๐ค AI Summary
This study addresses the challenge of quantifying optimal timing for proactive defense in single-attack scenarios by proposing a stochastic-process-based analytical framework, which introduces stochastic game theory into cybersecurity for the first time. By modeling defense as a continuous observation mechanism and integrating exponential distributions, Markovian Poisson arrival processes, LaplaceโCarson transforms, and first-exit theory, the work explicitly derives the marginal distribution and conditional expectation of defensive actions. A joint detection function is constructed to precisely localize the attack instant. The approach not only enables visualization of defense density but also provides conditional expectations of observation times before and after an attack, facilitating dynamic calibration of low-latency proactive defense parameters according to threat intensity.
๐ Abstract
This research presents a novel stochastic framework for proactive cybersecurity defense timing under a single attack scenario. The approach models the defense process as a continuous observation mechanism in which the defense instant and the subsequent observation slot follow independent exponential distributions. Laplace-Carson transforms combined with first-excess theory yield the joint detection function that brackets the attack moment. Marginalization under Markovian Poisson arrivals then produces the probability density of the defense moment and conditional expectations of pre-attack and post-attack observation times. These closed-form results enable quantitative assessment of defense timing sensitivity to threat intensity and support precise calibration of observation parameters for low-latency proactive measures. Major contributions include the explicit derivation of marginal distributions and expected values, visualization of defense moment density, and the bridging of stochastic duel methodology with practical cybersecurity applications.