Skip to main navigation Skip to search Skip to main content

Adaptive honeypot allocation in multi-attacker networks via Bayesian Stackelberg Games

  • Boise State University

Research output: Contribution to journalArticlepeer-review

Abstract

Defending against sophisticated cyber threats demands strategic allocation of limited security resources across complex network infrastructures. When the defender has limited defensive resources, the complexity of coordinating honeypot placements across hundreds of nodes grows exponentially. In this paper, we present a multi-attacker Bayesian Stackelberg framework for honeypot allocation against concurrent adversaries traversing a directed network. Each attacker is modeled as a follower with a latent type drawn from a finite set, parameterized by target preferences and exploit feasibility/costs. The defender maintains a posterior over attacker types from noisy IDS/honeypot observations and, at each round, re-optimizes the defense by solving a DOBSS-style multi-follower mixed-integer linear program (MILP) under the current belief state. To scale to realistic graphs, we leverage a Purdue-model-inspired layered structure to generate level-wise candidate deployments and introduce posterior/value-driven pruning, adaptive top-scaling by level importance, selective high-value interaction modeling, and distance precomputation. Experiments show that the proposed method delivers improvements over standard baselines and achieves the strongest overall realized defender payoff when performance is aggregated across deployment-capacity settings, with particularly pronounced payoffs as defensive resources increase. These results demonstrate that belief-driven equilibrium replanning enables scalable and effective cyber deception in multi-attacker environments under uncertainty.
Original languageEnglish
Article number104949
JournalComputers and Security
Volume168
DOIs
StatePublished - Sep 2026

Fingerprint

Dive into the research topics of 'Adaptive honeypot allocation in multi-attacker networks via Bayesian Stackelberg Games'. Together they form a unique fingerprint.

Cite this