 1t)</p>
        <sec id="sec-2-2-1">
          <title>F7ormation of optimal</title>
          <p>conditional strategy
a*(t + N/t)
Prediction
b*(t + N/t)</p>
        </sec>
        <sec id="sec-2-2-2">
          <title>F1o0rmation of optimal</title>
          <p>strategy a*(t + N)
12
Рer  Рer per</p>
          <p>Yes
13
Management decision
making
END</p>
          <p>Yes
where  er is some centered random variable with zero
mathematical expectation and variance δ2, which defines
some limit value of the error.</p>
          <p>Consider the algorithm for solving matrix games using
dynamic programming. In respect of cases examined
longterm forecasting allows with a fairly high degree of
reliability to limit the number of possible strategies for the
system of the offender in the next management cycles up to
2...4 and to reduce the game matrix. The solution of the
matrix game in keeping with the principle of forecasting
based on the Markov approach is to optimize the conditional
strategy of the SS for N cycles forward through the
predictable strategy of the system of the intruder. It is
obvious that with increasing N, the accuracy of the
prediction decreases. In this regard, consider the case when
N = 1. It is possible to allocate three stages of the algorithm
for forming the SS optimal strategy. In the first phase based
on information about the current state of protection, the
assumed value of the transition probabilities of SS, which
applies to the management cycle t of the strategy system of
the intruder b(t), and taking into account previous SS
policies an optimal conditional strategy à * (t  1 )t is
provided:
а * (t  1 )t  arg  аSSS </p>
          <p>max P (а (t ), b(t ), Н (t )) .</p>
          <p>The second stage solves the problem of prediction
strategy that is used at the management cycle t+1 of the SoI
and which will ensure the minimization of the functional
b * (t  1)t  arg min P(а * (t  1), b(t  1)).</p>
          <p>bSREP </p>
          <p>In the third stage, the optimal strategy of SS
management taking into account the projected system
strategy of the offender and the current status of protection
measures:
max P (а (t  1), 
 аSSS 
b * (t  1 t ), 
 
а * (t  1 t )  arg  Н (t  1), .</p>
          <p> m (t  1), 
k а ( Н (t  1) Н (t ))) 
</p>
          <p>To improve the reliability of the result the algorithm
may be repeated a limited number of times if there is a
certain dispersion of the probability distribution of the use
of strategies and their
à1* ( t  1 t ) ... à n* ( t  1 t )
subsequent evaluation based on the criteria of the benefits
that are introduced. In case of impossibility of definition of
such a strategy а * (t  1) , in which the losses do not
exceed the allowable values, the problem of expanding the
set of the admissible SS strategies is solved, then again,
а*(t+1) is defined. Similarly, the SS strategy through
conditional optimization of the management strategy of the
SS for N steps predicted strategy of SoI is formed. The third
stage of the algorithm in this case will look like this:</p>
          <p>Simultaneously, the prediction algorithm is
implemented. Table 1 shows a simplified example of the
predicted transition of the system from the state at cycle t
to the state (t+1) based on inhomogeneous Markov chains.
According to the principle of optimality, when finding the
optimal solution in a multistage problem optimizing the
choice of management strategy a(t) at each step regardless
of the initial state should be aimed at optimizing not only
this but also all subsequent steps. Considering the
prediction for (t+N) steps forward (in this case, no more than
three steps) the mechanism of choosing the optimal strategy
a*(t) at cycle t will also be defined by calculating the inverse
function of Bellman of the last predicted Nt+1 management
cycles. So, for t = N:</p>
          <p>BN (Н(N 1))  а(N)mIN(aНx(N1)) PN (Н(N 1),а(N)),
where Н(N1) is SS condition at (N1)-th management
cycle; a(N) is management strategy at a cycle of N;
 N ( Í ( N  1)) is a finite set of admissible strategies at
cycle (N  1).</p>
          <p>The method of Bellman is used to improve forecast
accuracy, the validity of the choice of current strategies, and
decision-making support by the management device of the
security system.</p>
          <p>The process of prediction
min (1  P3 j (t  1))
bj
3-rd stage
Probability of transition
Pi 4  k N  i 4
max Pi2 (t  1)
a1
b1
b2
b3
b4
…
аj</p>
          <p>P14
P24
P34
P44
…
Pi4
а1
а2
а3
а4
…
аi4</p>
          <p>t+1
а12</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Conclusions</title>
      <p>Thus, it is worth noting some peculiarities of using this
methodology, which is based on game theory about
information security systems.</p>
      <p>First of all, the winnings of the players in the mixed
situation were determined to be equal to the mathematical
expectation of their winnings. This assumes that the players
are risk-neutral when the game situation is repeated many
times. However, this is not entirely justified when
considering defense systems. If an attacker can be
considered a risk-neutral player, then the side of the defense
is likely irrelevant. Even a one-time breach of the security
of a protected system can be critical for it, putting it out of
commission for a long time.</p>
      <p>Second, the model can use certain data as input
parameters. In this case, the possibilities of obtaining
different data may be tasks of varying degrees of
complexity. For example, if the model uses characteristics of
threats, defenses, vulnerabilities, barriers, etc. as input
parameters, it is quite difficult to evaluate all these
characteristics and determine the relationships between
them, which will complicate the practical application of the
model in an intrusion detection system.</p>
      <p>Furthermore, it is known that a large number of
evaluation parameters play a very important role in
detecting network intrusions. Therefore, in anomaly
detection, one of the main tasks is to select the optimal set
of evaluation parameters, which cannot be done using game
theory methods. Therefore, it is advisable to use various
mathematical methods when building security systems, in
particular, intrusion detection systems.</p>
      <p>In general, the mathematical apparatus of game theory
allows for the analysis of tasks with an antagonistic,
repetitive nature, which is typical for information security
tasks. The proposed methods make it possible to choose at
the initial stage the strategy of actions in the process of
operation of the intrusion detection system and reduce the
computational costs of data processing in the information
security system.</p>
      <p>Thus, in the process of constrained optimization with
the current game matrix, the conventionally optimal
strategy will be formed, defining the phase trajectory of the
SS, starting from the final cycle of forecasting t = N to the
current value of t.</p>
      <p>The main problems with the use of game theory arise in
the definition of the function of gain for a particular
situation. For tasks that are solved by the security system,
the feature of win, first and foremost, needs to reflect the
change in the security system.</p>
      <p>If this situation is not satisfied with the SS, we should
implement measures to increase winnings with certain
combinations of modes.</p>
      <p>If the attacker deviates from its optimal strategy, the SS
has the opportunity to increase its winnings by deviating
from the optimal strategy as well.</p>
      <p>The results of simulation modeling of the SS functioning
process on the proposed game algorithm showed that the
additional use of forecasting strategies at N cycles ahead
allows to improve the efficiency by 5–8%.</p>
      <p>Thus, the theory of games allows us to offer
recommendations for creating the management strategy for
the operation of the protection systems. And, at least for
certain types of conflicts and matrixes of winnings, these
recommendations allow SS to win and improve their
technical characteristics.</p>
      <p>Analysis of winning, which gets SS in different
situations showed that game theory not only allows us to
generate an optimal strategy that can guarantee a certain
win but also allows you to issue recommendations for its
switching to increase the winnings if the system of the
violator deviates from his optimal strategy. When the
system of the offender follows his optimal strategy, game
theory allows to evaluation of the situation. If evaluation
results are not satisfied, it is necessary to implement
measures to change the situation.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Protecting Objects of Critical Information Infrastructure from Wartime Cyber Attacks by Decentralizing the Telecommunications Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems</source>
          , vol.
          <volume>3050</volume>
          (
          <year>2023</year>
          )
          <fpage>240</fpage>
          -
          <lpage>245</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>V.</given-names>
            <surname>Zhebka</surname>
          </string-name>
          , et al.,
          <article-title>Optimization of Machine Learning Method to Improve the Management Efficiency of Heterogeneous Telecommunication Network</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3288</volume>
          (
          <year>2022</year>
          )
          <fpage>149</fpage>
          -
          <lpage>155</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          , et al.,
          <article-title>An Approach to Restore the Proper Functioning of Embedded Systems Due to Cyber Threats, in: Information Technology and Implementation (IT&amp;I-</article-title>
          <year>2023</year>
          ), vol.
          <volume>3624</volume>
          (
          <year>2023</year>
          )
          <fpage>301</fpage>
          -
          <lpage>316</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kazimko</surname>
          </string-name>
          ,
          <article-title>Application of Game Theory for Modeling Information Security Problems</article-title>
          , Telecommun. Inf. Technol.
          <volume>1</volume>
          (
          <issue>74</issue>
          ) (
          <year>2022</year>
          )
          <fpage>123</fpage>
          -
          <lpage>134</lpage>
          . doi:
          <volume>10</volume>
          .31673/
          <fpage>2412</fpage>
          -
          <lpage>4338</lpage>
          .
          <year>2022</year>
          .
          <volume>011524</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>C. T.</given-names>
            <surname>Do</surname>
          </string-name>
          , er al.,
          <source>Game Theory for Cyber Security and Privacy, ACM Computing Surveys (CSUR)</source>
          ,
          <volume>50</volume>
          (
          <issue>2</issue>
          ) (
          <year>2017</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>R.</given-names>
            <surname>Hryshchuk</surname>
          </string-name>
          ,
          <article-title>Theoretical Foundations of Modeling of Information Attack Processes using the Methods of Theories of Differential Games and Differential Transformations: Monograph (</article-title>
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>D.</given-names>
            <surname>Bauso</surname>
          </string-name>
          .
          <source>Game Theory: Models, Numerical Methods and Applications, Foundations and Trends in Systems and Control</source>
          ,
          <volume>1</volume>
          (
          <issue>4</issue>
          ) (
          <year>2014</year>
          )
          <fpage>379</fpage>
          -
          <lpage>522</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>T.</given-names>
            <surname>Nguyen</surname>
          </string-name>
          , et al.
          <article-title>Multistage Attack Graph Security Games: Heuristic Strategies, with Empirical GameTheoretic Analysis</article-title>
          .
          <source>Security and Communication Networks</source>
          (
          <year>2018</year>
          ). doi:
          <volume>10</volume>
          .1155/
          <year>2018</year>
          /2864873.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>S.</given-names>
            <surname>Roy</surname>
          </string-name>
          , et al.,
          <article-title>A Survey of Game Theory as Applied to Network Security</article-title>
          ,
          <source>in: 43rd Hawaii International Conference on System Sciences</source>
          (
          <year>2010</year>
          )
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>R.</given-names>
            <surname>Sankardas</surname>
          </string-name>
          , et al.,
          <article-title>A Survey of Game Theory as Applied to Network Security</article-title>
          ,
          <source>Hawaii International Conference on System Sciences</source>
          (
          <year>2010</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kazimko</surname>
          </string-name>
          ,
          <article-title>Application of Game Theory for Modeling Information Security Problems</article-title>
          , Telecommun. Inf. Technol.
          <volume>1</volume>
          (
          <issue>74</issue>
          ) (
          <year>2022</year>
          ). doi:
          <volume>10</volume>
          .31673/
          <fpage>2412</fpage>
          -
          <lpage>4338</lpage>
          .
          <year>2022</year>
          .
          <volume>011524</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>D.</given-names>
            <surname>Akinwumi</surname>
          </string-name>
          , et al.,
          <article-title>A Review of Game Theory Approach to Cyber Security Risk Management</article-title>
          ,
          <string-name>
            <given-names>Nigerian J.</given-names>
            <surname>Technol</surname>
          </string-name>
          .
          <volume>36</volume>
          (
          <issue>4</issue>
          ) (
          <year>2017</year>
          ). doi:
          <volume>10</volume>
          .4314/njt.v36i4.
          <fpage>38</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>E.</given-names>
            <surname>Borel</surname>
          </string-name>
          ,
          <article-title>La théorie du jeu les équations integrales á yau symétrique</article-title>
          .
          <source>Comptes Rendus de l'Académie</source>
          ,
          <volume>173</volume>
          (
          <year>1921</year>
          )
          <fpage>1304</fpage>
          -
          <lpage>1308</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Protection of Information in Telecommunication Medical Systems based on a RiskOriented Approach</source>
          , in: Workshop on Cybersecurity Providing in
          <source>Information and Telecommunication Systems</source>
          , vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>158</fpage>
          -
          <lpage>167</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <article-title>Conflict Analysis in the “Subject-to-Subject” Security System</article-title>
          ,
          <source>Cybersecurity Providing in Information and Telecommunication Systems</source>
          Vol.
          <volume>3421</volume>
          (
          <year>2023</year>
          )
          <fpage>56</fpage>
          -
          <lpage>66</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <article-title>Conflicting Subsystems in the Information Space: A Study at the Software and Hardware Levels</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>333</fpage>
          -
          <lpage>342</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>V.</given-names>
            <surname>Astapenya</surname>
          </string-name>
          , et al.,
          <article-title>Conflict Model of Radio Engineering Systems under the Threat of Electronic Warfare</article-title>
          ,
          <source>in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>3654</volume>
          (
          <year>2024</year>
          )
          <fpage>290</fpage>
          -
          <lpage>300</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Babenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Trush</surname>
          </string-name>
          ,
          <article-title>The Building of a Security Strategy based on the Model of Game Management, in: 4th International Scientific-Practical Conference Problems of Infocommunications Science and Technology, PIC S and</article-title>
          <string-name>
            <surname>T 2017 - Proceedings</surname>
          </string-name>
          (
          <year>2017</year>
          )
          <fpage>57</fpage>
          -
          <lpage>60</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>S.</given-names>
            <surname>Huang</surname>
          </string-name>
          , et al.,
          <article-title>Markov Differential Game for Network Defense Decision-Making Method</article-title>
          , IEEE Access,
          <volume>6</volume>
          (
          <year>2018</year>
          )
          <fpage>39621</fpage>
          -
          <lpage>39634</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>T.</given-names>
            <surname>Nguyen</surname>
          </string-name>
          , et al.,
          <article-title>Multistage Attack Graph Security Games: Heuristic Strategies, with Empirical GameTheoretic Analysis, Security and Communication Networks (</article-title>
          <year>2018</year>
          ). doi:
          <volume>10</volume>
          .1155/
          <year>2018</year>
          /2864873.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>