{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T14:39:05Z","timestamp":1784212745992,"version":"3.55.0"},"reference-count":135,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2024,8,14]],"date-time":"2024-08-14T00:00:00Z","timestamp":1723593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"U.S. Department of Homeland Security","award":["24STADA00002"],"award-info":[{"award-number":["24STADA00002"]}]},{"name":"U.S. Department of Homeland Security","award":["22STESE00001-03-04"],"award-info":[{"award-number":["22STESE00001-03-04"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Games"],"abstract":"<jats:p>The focus of this review is the long and broad history of attacker\u2013defender games as a foundation for the narrower and shorter history of cyber security. The purpose is to illustrate the role of game theory in cyber security and which areas have received attention and to indicate future research directions. The methodology uses the search terms game theory, attack, defense, and cyber security in Web of Science, augmented with the authors\u2019 knowledge of the field. Games may involve multiple attackers and defenders over multiple periods. Defense involves security screening and inspection, the detection of invaders, jamming, secrecy, and deception. Incomplete information is reviewed due to its inevitable presence in cyber security. The findings pertain to players sharing information weighted against the security investment, influenced by social planning. Attackers stockpile zero-day cyber vulnerabilities. Defenders build deterrent resilient systems. Stochastic cyber security games play a role due to uncertainty and the need to build probabilistic models. Such games can be further developed. Cyber security games based on traffic and transportation are reviewed; they are influenced by the more extensive communication of GPS data. Such games should be extended to comprise air, land, and sea. Finally, cyber security education and board games are reviewed, which play a prominent role.<\/jats:p>","DOI":"10.3390\/g15040028","type":"journal-article","created":{"date-parts":[[2024,8,14]],"date-time":"2024-08-14T05:23:27Z","timestamp":1723613007000},"page":"28","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["A Review of Attacker\u2013Defender Games and Cyber Security"],"prefix":"10.3390","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7319-3876","authenticated-orcid":false,"given":"Kjell","family":"Hausken","sequence":"first","affiliation":[{"name":"Faculty of Science and Technology, University of Stavanger, 4036 Stavanger, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8605-1751","authenticated-orcid":false,"given":"Jonathan W.","family":"Welburn","sequence":"additional","affiliation":[{"name":"Pardee RAND Graduate School, 1776 Main St., Santa Monica, CA 90401-3208, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4830-6570","authenticated-orcid":false,"given":"Jun","family":"Zhuang","sequence":"additional","affiliation":[{"name":"Department of Industrial and Systems Engineering, University at Buffalo, Buffalo, NY 14260, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,8,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"881","DOI":"10.1007\/s13235-019-00335-x","article-title":"Preface to the Focused Issue on Dynamic Games in Cyber Security","volume":"9","author":"Amin","year":"2019","journal-title":"Dyn. Games Appl."},{"key":"ref_2","first-page":"30","article-title":"Game theory for cyber security and privacy","volume":"50","author":"Do","year":"2017","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"884","DOI":"10.1007\/s13235-018-00291-y","article-title":"Dynamic Games in Cyber-Physical Security: An Overview","volume":"9","author":"Etesami","year":"2019","journal-title":"Dyn. Games Appl."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"478","DOI":"10.1016\/j.ress.2009.12.001","article-title":"Assessing Risk from Intelligent Attacks: A Perspective on Approaches","volume":"95","author":"Guikema","year":"2010","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"100204","DOI":"10.1016\/j.iot.2020.100204","article-title":"Cyber resilience in firms, organizations and societies","volume":"11","author":"Hausken","year":"2020","journal-title":"Internet Things"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"355","DOI":"10.1016\/j.ejor.2023.12.023","article-title":"Fifty Years of Operations Research in Defense","volume":"318","author":"Hausken","year":"2024","journal-title":"Eur. J. Oper. Res."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"355","DOI":"10.23940\/ijpe.12.4.p355.mag","article-title":"Review of Systems Defense and Attack Models","volume":"8","author":"Hausken","year":"2012","journal-title":"Int. J. Perform. Eng."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"401","DOI":"10.1016\/j.ejor.2023.04.009","article-title":"A review of attacker-defender games: Current state and paths forward","volume":"313","author":"Hunt","year":"2024","journal-title":"Eur. J. Oper. Res."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1109\/MC.2014.366","article-title":"Security Outlook: Six Cyber Game Changers for the Next 15 Years","volume":"47","author":"Kott","year":"2014","journal-title":"Computer"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"172","DOI":"10.1287\/deca.2018.0387","article-title":"Information Sharing in Cybersecurity: A Review","volume":"16","author":"Pala","year":"2019","journal-title":"Decis. Anal."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Roy, S., Ellis, C., Shiva, S., Dasgupta, D., Shandilya, V., and Wu, Q. (2010, January 5\u20138). A survey of game theory as applied to network security. Proceedings of the System Sciences (HICSS), 2010 43rd Hawaii International Conference, Honolulu, HI, USA.","DOI":"10.1109\/HICSS.2010.35"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"216","DOI":"10.1109\/MNET.2018.1800279","article-title":"Cyber Security Game for Intelligent Transportation Systems","volume":"33","author":"Sedjelmaci","year":"2019","journal-title":"IEEE Netw."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1111\/0272-4332.t01-1-00002","article-title":"Probabilistic Risk Analysis and Game Theory","volume":"22","author":"Hausken","year":"2002","journal-title":"Risk Anal."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"342","DOI":"10.1111\/risa.12624","article-title":"Cross-Milieu Terrorist Collaboration: Using Game Theory to Assess the Risk of a Novel Threat","volume":"37","author":"Ackerman","year":"2017","journal-title":"Risk Anal."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1414","DOI":"10.1111\/risa.13257","article-title":"A Study on A Sequential One-Defender-N-Attacker Game","volume":"39","author":"Xu","year":"2019","journal-title":"Risk Anal."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1080\/00137910601159722","article-title":"Subsidies in Interdependent Security with Heterogeneous Discount Rates","volume":"52","author":"Zhuang","year":"2007","journal-title":"Eng. Econ."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1080\/00137911003775107","article-title":"Impacts of Subsidized Security on Stability and Total Social Costs of Equilibrium Solutions in an N-Player Game with Errors","volume":"55","author":"Zhuang","year":"2010","journal-title":"Eng. Econ."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1108","DOI":"10.1057\/jors.2013.53","article-title":"Subsidizing to Disrupt a Terrorism Supply Chain\u2014A Four-Player Game","volume":"65","author":"Shan","year":"2014","journal-title":"J. Oper. Res. Soc."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1287\/deca.1100.0194","article-title":"Governments\u2019 and Terrorists\u2019 Defense and Attack in a T-Period Game","volume":"8","author":"Hausken","year":"2011","journal-title":"Decis. Anal."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"33","DOI":"10.5711\/1082598318233","article-title":"Technology Adoption, Accumulation, and Competition in Multi-period Attacker-Defender Games","volume":"18","author":"Jose","year":"2013","journal-title":"Mil. Oper. Res."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"21","DOI":"10.5711\/1082598316121","article-title":"Defending against a Terrorist Who Accumulates Resources","volume":"16","author":"Hausken","year":"2011","journal-title":"Mil. Oper. Res."},{"key":"ref_22","first-page":"321","article-title":"Defending against a Stockpiling Terrorist","volume":"56","author":"Hausken","year":"2011","journal-title":"Eng. Econ."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"726","DOI":"10.1057\/jors.2011.79","article-title":"The Timing and Deterrence of Terrorist Attacks due to Exogenous Dynamics","volume":"63","author":"Hausken","year":"2012","journal-title":"J. Oper. Res. Soc."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1287\/deca.2013.0288","article-title":"Modeling Credible Retaliation Threats in Deterring the Smuggling of Nuclear Weapons Using Partial Inspection-A Three-Stage Game","volume":"11","author":"Shan","year":"2014","journal-title":"Decis. Anal."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.ejor.2011.01.019","article-title":"Balancing Congestion and Security in the Presence of Strategic Applicants with Private Information","volume":"212","author":"Wang","year":"2011","journal-title":"Eur. J. Oper. Res."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"237262","DOI":"10.1007\/s10479-015-2043-x","article-title":"Two-Stage Security Screening Strategies in the Face of Strategic Applicants, Congestions and Screening Errors","volume":"258","author":"Song","year":"2017","journal-title":"Ann. Oper. Res."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"292","DOI":"10.1016\/j.ress.2017.04.019","article-title":"N-Stage Security Screening Strategies in the Face of Strategic Applicants","volume":"165","author":"Song","year":"2017","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"118","DOI":"10.1111\/risa.12822","article-title":"Modelling Precheck Parallel Screening Process in the Face of Strategic Applicants with Incomplete Information and Screening Errors","volume":"38","author":"Song","year":"2018","journal-title":"Risk Anal."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"919","DOI":"10.1016\/j.ejor.2017.08.038","article-title":"Security Screening Queues with Impatient Applicants: A New Model with a Case Study","volume":"265","author":"Pala","year":"2018","journal-title":"Eur. J. Oper. Res."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1287\/deca.1110.0199","article-title":"Deterring the Smuggling of Nuclear Weapons in Container Freight through Detection and Retaliation","volume":"8","author":"Haphuriwat","year":"2011","journal-title":"Decis. Anal."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"866","DOI":"10.1287\/opre.1080.0643","article-title":"Interdicting a Nuclear-Weapons Project","volume":"57","author":"Brown","year":"2009","journal-title":"Oper. Res."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1002\/nav.20423","article-title":"A defender-attacker optimization of Port Radar surveillance: Defender-Attacker Optimization of Port Surveillance","volume":"58","author":"Gerald","year":"2011","journal-title":"Nav. Res. Logist."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"25","DOI":"10.5711\/1082598316425","article-title":"A Game-Theoretic Model for Defense of an Oceanic Bastion against Submarines","volume":"16","author":"Brown","year":"2011","journal-title":"Mil. Oper. Res."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"44","DOI":"10.1016\/j.compind.2017.03.007","article-title":"A game-theoretic approach to model and quantify the security of cyber-physical systems","volume":"88","author":"Orojloo","year":"2017","journal-title":"Comput. Ind."},{"key":"ref_35","first-page":"5","article-title":"Fast Design of Wireless Mesh Networks to Defend against Worst-Case Jamming","volume":"23","author":"Nicholas","year":"2018","journal-title":"Mil. Oper. Res."},{"key":"ref_36","first-page":"2319","article-title":"5G Cyberspace Security Game","volume":"42","author":"Xu","year":"2020","journal-title":"J. Electron. Inf. Technol."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"846","DOI":"10.1109\/TIFS.2022.3228520","article-title":"Power Allocation for Cooperative Jamming against a Strategic Eavesdropper Over Parallel Channels","volume":"18","author":"Xu","year":"2023","journal-title":"IEEE Trans. Inf. Forensic Secur."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"2155","DOI":"10.1109\/TWC.2015.2498934","article-title":"A Game Theoretic Analysis of Secret and Reliable Communication with Active and Passive Adversarial Modes","volume":"15","author":"Garnaev","year":"2016","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"320","DOI":"10.1016\/j.ejor.2015.04.043","article-title":"On the Value of Exposure and Secrecy of Defense System: First-Mover Advantage Vs. Robustness","volume":"246","author":"Nikoofal","year":"2015","journal-title":"Eur. J. Oper. Res."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1080\/10242694.2010.491668","article-title":"Secrecy and Deception at Equilibrium, with Applications to Anti-Terrorism Resource Allocation","volume":"22","author":"Zhuang","year":"2011","journal-title":"Def. Peace Econ."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1737","DOI":"10.1111\/j.1539-6924.2010.01455.x","article-title":"Reasons for Secrecy and Deception in Homeland-Security Resource Allocation","volume":"30","author":"Zhuang","year":"2010","journal-title":"Risk Anal."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"409","DOI":"10.1016\/j.ejor.2009.07.028","article-title":"Modeling Secrecy and Deception in a Multiple-Period Attacker-Defender Signaling Game","volume":"203","author":"Zhuang","year":"2010","journal-title":"Eur. J. Oper. Res."},{"key":"ref_43","first-page":"31","article-title":"Secrecy in Defensive Allocations as a Strategy for Achieving More Cost-Effective Attacker Deterrence","volume":"5","author":"Dighe","year":"2009","journal-title":"Int. J. Perform. Eng."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"286","DOI":"10.1287\/deca.1110.0218","article-title":"Target-Hardening Decisions Based on Uncertain Multiattribute Terrorist Utility","volume":"8","author":"Wang","year":"2011","journal-title":"Decis. Anal."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"756","DOI":"10.1111\/risa.12399","article-title":"Quantifying Adversary Capabilities to Inform Defensive Resource Allocation","volume":"36","author":"Wang","year":"2016","journal-title":"Risk Anal."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"408","DOI":"10.1111\/risa.13399","article-title":"Defender-Attacker Games with Asymmetric Player Utilities","volume":"40","author":"Zhai","year":"2020","journal-title":"Risk Anal."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1304","DOI":"10.1111\/risa.13626","article-title":"Defensive Resource Allocation: The Roles of Forecast Information and Risk Control","volume":"41","author":"Dong","year":"2021","journal-title":"Risk Anal."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"742","DOI":"10.1111\/risa.12439","article-title":"Modeling Opponents in Adversarial Risk Analysis","volume":"36","author":"Rios","year":"2016","journal-title":"Risk Anal."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"841","DOI":"10.1198\/jasa.2009.0155","article-title":"Adversarial Risk Analysis","volume":"104","author":"Rios","year":"2009","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"1219","DOI":"10.1111\/j.1539-6924.2011.01701.x","article-title":"Adversarial Risk Analysis with Incomplete Information: A Level-k Approach","volume":"32","author":"Rothschild","year":"2012","journal-title":"Risk Anal."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"e1530","DOI":"10.1002\/wics.1530","article-title":"Adversarial risk analysis: An overview","volume":"14","author":"Banks","year":"2022","journal-title":"Wiley Interdiscip. Rev. Comput. Stat."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"607","DOI":"10.1111\/j.1539-6924.2007.00906.x","article-title":"Choosing What to Protect","volume":"27","author":"Bier","year":"2007","journal-title":"Risk Anal."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"563","DOI":"10.1111\/j.1467-9779.2007.00320.x","article-title":"Choosing what to protect: Strategic defensive allocation against an unknown attacker","volume":"9","author":"Bier","year":"2007","journal-title":"J. Public Econ. Theory"},{"key":"ref_54","first-page":"23","article-title":"Choosing What to Protect When Attacker Resources and Asset Valuations are Uncertain","volume":"24","author":"Hausken","year":"2014","journal-title":"Oper. Res. Decis."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"515","DOI":"10.1016\/j.cie.2017.06.032","article-title":"A robust approach to infrastructure security games","volume":"110","author":"Yolmeh","year":"2017","journal-title":"Comput. Ind. Eng."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"790","DOI":"10.1057\/jors.2011.49","article-title":"Modelling \u2018Contracts\u2019 between a Terrorist Group and a Government in a Sequential Game","volume":"63","author":"He","year":"2012","journal-title":"J. Oper. Res. Soc."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1007\/s10479-014-1722-3","article-title":"Modeling Costly Learning and Counter-learning in a Defender-attacker Game with Private Defender Information","volume":"236","author":"Xu","year":"2016","journal-title":"Ann. Oper. Res."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"976","DOI":"10.1287\/opre.1070.0434","article-title":"Balancing Terrorism and Natural Disasters: Defensive Strategy with Endogenous Attacker Effort","volume":"55","author":"Zhuang","year":"2007","journal-title":"Oper. Res."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"107355","DOI":"10.1016\/j.ress.2020.107355","article-title":"Technology Adoption for Airport Security: Modeling Public Disclosure and Secrecy in an Attacker-defender Game","volume":"207","author":"Hunt","year":"2021","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"102138","DOI":"10.1016\/j.cose.2020.102138","article-title":"Quantitative cyber-physical security analysis methodology for industrial control systems based on incomplete information Bayesian game","volume":"102","author":"Liu","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1109\/TCNS.2016.2584183","article-title":"Dynamic Games with Asymmetric Information and Resource Constrained Players with Applications to Security of Cyberphysical Systems","volume":"4","author":"Gupta","year":"2017","journal-title":"IEEE Trans. Control Netw. Syst."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"113322","DOI":"10.1016\/j.chaos.2023.113322","article-title":"Implications of false alarms in dynamic games on cyber-security","volume":"169","author":"Han","year":"2023","journal-title":"Chaos Solitons Fractals"},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"1500","DOI":"10.1002\/dac.3115","article-title":"Game theoretic modeling of security and trust relationship in cyberspace","volume":"29","author":"Njilla","year":"2016","journal-title":"Int. J. Commun. Syst."},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/s00245-022-09851-6","article-title":"A Reputation Game on Cyber-Security and Cyber-Risk Calibration","volume":"85","author":"Han","year":"2022","journal-title":"Appl. Math. Optim."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"461","DOI":"10.1016\/j.jaccpubpol.2003.09.001","article-title":"Sharing information on computer systems security: An economic analysis","volume":"22","author":"Gordon","year":"2003","journal-title":"J. Account. Public Policy"},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1287\/isre.1050.0053","article-title":"The Economic Incentives for Sharing Security Information","volume":"16","author":"Ghose","year":"2005","journal-title":"Inf. Syst. Res."},{"key":"ref_67","doi-asserted-by":"crossref","first-page":"639","DOI":"10.1016\/j.jaccpubpol.2007.10.001","article-title":"Information Sharing Among Firms and Cyber Attacks","volume":"26","author":"Hausken","year":"2007","journal-title":"J. Account. Public Policy"},{"key":"ref_68","first-page":"245","article-title":"A Strategic Analysis of Information Sharing Among Cyber Attackers","volume":"12","author":"Hausken","year":"2015","journal-title":"J. Inf. Syst. Technol. Manag."},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1142\/S0219198917500104","article-title":"Information Sharing Among Cyber Hackers in Successive Attacks","volume":"19","author":"Hausken","year":"2017","journal-title":"Int. Game Theory Rev."},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Hausken, K. (2017). Security Investment, Hacking, and Information Sharing between Firms and between Hackers. Games, 8.","DOI":"10.3390\/g8020023"},{"key":"ref_71","doi-asserted-by":"crossref","first-page":"1750027","DOI":"10.1142\/S021919891750027X","article-title":"Proactivity and Retroactivity of Firms and Information Sharing of Hackers","volume":"20","author":"Hausken","year":"2018","journal-title":"Int. Game Theory Rev."},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"215","DOI":"10.1111\/risa.12878","article-title":"Perspectives on Cybersecurity Information Sharing among Multiple Stakeholders using a Decision Theoretic Approach","volume":"38","author":"He","year":"2018","journal-title":"Risk Anal."},{"key":"ref_73","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1016\/j.ress.2011.12.015","article-title":"Data Survivability Vs. Security in Information Systems","volume":"100","author":"Levitin","year":"2012","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1016\/j.jcss.2016.08.005","article-title":"Establishing evolutionary game models for CYBer security information EXchange (CYBEX)","volume":"98","author":"Tosh","year":"2018","journal-title":"J. Comput. Syst. Sci."},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1007\/s10799-010-0066-1","article-title":"Information security in networked supply chains: Impact of network vulnerability and supply chain integration on incentives to invest","volume":"11","author":"Bandyopadhyay","year":"2010","journal-title":"Inf. Technol. Manag."},{"key":"ref_76","doi-asserted-by":"crossref","unstructured":"Daras, N.J., and Rassias, M.T. (2015). A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability. Computation, Cryptography, and Network Security, Springer International Publishing.","DOI":"10.1007\/978-3-319-18275-9"},{"key":"ref_77","doi-asserted-by":"crossref","first-page":"588","DOI":"10.1016\/j.ejor.2016.12.034","article-title":"Multifirm models of cybersecurity investment competition vs. cooperation and network vulnerability","volume":"260","author":"Nagurney","year":"2017","journal-title":"Eur. J. Oper. Res."},{"key":"ref_78","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1016\/j.ejor.2019.09.017","article-title":"Cybersecurity investments in the supply chain: Coordination and a strategic attacker","volume":"282","author":"Simon","year":"2020","journal-title":"Eur. J. Oper. Res."},{"key":"ref_79","doi-asserted-by":"crossref","first-page":"1216","DOI":"10.1080\/00207543.2020.1721591","article-title":"Cybersecurity investments in a two-echelon supply chain with third-party risk propagation","volume":"59","author":"Li","year":"2020","journal-title":"Int. J. Prod. Res."},{"key":"ref_80","unstructured":"Alpcan, T., and Basar, T. (2006, January 3\u20136). An intrusion detection game with limited observations. Proceedings of the 12th International Symposium on Dynamic Games and Applications, Sophia Antipolis, France."},{"key":"ref_81","doi-asserted-by":"crossref","first-page":"536","DOI":"10.1016\/j.jet.2016.09.009","article-title":"Network security and contagion","volume":"166","author":"Acemoglu","year":"2016","journal-title":"J. Econ. Theory"},{"key":"ref_82","doi-asserted-by":"crossref","first-page":"2195","DOI":"10.1111\/ecin.12565","article-title":"The Optimal Defense of Networks of Targets","volume":"56","author":"Kovenock","year":"2018","journal-title":"Econ. Inq."},{"key":"ref_83","doi-asserted-by":"crossref","unstructured":"Wang, G., Welburn, J.W., and Hausken, K. (2020). A Two-Period Game Theoretic Model of Zero-Day Attacks with Stockpiling. Games, 11.","DOI":"10.3390\/g11040064"},{"key":"ref_84","doi-asserted-by":"crossref","first-page":"1609","DOI":"10.1007\/s10796-020-10054-z","article-title":"Attack and Defense Strategies in Cyber War Involving Production and Stockpiling of Zero-Day Cyber Exploits","volume":"23","author":"Hausken","year":"2021","journal-title":"Inf. Syst. Front."},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Schramm, H., Alderson, D.L., Carlyle, W.M., and Dimitrov, N.B. (2012). A Game Theoretic Model of Strategic Conflict in Cyberspace, Naval Postgraduate School.","DOI":"10.21236\/ADA555943"},{"key":"ref_86","unstructured":"Schelling, T.C. (1960). The Strategy of Conflict, Harvard University Press."},{"key":"ref_87","unstructured":"Dresher, M. (1961). Games of Strategy: Theory and Applications, RAND Corporation."},{"key":"ref_88","unstructured":"Libicki, M.C. (2009). Cyberdeterrence and Cyberwar, Rand Corporation."},{"key":"ref_89","first-page":"18","article-title":"Nuclear lessons for cyber security?","volume":"5","author":"Nye","year":"2011","journal-title":"Strateg. Stud. Q."},{"key":"ref_90","first-page":"100","article-title":"World gone cyber MAD: How \u201cMutually Assured Debilitation\u201d is the best hope for cyber deterrence","volume":"5","author":"Crosston","year":"2011","journal-title":"Strateg. Stud. Q."},{"key":"ref_91","first-page":"773","article-title":"Cyber deterrence","volume":"26","author":"Jensen","year":"2012","journal-title":"Emory Int\u2019l L. Rev."},{"key":"ref_92","unstructured":"Clarke, R.A., and Knake, R.K. (2014). Cyber War, Tantor Media, Incorporated."},{"key":"ref_93","first-page":"60","article-title":"Deterring malicious behavior in cyberspace","volume":"9","author":"Jasper","year":"2015","journal-title":"Strateg. Stud. Q."},{"key":"ref_94","doi-asserted-by":"crossref","first-page":"2825","DOI":"10.1073\/pnas.1700442114","article-title":"Strategic aspects of cyberattack, attribution, and blame","volume":"114","author":"Edwards","year":"2017","journal-title":"Proc. Natl. Acad. Sci. USA"},{"key":"ref_95","doi-asserted-by":"crossref","first-page":"1155","DOI":"10.1017\/S0003055420000362","article-title":"Deterrence with Imperfect Attribution","volume":"114","author":"Baliga","year":"2020","journal-title":"Am. Political Sci. Rev."},{"key":"ref_96","doi-asserted-by":"crossref","first-page":"1399","DOI":"10.1016\/j.ejor.2022.07.021","article-title":"Cyber deterrence with imperfect attribution and unverifiable signaling","volume":"306","author":"Welburn","year":"2023","journal-title":"Eur. J. Oper. Res."},{"key":"ref_97","doi-asserted-by":"crossref","first-page":"46","DOI":"10.1109\/MCS.2014.2364710","article-title":"Game-theoretic methods for robustness, security, and resilience of cyberphysical control systems: Games-in-games principle for optimal cross-layer resilient control systems","volume":"35","author":"Zhu","year":"2015","journal-title":"IEEE Control Syst. Mag."},{"key":"ref_98","doi-asserted-by":"crossref","first-page":"2320","DOI":"10.1109\/TSG.2013.2270291","article-title":"Cyber-Physical Security: A Game Theory Model of Humans Interacting Over Control Systems","volume":"4","author":"Backhaus","year":"2013","journal-title":"IEEE Trans. Smart Grid"},{"key":"ref_99","doi-asserted-by":"crossref","first-page":"113599","DOI":"10.1016\/j.dss.2021.113599","article-title":"Bayesian Stackelberg games for cyber-security decision support","volume":"148","author":"Zhang","year":"2021","journal-title":"Decis. Support Syst."},{"key":"ref_100","doi-asserted-by":"crossref","first-page":"856","DOI":"10.1109\/TCST.2022.3207671","article-title":"A Robust Stackelberg Game for Cyber-Security Investment in Networked Control Systems","volume":"31","author":"Shukla","year":"2023","journal-title":"IEEE Trans. Control Syst. Technol."},{"key":"ref_101","doi-asserted-by":"crossref","first-page":"9017039","DOI":"10.1155\/2017\/9017039","article-title":"Stackelberg Interdependent Security Game in Distributed and Hierarchical Cyber-Physical Systems","volume":"2017","author":"Shen","year":"2017","journal-title":"Secur. Commun. Netw."},{"key":"ref_102","doi-asserted-by":"crossref","first-page":"30322","DOI":"10.1109\/ACCESS.2020.2973030","article-title":"Modeling an Attack-Mitigation Dynamic Game-Theoretic Scheme for Security Vulnerability Analysis in a Cyber-Physical Power System","volume":"8","author":"Gao","year":"2020","journal-title":"IEEE Access"},{"key":"ref_103","doi-asserted-by":"crossref","first-page":"178605","DOI":"10.1109\/ACCESS.2019.2958856","article-title":"Graphical Evolutionary Game Model of Virus-Based Intrusion to Power System for Long-Term Cyber-Security Risk Evaluation","volume":"7","author":"Li","year":"2019","journal-title":"IEEE Access"},{"key":"ref_104","doi-asserted-by":"crossref","first-page":"1683","DOI":"10.1109\/TNSM.2020.2995713","article-title":"Optimal Decision Making Approach for Cyber Security Defense Using Evolutionary Game","volume":"17","author":"Hu","year":"2020","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_105","doi-asserted-by":"crossref","first-page":"2371","DOI":"10.1109\/TIE.2019.2907451","article-title":"A Game-Theoretic Approach to Cross-Layer Security Decision-Making in Industrial Cyber-Physical Systems","volume":"67","author":"Huang","year":"2020","journal-title":"IEEE Trans. Ind. Electron."},{"key":"ref_106","doi-asserted-by":"crossref","first-page":"669","DOI":"10.1007\/s00245-016-9389-6","article-title":"Mean-Field-Game Model for Botnet Defense in Cyber-Security","volume":"74","author":"Kolokoltsov","year":"2016","journal-title":"Appl. Math. Optim."},{"key":"ref_107","doi-asserted-by":"crossref","first-page":"1550147717737908","DOI":"10.1177\/1550147717737908","article-title":"Cyber security based on mean field game model of the defender: Attacker strategies","volume":"13","author":"Miao","year":"2017","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_108","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1016\/j.automatica.2018.03.012","article-title":"A hybrid stochastic game for secure control of cyber-physical systems","volume":"93","author":"Miao","year":"2018","journal-title":"Automatica"},{"key":"ref_109","doi-asserted-by":"crossref","first-page":"1550147719831180","DOI":"10.1177\/1550147719831180","article-title":"Optimal defense strategy based on the mean field game model for cyber security","volume":"15","author":"Miao","year":"2019","journal-title":"Int. J. Distrib. Sens. Netw."},{"key":"ref_110","doi-asserted-by":"crossref","first-page":"929","DOI":"10.1007\/s10922-018-9449-0","article-title":"A Stochastic Game Model for Evaluating the Impacts of Security Attacks against Cyber-Physical Systems","volume":"26","author":"Orojloo","year":"2018","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_111","doi-asserted-by":"crossref","first-page":"819","DOI":"10.1007\/s12065-021-00684-w","article-title":"A generic scheme for cyber security in resource constraint network using incomplete information game","volume":"16","author":"Singh","year":"2023","journal-title":"Evol. Intell."},{"key":"ref_112","doi-asserted-by":"crossref","first-page":"5384","DOI":"10.1109\/TAC.2021.3116093","article-title":"Security Investment in Cyber-Physical Systems: Stochastic Games with Asymmetric Information and Resource-Constrained Players","volume":"67","author":"Xing","year":"2022","journal-title":"IEEE Trans. Autom. Control"},{"key":"ref_113","doi-asserted-by":"crossref","first-page":"3038586","DOI":"10.1155\/2019\/3038586","article-title":"Optimal Decision-Making Approach for Cyber Security Defense Using Game Theory and Intelligent Learning","volume":"2019","author":"Zhang","year":"2019","journal-title":"Secur. Commun. Netw."},{"key":"ref_114","doi-asserted-by":"crossref","unstructured":"Huo, Y., Dong, W., Qian, J., and Jing, T. (2017). Coalition Game-Based Secure and Effective Clustering Communication in Vehicular Cyber-Physical System (VCPS). Sensors, 17.","DOI":"10.3390\/s17030475"},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"6990","DOI":"10.1109\/TCOMM.2020.3010289","article-title":"A Game of Drones: Cyber-Physical Security of Time-Critical UAV Applications with Cumulative Prospect Theory Perceptions and Valuations","volume":"68","author":"Sanjab","year":"2020","journal-title":"IEEE Trans. Commun."},{"key":"ref_116","doi-asserted-by":"crossref","first-page":"429","DOI":"10.1109\/TETC.2018.2890476","article-title":"Cyber Security Framework for Vehicular Network Based on a Hierarchical Game","volume":"9","author":"Sedjelmaci","year":"2021","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"ref_117","doi-asserted-by":"crossref","unstructured":"Wu, Z.J., Dong, R.C., and Wang, P. (2022). Research on Game Theory of Air Traffic Management Cyber Physical System Security. Aerospace, 9.","DOI":"10.3390\/aerospace9080397"},{"key":"ref_118","doi-asserted-by":"crossref","first-page":"3571","DOI":"10.1109\/TITS.2022.3223337","article-title":"Research on Security Defense of Coupled Transportation and Cyber-Physical Power System Based on the Static Bayesian Game","volume":"24","author":"Yang","year":"2023","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_119","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1016\/j.cose.2006.10.005","article-title":"A video game for cyber security training and awareness","volume":"26","author":"Cone","year":"2007","journal-title":"Comput. Secur."},{"key":"ref_120","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1109\/TSE.2017.2782813","article-title":"The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game","volume":"45","author":"Frey","year":"2019","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_121","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1080\/09662839.2015.1112276","article-title":"War Games redux? Cyberthreats, US-Russian strategic stability, and new challenges for nuclear security and arms control","volume":"25","author":"Futter","year":"2016","journal-title":"Eur. Secur."},{"key":"ref_122","doi-asserted-by":"crossref","first-page":"101827","DOI":"10.1016\/j.cose.2020.101827","article-title":"Riskio: A Serious Game for Cyber Security Awareness and Education","volume":"95","author":"Harta","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_123","doi-asserted-by":"crossref","unstructured":"Jin, Z.W., Zhang, S.T., Hu, Y.Y., Zhang, Y.N., and Sun, C.Y. (2022). Security State Estimation for Cyber-Physical Systems against DoS Attacks via Reinforcement Learning and Game Theory. Actuators, 11.","DOI":"10.3390\/act11070192"},{"key":"ref_124","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.sysconle.2019.01.008","article-title":"Non-equilibrium dynamic games and cyber-physical security: A cognitive hierarchy approach","volume":"125","author":"Kanellopoulos","year":"2019","journal-title":"Syst. Control Lett."},{"key":"ref_125","doi-asserted-by":"crossref","unstructured":"Maqbool, Z., Aggarwal, P., Pammi, V.S.C., and Dutt, V. (2020). Cyber Security: Effects of Penalizing Defenders in Cyber-Security Games via Experimentation and Computational Modeling. Front. Psychol., 11.","DOI":"10.3389\/fpsyg.2020.00011"},{"key":"ref_126","first-page":"91","article-title":"Modelling serious games for enhancing end user cyber security awareness","volume":"15","author":"Nicho","year":"2020","journal-title":"Iadis-Int. J. Comput. Sci. Inf. Syst."},{"key":"ref_127","doi-asserted-by":"crossref","first-page":"524","DOI":"10.1016\/j.ins.2021.08.098","article-title":"SCIPS: A serious game using a guidance mechanic to scaffold effective training for cyber security","volume":"580","author":"Hasshu","year":"2021","journal-title":"Inf. Sci."},{"key":"ref_128","doi-asserted-by":"crossref","first-page":"54","DOI":"10.14429\/dsj.68.11402","article-title":"A Game Theoretic Software Test-bed for Cyber Security Analysis of Critical Infrastructure","volume":"68","author":"Ravishankar","year":"2018","journal-title":"Def. Sci. J."},{"key":"ref_129","doi-asserted-by":"crossref","first-page":"576","DOI":"10.1108\/ICS-05-2022-0087","article-title":"Cyber Suraksha: A card game for smartphone security awareness","volume":"31","author":"Shah","year":"2023","journal-title":"Inf. Comput. Secur."},{"key":"ref_130","doi-asserted-by":"crossref","first-page":"1300","DOI":"10.1080\/10494820.2022.2120015","article-title":"Building a self-evolving iMonsters board game for cyber-security education","volume":"32","author":"Tseng","year":"2022","journal-title":"Interact. Learn. Environ."},{"key":"ref_131","doi-asserted-by":"crossref","first-page":"102450","DOI":"10.1016\/j.cose.2021.102450","article-title":"Serious games as a tool to model attack and defense scenarios for cyber-security exercises","volume":"110","author":"Yamin","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_132","doi-asserted-by":"crossref","first-page":"179","DOI":"10.1016\/j.infsof.2017.12.002","article-title":"Design and preliminary evaluation of a cyber Security Requirements Education Game (SREG)","volume":"95","author":"Yasin","year":"2018","journal-title":"Inf. Softw. Technol."},{"key":"ref_133","doi-asserted-by":"crossref","unstructured":"Zeijlemaker, S., Rouwette, E., Cunico, G., Armenia, S., and von Kutzschenbach, M. (2022). Decision-Makers\u2019 Understanding of Cyber-Security\u2019s Systemic and Dynamic Complexity: Insights from a Board Game for Bank Managers. Systems, 10.","DOI":"10.3390\/systems10020049"},{"key":"ref_134","unstructured":"Simon, H.A. (1969). The Sciences of the Artificial, MIT Press."},{"key":"ref_135","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1016\/j.ress.2017.03.027","article-title":"Special Versus General Protection and Attack of Parallel and Series Components","volume":"165","author":"Hausken","year":"2017","journal-title":"Reliab. Eng. Syst. Saf."}],"container-title":["Games"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-4336\/15\/4\/28\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T15:36:26Z","timestamp":1760110586000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-4336\/15\/4\/28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,14]]},"references-count":135,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,8]]}},"alternative-id":["g15040028"],"URL":"https:\/\/doi.org\/10.3390\/g15040028","relation":{},"ISSN":["2073-4336"],"issn-type":[{"value":"2073-4336","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,14]]}}}