Netinfo Security ›› 2024, Vol. 24 ›› Issue (8): 1241-1251.doi: 10.3969/j.issn.1671-1122.2024.08.010

Previous Articles     Next Articles

Inducement Game Model of Data-Stealing Trojan Based on Stochastic Game Nets

GUO Yuzheng1,2, GUO Chun1,2(), CUI Yunhe1,2, LI Xianchao1   

  1. 1. College of Computer Science and Technology, Guizhou University, Guiyang 550025, China
    2. Engineering Research Center for Text Computing and Cognitive Intelligence, Ministry of Education, Guiyang 550025, China
  • Received:2024-05-13 Online:2024-08-10 Published:2024-08-22

Abstract:

To achieve the long-term goal of information theft, data-stealing Trojans typically employ the trigger execution strategy, providing high concealment and uncertainty in the execution of their malicious actions. The mainstream defense model against data-stealing Trojans adopts a passive defense strategy that involves monitoring and detecting the behavior of these Trojans, but is prone to omissions and delayed detection. To improve the defense effectiveness, this paper introduced the concept of inducement operation to construct an inducement-based defense strategy targeting data-stealing Trojans. Using stochastic game nets, this paper modeled and analyzed the confrontation process between the data-stealing Trojans and defenders, resulting in the development of the Inducement Game Model of Data-Stealing Trojan (IGMDT-SGN). IGMDT-SGN provides a clear illustration of the strategic logic and temporal dynamics of employing the inducement defense strategy against these Trojans. Quantitative analysis conducted through model calculations shows that the inducement defense strategy, as presented in IGMDT-SGN, outperforms the passive defense strategy in terms of defense success rate and average defense time. This finding provides useful guidance for defending against data-stealing Trojans.

Key words: data-stealing Trojan, game model, inducement operation, stochastic game nets

CLC Number: