Abstract
We demonstrate that game-theoretic calculations serve as a useful tool for assisting cyber wargaming teams in identifying effective strategies. We note a significant similarity between formulating cyber wargaming strategies and the methodology known in the military practice as Course of Action (COA) generation. For scenarios in which the attacker must penetrate multiple layers in a defense-in-depth security configuration, an accounting of attacker and defender costs and penetration probabilities provides cost–utility payoff matrices and penetration probability matrices. These can be used as decision tools by both the defender and attacker. Inspection of the matrices allows players to deduce preferred strategies (COAs) based on game-theoretical equilibrium solutions. The matrices also help in analyzing the anticipated effects of potential human-based choices of wargame strategies and counter-strategies. We describe a mathematical game-theoretic formalism and offer detailed analysis of a cyber-physical table-top wargame executed at the US Army Research Laboratory. Our analysis shows how game-theoretical calculations can indeed provide a useful tool for effective decision-making during cyber wargames.
1. Introduction and motivation
Cyber wargaming is increasingly often used by commercial and public-sector organizations. Such a wargame typically involves actual employees of an organization who play roles in a human-based (and occasionally computer-based) simulation of a cyber attack and responses to the attack. A number of consulting organizations provide wargaming design and facilitation as a service. 1 The growing prominence of cyber wargames is hardly surprising. Cyber conflicts involve problems of an adversarial nature, not unlike those in military practice, and these are often solved by resorting to game-theoretic models, or by simulations—wargames.
However, theoretical foundations and guidance for cyber wargaming are lacking. In this paper, we offer a game-theoretic model of cyber attack and defense, compare the model-based analysis with experiences of an actual table-top wargame, and offer recommendations on using game-theoretic analysis for enhancing the accuracy and value of such cyber wargames.
1.1. Current practices of cyber wargaming
In spite of its growing popularity among corporate and government organizations, 2 the term “cyber wargame” is not particularly well defined and may refer to many different forms of an exercise, test, simulation, or emulation event. Typically, unlike penetration testing in which “white hat” hackers seek to find the company’s technical vulnerabilities, a corporate cyber wargame often places emphasis on a business scenario involving a cross-section of the company’s business functions.3–5 Modern cyber wargaming in corporate and government scenarios6,7 utilizes the insights and experience gained from military wargaming.8–10
The wargame is structured—often by a specialized consulting organization hired for this purpose 1 —to simulate experiences of a real cyber attack, and realistic responses to it. Participants of the wargame often comprise the company’s employees from multiple functional areas: information security, application development, network operations, facilities management, customer service, production, marketing, legal and public affairs, financial, and distribution. These players gather in one or several conference rooms, for a duration of anywhere from 4 hours to 3 days, and under the guidance of professional facilitators proceed to enact the events of a cyber attack, usually developing a strong commitment and passion in the game.
Great diversity in the types and forms of cyber wargames is found in current cyber exercises. Such diversity can be characterized along several dimensions.
Breadth of business functions: the focus of a wargame may range from strictly technical considerations of vulnerabilities, capabilities, and activities of software and hardware to a broad coverage of business functions, for example, financial, media, legal, and business operations aspects, where the technical cyber compromise is merely a starting point of the scenario. This may correlate with the seniority of decision-makers involved: broader scenarios may involve leaders higher on the corporate ladder.
Scale of an entity under consideration: a wargame may concern itself with an entity limited to a single web server to large-scale operations or a multi-national corporation; it could be a single system or network, a site or an enterprise or an international system of enterprises.
Realism of the game: a wargame may range from a table-top exercise with little more than paper and pencil, to computer-assisted simulations, to use of emulated cyber ranges, and even to attacks on operational systems.
The process of designing, implementing, and executing a cyber game normally involves most of the following steps (not necessarily sequential or in this order). They could be performed by a consulting organization in close collaboration with personnel of the company. 2
Defenses: identify security mechanisms, tools, and personnel, their attributes and capabilities.
Threats: hypothesize suitable threats, their capabilities, and likely TTPs (Tactics, Techniques, and Procedures), goals, limitations, access opportunities, skill levels, time, and resources available to them.
Attacks: formulate and select attack scenarios, including at least two: that most likely to be executed by the threat against this organization and most dangerous, and that which may be less likely but would cause the greatest damage.
Players: recruit relevant participants-defenders from the company who are relevant to the site or enterprise being wargamed and who would realistically be engaged in defending against a given a threat scenario.
Blue cell(s): organize the participants-defenders into a team or teams responsible for planning and executing defensive actions; such a team is called a Blue cell; preferably, participants are organized into teams (cells) that are reflective of the actual organizational structure of the company.
White cell: provide a white cell, that is, trained individuals who have experience in wargames and can document important information emerging during the wargame, guide and facilitate the game, and adjudicate or arbitrate outcomes of individual actions taken by participants. These are usually outside consultants.
Red cell: provide or designate a team of individuals who play the role of the attacker; such a team is called the Red cell.
Rooms and props: prepare physical facilities, means of communication, and paper- or computer-based products to conduct the game.
Play: assemble all cells, begin execution of the scenario, let the Red cell attack, Blue cell defend, and White cell declare the status as it evolves and inject additional events to keep the game moving in the right direction.
Payoff: analyze the observations and results of the game, and formulate recommendations.
The outcomes and benefits of the cyber wargame vary depending on the goals of the organization. These may include identification of hidden vulnerabilities, incorrect assumptions, and the need for additional procedures and training.
A cyber wargame can also help identify poorly understood risks; educate and entertain personnel; obtain support of senior decision-makers; explore the extent of potential disruption to various business functions; clarify the roles and responsibilities of cyber responders; improve communication among them; allow stakeholders to get to know one another, and build relationships; understand decision-making authorities; highlight interactions with third-party business partners; and identify potential gaps in an organization’s preparedness and response plans.
1.2. Military practice of Course of Action analysis
Many of the techniques used in cyber wargaming appear to be influenced or directly borrowed from military wargaming practices. The US Navy War College has provided extensive expertise and documented guidance for military wargaming.9,10 In the US Army, wargaming practice is often called Course of Action (COA) analysis.11,12 Although such analysis is performed by military units of various sizes—from a small unit called squad to a very large organization called a corps—here we will use an example of a unit called a Brigade Combat Team (BCT).
Somewhat comparable to a mid-size corporation, a US Army BCT includes several thousands of professional soldiers and officers, hundreds of combat and support vehicles, helicopters, sophisticated intelligence and communication equipment and specialists, artillery and missiles, engineers, medical units, and repair shops. In a battle, these assets might perform hundreds of complex tasks of multiple types (similar to corporate “business functions”): collecting intelligence; movements; direct and indirect fires; constructing roads, bridges, and obstacles; transporting and handling supplies; managing the civilian population; command and control; and so on. Unlike in cyber wargaming, the threat (i.e., the enemy that the BCT fights against) tries to apply much physical destruction to the BCT, although cyber attacks are often also a part of the threat’s repertoire.
Detailed planning of a military operation requires an intensive effort of highly trained professionals, called the BCT planning staff. Typically, it consists of four or five officers, ranging in rank from captain to lieutenant colonel, who perform this work with the support of a subordinate staff. The process normally takes from 2 to 8 hours—not unlike a typical cyber wargame. The physical environment often consists of a tent extended from the back of one or several Army trucks or armored command-and-control vehicles; folding tables and chairs; and—similar to a cyber wargame—either computer screens or paper maps on which the officers draw symbols of units and arrows of movements.
The input for the staff’s effort comes usually from the unit commander as a high-level specification of the operation. With this input, the planning staff works as a team—called the Blue cell—performing actual wargaming, including the following.
Predicting enemy actions or reactions. This is done by the Red cell, usually the officer who specializes in collecting and analyzing enemy intelligence. 13 The Red cell plays the role of the enemy in order to help the Blue cell understand possible actions and responses of the enemy. Similar to the cyber wargames, the Red cell provides two cases of enemy actions: the most likely plan of enemy actions, and the most dangerous (to the BCT) plan of enemy actions. The latter might be the same as the former, but usually it is different as it involves assumptions of greater capabilities on the part of the enemy.
Planning and scheduling the detailed tasks required to accomplish the specified COA, 14 and to prevent or respond to the threat actions (like the Blue cell defenders would do in a cyber wargame), and allocating tasks to the diverse forces constituting the BCT (like elements of a corporate response to a cyber attack).
Estimating the success of failure of friendly and enemy actions, and battle losses. 15 This is similar to the function performed by the White cell in cyber wargaming.
The process of estimating enemy actions and friendly actions may repeat in several cycles until a convergence is achieved: the Red cell is unable to suggest any further improvements of the enemy actions, and the Blue cell is unable to suggest any further improvements of the friendly actions. This hints at reaching something akin to Nash equilibrium, in game-theoretic terms.
This wargaming usually produces a plan/schedule in a synchronization-matrix format, a type of Gantt chart (see Figure 1). The chart’s columns represent time periods. The rows contain functional classes of actions, such as Maneuver (which in turn includes such subclasses as Main Effort and Security), Combat Service Support (for example, logistics), Military Intelligence, and so on. This plan-schedule’s content, recorded largely in the matrix cells, includes the tasks and actions of the friendly force’s subunits and assets, their objectives and manner of execution, expected timing, dependencies and synchronization, routes and locations, availability of supplies, combat losses, enemy situation and actions, and so on.

Fragment of a wargaming output in a synchronization-matrix format, adapted from Rasch et al. 14 The horizontal axis is time and the vertical axis describes specific wargame functions.
Ultimately, the purpose of the military wargame is for the Blue cell to consider and select a small (manageable, often of the order of three) number of COAs that are seen as most advantageous to the Blue side. In doing so, the Blue cell has to make an assumption about the COA that would be adopted by the Red side. In military wargaming, there are several ways to approach this difficult decision.
One approach is to consider the “most likely” COA of the opponent, that is, the Red COA that the Blue cell feels is most likely to be adopted by the Red side. This assessment of likelihood might be based on the Blue cell’s knowledge of the Red side’s preferences, for example, the COAs that the Red side has adopted in previous battles. Alternatively, the Blue cell might decide that the most likely Red COA is the one that provides the Red side with the greatest advantage or greatest utility in the battle.
Another approach might be to consider the “most dangerous” or “most damaging” Red COA—the COA that would cause the greatest damage to the Blue side. Note that the “most likely” and “most damaging” Red COAs are often different.
Having selected the “most likely” Red COA, and the “most damaging” Red COA, the Blue cell usually attempts to select a Blue COA that would perform sufficiently well against both of the Red COAs.
Besides creating this tangible set of potential strategies, other valuable outcomes of this wargaming are similar to those of corporate cyber wargames: identification of hidden vulnerabilities; incorrect assumptions; risks and losses; education; and clarity of roles and responsibilities. It is important to note that the execution and modeling of a wargame is not necessarily representative of a real-world encounter. Real-world actors likely do not have complete knowledge of the strategies and limitations of their opponents and a systematic or mathematical formulation for computing optimal strategies may be difficult or impractical. While complex models may be able to be constructed for real-world scenarios, it is outside the scope of this paper to do so; our simple model is meant to apply only to cyber wargaming.
In the remainder of the paper, we first propose a game-theoretic model of a contest between cyber attacker and cyber defender. Then we describe an actual cyber wargame designed and led by one of this paper’s authors. We explore how our theoretical model may apply to the actual wargame. Finally, we discuss the insights and benefits that the model brings to the cyber wargame, and offer a set of practical recommendations for designing and conducting cyber wargames.
2. Game-theoretic method
In this section, we formulate an approach to the analysis of a cyber wargame problem that combines elements of game-theoretic and risk analytic treatments. We believe our approach is useful as a computational tool to aid in complex wargame and training exercises in which the strategy space is larger or more complex than is normally possible for most humans to explore. In a later section of the paper, we then discuss an example of a real-world process where an approximation of this approach is used.
2.1. Mathematical model
In the following formulation, we are partly inspired by Hausken. 16 Consider the cyber-physical system in Figure 2.

Sample cyber-physical system (CPS) connected to the Internet. Three programmable logic controllers (PLCs) control fuel tanks and a dispensing authorization station.
For this system, a cyber attacker desires to obtain a benefit b by accessing the system via the Internet and eventually obtaining control of the plant’s programmable logic controllers (PLCs). In doing so, the attacker would have to penetrate defensive mechanisms and overcome actions of the defenders in several layers of the cyber-physical system.
To make the discussion more general, in Figure 3 we illustrate an abstract notion of the problem: an attacker enters the outer attack surface with the intention of penetrating a series of layers guarded by the defender before arriving at the target. Penetration of the layers will require specific malicious actions, and the overall path to the target determines the precise attacker “strategy” that the attacker intends to use.

Abstract illustration of an attacker and defender penetrating and protecting Nl cyber layers surrounding a central target. The attacker receives benefit b after penetrating the final layer.
We describe the plans of the attacker with a set of
As shown in Figure 3, there are
There are costs for both the attacker and the defender for each specific strategy tuple
Finally, given a strategy choice
In the model below, we consider the scenario of when the attacker gains benefit b, the defender loses an equivalent value (b) of his assets. This constraint could easily be modified as the situation demands.
The attacker and defender expected utility
or, in shorthand notation:
Likewise, for the defender:
or, in shorthand notation:
The challenge for each player is to select the strategy,
2.2. Strategy selection
Once the attacker and defender costs and penetration probabilities are known or assumed, payoff matrices
2.2.1 Pure strategy equilibria
We first describe the case in which the players choose a single unique strategy (pure strategy approach) as opposed to estimating a probabilistically weighted set of multiple strategies (a.k.a. mixed-strategy approach).
The model outlined in Section 2.1 does not describe a zero-sum game (defined as
That is, if we search over each defense strategy j for the preferred attack strategies
and, likewise, search over each attack strategy i for the preferred defense strategies
and find saddle points in the payoff matrices, one or more “most likely” equilibrium strategies may be found. If only one equilibrium point is found, it is by definition a Nash equilibrium. We illustrate this method further in Sections 3 and 4.
Equilibrium strategies such as these may be preferred by the players in the case when the payoff matrices are fully disclosed to both players and both players must choose their strategy simultaneously.
2.2.2. Strong Stackelberg Strategy Equilibria
A common method for finding solutions to non zero-sum games is to assume that one of the players has the opportunity to be first in selecting his strategy, and chooses a mixed-strategy solution and the opponent follows with a pure strategy (i.e., a single strategy with 100% probability). The equilibrium strategies in this scenario are known as Strong Stackelberg Equilibria (SSE).17,18 If the wargame is played in this manner, the leader and the follower could use one of the many methods for finding SSE solutions, such as those described by Korzhyk et al. 19 While we do not discuss SSE further in this work, we later consider an example where multiple strategies are considered to some extent.
2.2.3. Playing against the most likely strategy of the opponent
As described in Section 1.2, a player may choose a strategy by first estimating the “most likely” strategy of the opponent, based on any available information about the opponent. Then the player selects his own strategy based on how successful it will be against the “most likely” strategy of the opponent.
2.2.4. Playing against the most damaging strategy of the opponent
Alternatively, as described in Section 1.2, a player may choose a strategy by first estimating the “most damaging” strategy of the opponent, that is, the strategy in which the opponent would impose the most severe losses on the player. Then the player selects his own strategy based on how successful it will be against the “most damaging” strategy of the opponent.
2.3. Sample calculation
To illustrate, we provide sample calculations for a simple scenario. Suppose a freelancing cyber-crime group is engaged by an anonymous third party to penetrate controls of a munitions plant. Two layers of the network need to be defeated:
Based on the preliminary reconnaissance of the plant’s network, the attacker considers two possible strategies. The first strategy
Using Equation (1), the expected attacker utilities for the first and second attacks are, respectively:
Clearly, the second attack has higher utility and therefore the attacker selects
2.4. Practical considerations
To generalize, the overall process for calculating the game-theoretic quantities in Section 2.1 is as follows:
collect information about
compute cost-utility functions (payoff matrices) and the total penetration probability matrix using Equations (1)–(3);
utilize the payoff matrices to determine the best strategy (see Section 2.2).
The most difficult step may be the first one. Quantitative data, such as
2.5. Relation to military wargaming practice
As described in Section 1.2, the practice and process of military wargaming (COA analysis) is as follows. Having collected and considered the relevant information, the Blue cell officers propose a friendly defense strategy
In a comparable cyber wargame, our game-theoretic model and strategy selection methods offer an analytical tool for the Blue and Red cells to decide on their initial strategies
3. Experimental investigation of cyber wargaming
3.1. General
As a more elaborate example, we consider the application of our game-theoretical framework to a table-top wargaming activity conducted at the US Army Research Laboratory. 20 In this event, a fictitious AQUA cyber-physical control system (specifically, an Industrial Control System [ICS]) was designed and presented to two teams of human cyber experts—a RED team (i.e., Red cell) and a BLUE team (i.e., Blue cell)—representing the attacker and defender, respectively.
3.2. AQUA wargame information packet
A technical information packet 21 describing the AQUA ICS was provided to both teams before the exercise began. Highlights from the information packet follow.
The AQUA ICS is a food processing plant that produces packaged meals. The process map for our fictitious AQUA plant is shown in Figure 4. The plant executes six manufacturing processes. The meat and vegetables are cooked separately. Once they are cooked, the meals are prepared and packaged in a material suitable for high-pressure processing. Once the high-pressure process is completed, the meals are placed in boxes and stored in a warehouse.

Process map for the production line in the ficticious AQUA plant.
The plant network used by the AQUA is shown in Figure 5. It consists of six PLCs, several workstations, a closed circuit television (CCTV) system, and a wireless network for tablet computers. Technicians use the tablet computers to access the human–machine interface (HMI) displays. The plant network is not connected to the corporate network or the Internet. All plant machinery is hard-wired to the input and output modules of the PLCs. The CCTV cameras are hard-wired to the digital video recorder (DVR).

Plant network used to control the AQUA production line system.
3.3. Cyber wargame method and execution
Before the wargame began, in addition to reviewing the information packet read-ahead document, both teams were allowed to ask the game facilitators specific technical questions. Answers were shared with both teams. During the exercise, the RED and BLUE teams met separately to review all of the technical information and discuss strategies. Each team documented their potential strategies. After this, the teams converged to share their findings. The RED team shared their attack strategies with the BLUE team. Mitigations, counter-attacks, and counter-mitigations were discussed. Details about the RED team strategies and BLUE team mitigations can be found in Colbert et al. 20 The representation of those results in terms of our game-theoretic framework (Section 2.1) is described in the following sections.
3.4. Description of game-theoretic variables
3.4.1. Attack and defense strategies
The RED team submitted five attack strategies
RED team attack strategies.
PLC: programmable logic controller.
The BLUE team proposed 15 specific mitigations (see Table 2) for their defense against the proposed attack strategies. Since it is not feasible to consider all possible (
BLUE team defense strategies and mitigations. Estimated costs are shown for individual mitigations and for the five strategies associated with the mitigations.
VLAN: virtual local area network; BIOS: Basic Input/Output System; PLC: programmable logic controller; IDS: Intrusion Detection System; STIG: Security Technical Implementation Guide.
3.4.2. Defender computations
We next describe our game-theoretical computations. Since all strategies by both BLUE and RED teams were known by both teams in the exercise, costs and penetration probabilities of the RED team were estimated based on the BLUE team mitigations. We therefore discuss the defender mitigations and computations first.
We first construct a translation matrix
The vector defining defender costs by mitigation m,
Although the defender costs are not dependent on the attacker strategies {i}, we construct the defender cost matrix over {ij}:
and use it to compute the defender utility. Here, we have assumed that the defender strives to keep the portion of the defender’s assets b that would have otherwise been forfeited to the attacker as a benefit. The probability that those assets are not forfeited is
We can then compute the defender cost utility as follows:
where
3.4.3. Attacker computations
Four attack layers (cf. Figure 3) were identified by the RED team. We reference the attack layers with index {l} and list descriptions of the layers in Table 3.
Penetration layers for attack.
PLC: programmable logic controller.
Attacker costs were estimated by the RED team for each attack strategy
Fixed attacker costs. These costs were independent of mitigation or defense strategy. We assume labor costs of 1k$ per hour of RED team activity.
PLC: programmable logic controller.
Differential attacker costs. These costs are dependent on BLUE team mitigations. We again assume labor costs of 1k$ per hour of RED team activity.
HID: human interface device.
For the purposes of computing our game-theoretic model, we construct attacker fixed cost
Next, we utilize the RED team input from Table 5 to construct differential attacker cost
For example, for attack 3, by examining Table 5, we can construct differential cost
Since our game-theoretical model references defender strategy j instead of mitigation m, we recompute the differential attacker cost over {l,j}:
We next need to condense {l} and construct a single differential cost matrix for all attacks {i}. By summing row vectors over {l}, we obtain
We can now compute the total attacker cost matrix
The differential penetration probabilities for the mitigations are also computed from information provided by the attacker (given in Table 5) by constructing the differential penetration probabilities
Each entry is computed by multiplying probabilities over layers {l} for each {i,m} combination. For example, from Table 5, attack 2, mitigation 8 has penetration probabilities of 0.5 for each of layers 2, 3, and 5, so that
Once
The total probability matrix can then be computed by taking the element-by-element product with the fixed probability matrix:
The utility cost of the attacker
4. Discussion
As described in Section 2, the objective of our game-theoretic model is to provide a useful analytical tool for the attacker and defender to select their strategies based on cost utilities (Equations (1) and (2)) and penetration probability (Equation (3)).
For convenience, we provide the attacker and defender cost utilities (payoff matrices) and total penetration probability matrix in Tables 6–8, respectively.
Defender cost utility
As mentioned, in both our table-top wargame and our game-theoretic framework (Section 2), we assume that defender and attacker have full knowledge of all player strategies and costs, and are able to compute the utility and penetration probability matrices.
Given all this information, how should players select the most advantageous strategies? Earlier in Sections 1.2 and 2.2, we discussed general approaches to such a selection. In the following sections, we consider how to apply those approaches in our example wargame.
4.1. Pure strategy equilibrium
If both players select their strategies simultaneously and each acts to maximize their own utility, an equilibrium strategy pair will exist if the conditions outlined in Section 2.2.1 lead to a single unique strategy pair. That is, there is a strategy pair
Preferred cost-utility strategies (see Equations (4a) and (4b)) for the attacker (A) and the defender (D).
However, consider a situation where players are uncertain about cost and benefit estimates—a likely situation in the domain of cybersecurity. The players may decide instead to use the penetration probabilities alone as utility functions so that the attacker aims to maximize
Preferred strategies for the attacker (A) and the defender (D) when the penetration probability matrix is used as a utility function instead of the cost-utility matrices.
4.2. Considering multiple strategies of the opponent
Although we are not exploring here a mixed-strategy approach, such as the Strong Stackelberg Strategy Equilibria mentioned earlier, we can consider multiple strategies in our example wargame. For the sake of concreteness, let us adopt the perspective of the BLUE team, the defenders. Looking at Table 6, the BLUE team would notice that from the attacker’s perspective strategy i = 5 is generally better than i = 4. Indeed, with i = 5, the attacker gains better utility for all defense strategies except j = 0, and even in the case of j = 0, the benefit of i = 4 for the attacker is insignificant (460 versus 465). Thus, if the cost utility is the primary consideration for the attacker, the attacker would surely select i = 5 over i = 4. Similar considerations may apply when the BLUE team explores the attacker’s strategies i =1, 2, and 3. After consideration, the BLUE team might conclude that it needs to select a strategy that defends the best against both strategies i = 1 and i = 5. Then, looking at Table 7, the BLUE team may decide that the defense strategy j = 4 offers the BLUE team a relatively safe defense (in terms of cost utility) against both i = 1 and i = 5. Thus, the BLUE team could select j = 4 as its preferred strategy in this manner based on the cost-utility matrices. To rephrase, here the defender decided that the most likely strategies of the attacker are strategy 5 and strategy 1, and then selected its own strategy 4 as it provides better outcomes whether the attacker chooses 5 or 1.
4.3. Playing against the most likely strategyof the opponent
Suppose the BLUE team has additional information that the attacker tends to be risk-averse. In that case, the attacker is likely to prefer i = 5 over i = 1, because i = 1 might cause the attacker heavy loss (–193.25 in the case that the defender selects j = 4). With this, the BLUE team can conclude that the attacker has a single “most likely” strategy i = 5. In that case, the BLUE team selects defense strategy j = 1 (with its defender’s cost utility of 685) as its best play against the attacker’s i = 5. To rephrase, here the defender decided that the one most likely strategy of the attacker is strategy 5, and then selected its own strategy 4 as the most likely to bring the best outcome against the attacker’s strategy 5.
4.4. Playing against the most damaging strategy of the opponent
Alternatively, the BLUE team might consider how to avoid heavy losses, rather than how to gain the best cost utility. Looking at Table 7, the BLUE team would notice that the attacker strategy i = 1 brings the defender the least utility against four out of five defense strategies. In other words, the attacker strategy i = 1 is the “most damaging” to the defender. In this case, j = 4 could be a strong strategy for the defender. However, considering that the “most likely” strategy of the attacker is i = 5 (as we determined above), it is safer for the BLUE team to select j = 1, which gives the BLUE team a relatively good cost utility of 235 even if the attacker selects the “most damaging”i = 1. To rephrase, here the defender decides to focus on two strategies of the attacker—the most likely strategy 5 and the most damaging strategy 1—and then selects its own strategy 1 that offers acceptable losses regardless of whether the attacker chooses the attacker’s strategy 5 or 1.
4.5. Consequential moves
In summary, our game-theoretic model computations outlined in Section 2.1 offer a set of tools in the form of matrices that the wargame players may use for selecting their initial strategies. While we do not describe consequential strategies in this work, the model could be adapted so that similar matrix calculations could be used to consider consequential strategies. Both teams would need to reassess new costs and penetration probabilities given their current position in the game. An elaborate game-in-game theoretical framework for solving a complete path through the layers of defense is described by Rass and Zhu. 23 In implementing such a decision scheme in practice, one must incorporate the effects that increasingly accurate information of the attacker has on his consequential moves as he penetrates the layers.
In the case that either the defender or the attacker selects his strategy first and the opponent follows, any of the SSE computational methods may be used to find a vector of weights for the leader initial strategy. 19 The follower can then use the payoff and penetration probability matrix to decide on his next strategy.
5. Conclusions
While our methods may have limitations in real-world scenarios, the game-theoretic model we outlined in this paper is suitable for assisting wargaming teams. We demonstrate an application of our model to a fairly realistic wargame for which opposing teams have complete knowledge of the system and each other’s strategies. Specifically, we find that the use of the model benefits the participants of a cyber wargame in several ways.
5.1. Elucidation of costs, benefits, and assumptions
The players—either within a single team or in joint discussions by both BLUE and RED teams—are motivated to explicitly define, quantify, and document a number of critical elements of their decision-making process. They discuss and document layers of the defense that the attacker must penetrate. They think about costs and benefits from the perspective of both teams. They are compelled to search for additional pertinent information about costs and timing of attacks and of defensive mitigations, as well as their probabilities of success. They uncover and clarify inconsistent assumptions. Ultimately, they either arrive at a well-reasoned consensus or a clear understanding of where the opinions differ. All these considerations and conclusions are likely to be well-documented as a result of these steps in the wargaming process
5.2. Enhancement of potential strategies
Having distilled their assumptions and estimates into overall quantifications of utilities and probabilities (such as those shown in Tables 6–8), the BLUE and RED teams can examine the data for the purposes of identifying opportunities for strategy improvements. For example, the RED team might notice that attack strategy i = 4 is clearly inferior to i = 5 from the perspective of the attacker cost utility. Should strategy i = 4 be eliminated from the attacker’s repertoire? Or, is this an indication of incomplete or inaccurate information somewhere in the process? Or, could strategy i = 4 be improved in a way that would make it competitive with i = 5? These are questions that are not likely to be asked—or answered—without such a quantitative analysis.
5.3. Articulated selection of strategies
The players can use this analytical process to engage in rational assessment of alternatives, and arrive at the selection of an appropriate strategy in a well-reasoned manner. The reasons for preferring a certain strategy can be clearly stated, often in a quantitative manner, and underlying reasons can be readily explained. Without such an analytical tool, cyber wargamers often have difficulties making a rational, explainable strategy selection.
5.4. Future research
While this line of research can be extended in a number of directions, one of them is particularly salient: relaxing the assumption that both the attacker and the defender have full knowledge of the systems and technologies available to both sides. Relaxation of this simplifying assumption raises numerous challenging research questions. For example, how should one make appropriate assumptions about the opponent’s lack of knowledge? How does making such an assumption increase the risk that the selected strategy might fail if the assumption is wrong? How can such relaxation of assumptions be portrayed realistically in human wargaming?
Footnotes
Acknowledgements
We would like to thank Professor Quanyan Zhu and Dr Jeffrey Pawlick for thoughtful discussions and suggestions.
Disclaimer
The views expressed in this article are those of the authors and do not reflect the official policy or position of the US Army, Department of Defense, or the US Government.
Funding
This research received no specific grant from any funding agency in the public, commercial, or not-for-profit sectors.
