Submitted:
08 July 2026
Posted:
09 July 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
- A simulation confidence factor S measuring agreement between Monte Carlo-predicted attack paths and observed actions, embedded directly into the defender payoff function so that higher prediction accuracy produces higher equilibrium payoff;
- A multi-stage, temporally discounted payoff function that incorporates simulation confidence, response latency, and stage-specific costs across all five CKC stages;
- A Bayesian belief update augmented with simulation-predicted action distributions, enabling attacker type estimation to be refined after each CKC stage;
- A fictitious play algorithm for SSE computation with a convergence proof, evaluated against BNE and three additional baselines on a 10-node enterprise network.
2. Related Work
2.1. Game-Theoretic Approaches to Cyber Defense
2.2. Attack Modeling and the Cyber Kill Chain
2.3. Bayesian Games and Belief Update Mechanisms
3. System Model and Problem Formulation
3.1. Network and Threat Model
3.2. Stackelberg Game Formulation
![]() |
(1) |
4. Multi-Stage Payoff Model with Simulation Integration
4.1. Attack Behavior Simulation and Confidence Factor
![]() |
(2) |
4.2. Defender Payoff Function
![]() |
(3) |
4.3. Attacker Payoff Function
![]() |
(4) |
4.4. Impact of Simulation Confidence on Defender Payoff
5. Belief Update Mechanism and SSE Computation Algorithm
5.1. Simulation-Augmented Bayesian Belief Update
![]() |
(5) |
![]() |
(6) |
5.2. SSE Computation via Fictitious Play
![]() |
(7) |
| Algorithm 1: Simulation-Augmented Fictitious Play for SSE Computation ───────────────────────────────────────────────────────────────── Input: Game Γ = ⟨N, A, Θ, μ0, U⟩, N_sim=1000, ε=0.001, ε_b=0.05 Output: SSE strategy σ_D*, SSE payoff U_D* ───────────────────────────────────────────────────────────────── 1: Initialize σ_D0 ← uniform mixed strategy over A_D 2: Initialize μ0(θ_k) ← 1/K for all k 3: t ← 0 4: while d^t ≥ ε do 5: for each stage s = 1 to 5 do 6: Run N_sim Monte Carlo simulations → {â_A} 7: Compute S^s ← 1 - d(â_A, a_A) / d_max 8: a_A*(t) ← argmax_{a_A} U_A(σ_D^t, a_A, μ^t) 9: Solve LP: σ_D^{t+1} ← argmax_{σ_D} Σ_k μ^t(θ_k)·U_D(σ_D, a_A*(θ_k), S^s) 10: Update μ^{t+1}(θ_k) via Equations (4)–(5) 11: end for 12: Compute d^t ← ‖σ_D^{t+1} - σ_D^t‖ + ‖σ_A^{t+1} - σ_A^t‖ 13: t ← t + 1 14: end while 15: return σ_D* ← σ_D^t, U_D* ← U_D(σ_D*, a_A*, S) ───────────────────────────────────────────────────────────────── |
5.3. Convergence Analysis
6. Experimental Evaluation
6.1. Experimental Setup
6.2. Impact of Response Latency on Defender Payoff
6.3. Algorithm Convergence Comparison
6.4. Performance Comparison Across Defense Methods
6.5. Sensitivity Analysis
7. Conclusions
References
- Hutchins, E.M.; Cloppert, M.J.; Amin, R.M. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. In Proceedings of the 6th International Conference on Information Warfare and Security, Washington, DC, USA, 17–18 March 2011; pp. 113–125. [Google Scholar]
- Von Stengel, B.; Zamir, S. Leadership games with convex strategy sets. Games Econ. Behav. 2010, 69, 446–457. [Google Scholar] [CrossRef]
- Shan, X.; Zhuang, J. Hybrid defensive resource allocations in the face of partially strategic attackers in a sequential defender-attacker game. Eur. J. Oper. Res. 2013, 228, 262–272. [Google Scholar] [CrossRef]
- Zhu, Q.; Başar, T. Game-theoretic approach to feedback-driven multi-stage moving target defense. In Proceedings of the International Conference on Decision and Game Theory for Security, Fort Worth, TX, USA, 14–15 November 2013; Springer: Berlin/Heidelberg, Germany, 2013; pp. 246–263. [Google Scholar] [CrossRef]
- Manshaei, M.H.; Zhu, Q.; Alpcan, T.; Başar, T.; Hubaux, J.P. Game theory meets network security and privacy. ACM Comput. Surv. 2013, 45, 25. [Google Scholar] [CrossRef]
- Roy, S.; Ellis, C.; Shiva, S.; Dasgupta, D.; Shandilya, V.; Wu, Q. A survey of game theory as applied to network security. In Proceedings of the 2010 43rd Hawaii International Conference on System Sciences, Kauai, HI, USA, 5–8 January 2010; IEEE: New York, NY, USA, 2010; pp. 1–10. [Google Scholar]
- Tambe, M. Security and Game Theory: Algorithms, Deployed Systems, Lessons Learned; Cambridge University Press: Cambridge, UK, 2011; ISBN 978-1-107-00843-5. [Google Scholar]
- Conitzer, V.; Sandholm, T. Computing the optimal strategy to commit to. In Proceedings of the 7th ACM Conference on Electronic Commerce, Ann Arbor, MI, USA, 11–15 June 2006; ACM: New York, NY, USA, 2006; pp. 82–90. [Google Scholar] [CrossRef]
- Spring, J.M.; Kern, S.; Summers, A. Global adversarial capability modeling. In Proceedings of the 2015 APWG Symposium on Electronic Crime Research, Barcelona, Spain, 26–28 May 2015; IEEE: New York, NY, USA, 2015; pp. 1–21. [Google Scholar]
- Rubinstein, A. Modeling Bounded Rationality; MIT Press: Cambridge, MA, USA, 1998; ISBN 978-0-262-18187-5. [Google Scholar]
- Aven, T. On the meaning of a black swan in a risk context. Saf. Sci. 2013, 57, 44–51. [Google Scholar] [CrossRef]
- Brown, G.W. Iterative solution of games by fictitious play. Act. Anal. Prod. Alloc. 1951, 13, 374–376. [Google Scholar]
- Fudenberg, D.; Tirole, J. Game Theory; MIT Press: Cambridge, MA, USA, 1991; ISBN 978-0-262-06141-4. [Google Scholar]
- Sinha, A.; Malo, P.; Deb, K. A review on bilevel optimization: From classical to evolutionary approaches and applications. IEEE Trans. Evol. Comput. 2018, 22, 276–295. [Google Scholar] [CrossRef]
- Zhuang, R.; De, S.; Chen, X. A game-theoretic approach for active defense resource allocation in enterprise networks. IEEE Trans. Netw. Sci. Eng. 2021, 8, 2535–2548. [Google Scholar] [CrossRef]
- Anwar, M.W.; Farris, K.A. Game theory-based cyber deception framework against advanced persistent threats. In Proceedings of the 2022 IEEE International Conference on Cyber Security and Resilience (CSR), Rhodes, Greece, 27–29 July 2022; IEEE: New York, NY, USA, 2022; pp. 372–377. [Google Scholar] [CrossRef]
- Gnas, M.; Hieb, J.L. Defending against multi-stage attacks using a cyber kill chain-based game. J. Cybersecur. 2020, 6, tyaa010. [Google Scholar] [CrossRef]
- Horák, K.; Krmíček, V. Dynamic Bayesian game model for cyber security. IEEE Access 2022, 10, 56003–56017. [Google Scholar] [CrossRef]




| Parameter | Symbol | Value | Description |
| Asset value (defender) | V_D | 10.0 | Normalized monetary/operational value of protected asset |
| Simulation amplification | λ | 0.35 | Payoff gain per unit simulation confidence |
| Latency decay coefficient | μ | 0.10 | Exponential rate of payoff decay with response delay |
| Latency penalty | β | 0.05 | Linear cost per second of response delay |
| Temporal discount factor | γ | 0.92 | Stage-to-stage payoff discount (per CKC stage) |
| Max behavioral divergence | d_max | 1.0 | Normalization bound for confidence computation |
| Simulation trials per stage | N | 1000 | Monte Carlo iterations per CKC stage |
| Convergence threshold | ε | 0.01 | Nash distance termination criterion |
| Belief smoothing factor | ε_b | 0.05 | Dirichlet smoothing for belief update stability |
| Method | U_D | Δt (s) | Iterations | P_def (%) |
| Proposed SSE | 2.90 | 1.09 | 199 | 38.9 |
| BNE Baseline | 2.67 | 1.40 | 354 | 43.3 |
| RBDD | 2.27 | 1.00 | N/A | 35.6 |
| SDS | 2.19 | 1.08 | N/A | 35.9 |
| RDS | 2.47 | 1.08 | N/A | 38.5 |
| λ | γ = 0.85 | γ = 0.90 | γ = 0.92 | γ = 0.95 |
| 0.10 | 3.30 | 3.23 | 3.20 | 3.16 |
| 0.20 | 3.46 | 3.39 | 3.36 | 3.31 |
| 0.35 | 3.69 | 3.62 | 3.59 | 3.54 |
| 0.50 | 3.93 | 3.85 | 3.82 | 3.77 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.






