Abstract
Defending against sophisticated cyber threats demands strategic allocation of limited security resources across complex network infrastructures. When the defender has limited defensive resources, the complexity of coordinating honeypot placements across hundreds of nodes grows exponentially. In this paper, we present a multi-attacker Bayesian Stackelberg framework for honeypot allocation against concurrent adversaries traversing a directed network. Each attacker is modeled as a follower with a latent type drawn from a finite set, parameterized by target preferences and exploit feasibility/costs. The defender maintains a posterior over attacker types from noisy IDS/honeypot observations and, at each round, re-optimizes the defense by solving a DOBSS-style multi-follower mixed-integer linear program (MILP) under the current belief state. To scale to realistic graphs, we leverage a Purdue-model-inspired layered structure to generate level-wise candidate deployments and introduce posterior/value-driven pruning, adaptive top-k scaling by level importance, selective high-value interaction modeling, and distance precomputation. Experiments show that the proposed method delivers improvements over standard baselines and achieves the strongest overall realized defender payoff when performance is aggregated across deployment-capacity settings, with particularly pronounced payoffs as defensive resources increase. These results demonstrate that belief-driven equilibrium replanning enables scalable and effective cyber deception in multi-attacker environments under uncertainty.
| Original language | English |
|---|---|
| Article number | 104949 |
| Journal | Computers and Security |
| Volume | 168 |
| DOIs | |
| State | Published - Sep 2026 |
Fingerprint
Dive into the research topics of 'Adaptive honeypot allocation in multi-attacker networks via Bayesian Stackelberg Games'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver