{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,11]],"date-time":"2025-11-11T15:49:03Z","timestamp":1762876143818,"version":"build-2065373602"},"reference-count":53,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2020,2,1]],"date-time":"2020-02-01T00:00:00Z","timestamp":1580515200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Key Research and Development Project","award":["2016YFB0801001"],"award-info":[{"award-number":["2016YFB0801001"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1836203"],"award-info":[{"award-number":["U1836203"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004739","name":"Youth Innovation Promotion Association CAS","doi-asserted-by":"publisher","award":["2019160"],"award-info":[{"award-number":["2019160"]}],"id":[{"id":"10.13039\/501100004739","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With limited computing resources and a lack of physical lines of defense, the Internet of Things (IoT) has become a focus of cyberattacks. In recent years, outbreak propagation attacks against the IoT have occurred frequently, and these attacks are often strategical. In order to detect the outbreak propagation as soon as possible, t embedded Intrusion Detection Systems (IDSs) are widely deployed in the IoT. This paper tackles the problem of outbreak detection in adversarial environment in the IoT. A dynamic scheduling strategy based on specific IDSs monitoring of IoT devices is proposed to avoid strategic attacks. Firstly, we formulate the interaction between the defender and attacker as a Stackelberg game in which the defender first chooses a set of device nodes to activate, and then the attacker selects one seed (one device node) to spread the worms. This yields an extremely complex bilevel optimization problem. Our approach is to build a modified Column Generation framework for computing the optimal strategy effectively. The optimal response of the defender\u2019s problem is expressed as mixed-integer linear programming (MILPs). It is proved that the solution of the defender\u2019s optimal response is a NP-hard problem. Moreover, the optimal response of defenders is improved by an approximate algorithm--a greedy algorithm. Finally, the proposed scheme is tested on some randomly generated instances. The experimental results show that the scheme is effective for monitoring optimal scheduling.<\/jats:p>","DOI":"10.3390\/s20030804","type":"journal-article","created":{"date-parts":[[2020,2,5]],"date-time":"2020-02-05T03:18:48Z","timestamp":1580872728000},"page":"804","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["A Stackelberg Security Game for Adversarial Outbreak Detection in the Internet of Things"],"prefix":"10.3390","volume":"20","author":[{"given":"Lili","family":"Chen","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, Xidian University, Xi\u2019an 710071, China"},{"name":"Institute of Information Engineering Chinese Academy of Sciences, Beijing 100093, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3399-5281","authenticated-orcid":false,"given":"Zhen","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences, Beijing 100093, China"},{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fenghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, Xidian University, Xi\u2019an 710071, China"},{"name":"Institute of Information Engineering Chinese Academy of Sciences, Beijing 100093, China"},{"name":"School of Cybersecurity, University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yunchuan","family":"Guo","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences, Beijing 100093, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kui","family":"Geng","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering Chinese Academy of Sciences, Beijing 100093, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,2,1]]},"reference":[{"key":"ref_1","unstructured":"Li, S., Xu, L., and Zhao, S. (2015). The Internet of Things: A Survey, Kluwer Academic Publishers."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1016\/j.jnca.2017.04.002","article-title":"Internet of things Security: A Survey","volume":"88","author":"Alaba","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Wang, T., Wu, Q., Wen, S., Cai, Y., Tian, H., Chen, Y., and Wang, B. (2017). Propagation Modeling and Defending of a Mobile Sensor Worm in Wireless Sensor and Actuator Networks. Sensors, 17.","DOI":"10.3390\/s17010139"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"DDoS in the IoT. Mirai and Other Botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"IEEE Comput."},{"key":"ref_5","unstructured":"(2020, January 31). Kaspersky. Available online: https:\/\/www.kaspersky.com\/blog\/attack-on-dyn-explained\/13325\/."},{"key":"ref_6","unstructured":"(2020, January 31). Csoonline. Available online: https:\/\/www.csoonline.com\/article\/3227906\/what-is-wannacry-ransomware-how-does-it-infect-and-who-was-responsible.html."},{"key":"ref_7","unstructured":"(2020, January 31). ZDNet. Available online: https:\/\/www.zdnet.com\/article\/iot-security-warning-cyber-attacks-on-medical-devices-could-put-patients-at-risk\/."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1016\/j.jnca.2017.02.009","article-title":"A survey of intrusion detection in Internet of Things","volume":"84","author":"Zarpelao","year":"2017","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_9","first-page":"138","article-title":"A survey on Intrusion Detection Systems and Honeypot based proactive security mechanisms in VANETs and VANET Cloud","volume":"12","author":"Sharma","year":"2018","journal-title":"Veh. Commun."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Leskovec, J., Krause, A., Guestrin, C., Faloutsos, C., Faloutsos, C., VanBriesen, J., and Glance, N. (2007, January 12\u201315). Cost-effective outbreak detection in networks. Proceedings of the 13th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Jose, CA, USA.","DOI":"10.1145\/1281192.1281239"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/MC.2009.265","article-title":"Optimizing Sensing: From Water to the Web","volume":"42","author":"Krause","year":"2009","journal-title":"IEEE Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"2390","DOI":"10.1109\/TAC.2011.2164010","article-title":"Simultaneous optimization of sensor placements and balanced schedules","volume":"56","author":"Krause","year":"2011","journal-title":"IEEE Trans. Automat. Contr."},{"key":"ref_13","first-page":"1","article-title":"Sensor placement for fault location identification in water networks: A minimum test cover approach","volume":"72","author":"Sela","year":"2016","journal-title":"Automatica"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"04018031","DOI":"10.1061\/(ASCE)WR.1943-5452.0000953","article-title":"Using mechanical reliability in multiobjective optimal meter placement for pipe burst detection","volume":"144","author":"Jung","year":"2018","journal-title":"J. Water Resour. Plan. Manag."},{"key":"ref_15","unstructured":"Shakarian, P., Lei, H., and Lindelauf, R. (2014, January 5\u20139). Power grid defense against malicious cascading failure. Proceedings of the 2014 International Conference on Autonomous Agents and Multi-Agent Systems, Paris, France."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"45","DOI":"10.1109\/MCE.2018.2851723","article-title":"Fair Resource Allocation in an Intrusion-Detection System for Edge Computing: Ensuring the Security of Internet of Things Devices","volume":"7","author":"Lin","year":"2018","journal-title":"IEEE Consum. Electron. Mag."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"2840","DOI":"10.1109\/ACCESS.2016.2575863","article-title":"Security enhancement for IoT communications exposed to eavesdroppers with uncertain locations","volume":"4","author":"Xu","year":"2016","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Veerappan, C.S., Keong, P.L.K., Tang, Z., and Tan, F. (2018, January 5\u20138). Taxonomy on malware evasion countermeasures techniques. Proceedings of the IEEE World Forum on Internet of Things, Singapore.","DOI":"10.1109\/WF-IoT.2018.8355202"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Hu, H., Wang, M., Ouyang, M., and Hu, G. (2019). Toward Network Worm Victims Identification Based on Cascading Motif Discovery. Electronics, 9.","DOI":"10.3390\/electronics8020183"},{"key":"ref_20","unstructured":"Bethencourt, J., Franklin, J., and Vernon, M.K. (August, January 31). Mapping Internet Sensors with Probe Response Attacks. Proceedings of the USENIX Security Symposium, Baltimore, MD, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Hu, F. (2016). Security and privacy in Internet of things (IoTs): Models, Algorithms, and Implementations, CRC Press.","DOI":"10.1201\/b19516"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"304","DOI":"10.1016\/j.jocs.2017.10.014","article-title":"Early detection of dynamic harmful cascades in large-scale networks","volume":"28","author":"Zhou","year":"2018","journal-title":"J. Comput. Sci-Neth."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"3745619:1","DOI":"10.1155\/2019\/3745619","article-title":"Modelling the Spread of Botnet Malware in IoT-Based Wireless Sensor Networks","volume":"2019","author":"Acarali","year":"2019","journal-title":"Secur. Commun. Netw."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Sedjelmaci, H., Senouci, S.M., and Al-Bahri, M. (2016, January 22\u201327). A lightweight anomaly detection technique for low-resource IoT devices: A game-theoretic methodology. Proceedings of the IEEE International Conference on Communications, Kuala Lumpur, Malaysia.","DOI":"10.1109\/ICC.2016.7510811"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Liu, B., Xu, H., and Zhou, X. (2018). Stackelberg Dynamic Game-Based Resource Allocation in Threat Defense for Internet of Things. Sensors, 18.","DOI":"10.3390\/s18114074"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Sohail, M., Khan, S., Ahmad, R., Singh, D., and Lloret, J. (2019). Game Theoretic Solution for Power Management in IoT-Based Wireless Sensor Networks. Sensors, 19.","DOI":"10.3390\/s19183835"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1989734.1989736","article-title":"Submodularity and its Applications in Optimized Information Gathering","volume":"2","author":"Krause","year":"2011","journal-title":"ACM TIST"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Huang, C.T., Sakib, M.N., Njilla, L., and Kamhoua, C. (2019, January 18\u201321). A Game Theoretic Approach for Making IoT Device Connectivity Decisions During Malware Outbreak. Proceedings of the International Conference on Computing, Networking and Communications, Honolulu, HI, USA.","DOI":"10.1109\/ICCNC.2019.8685493"},{"key":"ref_29","unstructured":"Robert, C., and George, C. (2020, January 31). Monte Carlo Statistical Methods. Available online: https:\/\/books.google.com.hk\/books?hl=en&lr=&id=lrvfBwAAQBAJ&oi=fnd&pg=PR17&dq=Monte+Carlo+statistical+methods&ots=GNEp5duzJ5&sig=Oe3pCPujDaKSK25qQ4eoT_OrKDU&redir_esc=y&hl=zh-CN&sourceid=cndr#v=onepage&q=Monte%20Carlo%20statistical%20methods&f=false."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"3496","DOI":"10.1109\/COMST.2018.2844742","article-title":"A critical review of practices and challenges in intrusion detection systems for IoT: Toward universal and resilient systems","volume":"20","author":"Benkhelifa","year":"2018","journal-title":"IEEE Commun. Suvr. Tut."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Sforzin, A., M\u00e1rmol, F.G., Conti, M., and Bohli, J.M. (2016, January 18\u201321). RPiDS: Raspberry Pi IDS\u2014A Fruitful Intrusion Detection System for IoT. Proceedings of the IEEE Conferences on Ubiquitous Intelligence & Computing, Advanced and Trusted Computing, Scalable Computing and Communications, Cloud and Big Data Computing, Internet of People, and Smart World Congress, Toulouse, France.","DOI":"10.1109\/UIC-ATC-ScalCom-CBDCom-IoP-SmartWorld.2016.0080"},{"key":"ref_32","unstructured":"Peng, Y., Yang, J., Wu, C., Guo, C., Hu, C., and Li, Z. (2017, January 12\u201314). deTector: A Topology-aware Monitoring System for Data Center Networks. Proceedings of the USENIX Annual Technical Conference, Santa Clara, CA, USA."},{"key":"ref_33","first-page":"881","article-title":"On early detection of strong infections in complex networks","volume":"47","author":"Yu","year":"2014","journal-title":"J. Phys. A-Math. Thero."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Zhang, H., Alim, M.A., Thai, M.T., and Nguyen, H.T. (2015, January 8\u201312). Monitor placement to timely detect misinformation in Online Social Networks. Proceedings of the IEEE International Conference on Communications, London, UK.","DOI":"10.1109\/ICC.2015.7248478"},{"key":"ref_35","unstructured":"Krause, A., McMahan, B., Guestrin, C., and Gupta, A. (2007, January 3\u20136). Selecting Observations against Adversarial Objectives. Proceedings of the Advances in Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1109\/MCOM.2017.1600568CM","article-title":"Game theoretic mechanisms for resource management in massive wireless IoT systems","volume":"55","author":"Semasinghe","year":"2017","journal-title":"IEEE Commun. Mag."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3139293","article-title":"Pareto optimal security resource allocation for Internet of Things","volume":"20","author":"Rullo","year":"2017","journal-title":"TOPS"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Altman, E., Avrachenkov, K., and Garnaev, A. (2009, January 13\u201315). Jamming in wireless networks: The case of several jammers. Proceedings of the 2009 International Conference on Game Theory for Networks, Istanbul, Turkey.","DOI":"10.1109\/GAMENETS.2009.5137448"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Namvar, N., Saad, W., Bahadori, N., and Kelley, B. (2016, January 4\u20138). Jamming in the Internet of Things: A Game-Theoretic Perspective. Proceedings of the IEEE Global Communications Conference, Washington, DC, USA.","DOI":"10.1109\/GLOCOM.2016.7841922"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Zhu, Q., Bushnell, L., and Ba\u015far, T. (2012, January 10\u201313). Game-theoretic analysis of node capture and cloning attack with multiple attackers in wireless sensor networks. Proceedings of the 51th IEEE Conference on Decision and Control, Maui, HI, USA.","DOI":"10.1109\/CDC.2012.6426481"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"1573","DOI":"10.1109\/TWC.2008.080726","article-title":"Pareto optimal resource management for wireless mesh networks with QoS assurance: joint node clustering and subcarrier allocation","volume":"8","author":"Cheng","year":"2009","journal-title":"IEEE T. Wirel. Commun."},{"key":"ref_42","unstructured":"Tsai, J., Nguyen, T.H., and Tambe, M. (2012, January 22\u201326). Security Games for Controlling Contagion. Proceedings of the 26th AAAI Conference on Artificial Intelligence, Toronto, ON, Canada."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Yin, Y., An, B., and Jain, M. (2014, January 27\u201331). Game-theoretic resource allocation for protecting large public events. Proceedings of the 28th AAAI Conference on Artificial Intelligence, Quebec, QC, Canada.","DOI":"10.1609\/aaai.v28i1.8794"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Wang, Z., Yin, Y., and An, B. (2016, January 12\u201317). Computing Optimal Monitoring Strategy for Detecting Terrorist Plots. Proceedings of the of the 30th AAAI Conference on Artificial Intelligence, Phoenix, AZ, USA.","DOI":"10.1609\/aaai.v30i1.10028"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Jain, M., Kardes, E., Kiekintveld, C., Ord\u00f3nez, F., and Tambe, M. (2010, January 11\u201315). Security Games with Arbitrary Schedules: A Branch and Price Approach. Proceedings of the 24th AAAI Conference on Artificial Intelligence, Atlanta, GA, USA.","DOI":"10.1609\/aaai.v24i1.7611"},{"key":"ref_46","unstructured":"Jain, M., Kardes, E., Kiekintveld, C., Ord\u00f3nez, F., and Tambe, M. (2015, January 25\u201330). Security games with protection externalities. Proceedings of the 29th AAAI Conference on Artificial Intelligence, Austin, TX, USA."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1016\/j.cor.2018.12.007","article-title":"A branch and price algorithm for EOS constellation imaging and downloading integrated scheduling problem","volume":"104","author":"Hu","year":"2019","journal-title":"Comput & OR"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Rullo, A., Serra, E., Bertino, E., and Lobo, J. (2017, January 11\u201315). Shortfall-based optimal placement of security resources for mobile IoT scenarios. Proceedings of the European Symposium on Research in Computer Security, Oslo, Norway.","DOI":"10.1007\/978-3-319-66399-9_23"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2699907","article-title":"Pareto-Optima Adversarial Defense of Enterprise Systems","volume":"17","author":"Serra","year":"2015","journal-title":"ACM Tans. Inf. Syst. Secur."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/BF01588971","article-title":"An analysis of approximations for maximizing submodular set functions\u2014I","volume":"14","author":"Nemhauser","year":"1978","journal-title":"Math. Program."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1109\/TDSC.2013.49","article-title":"Modeling and analysis on the propagation dynamics of modern email malware","volume":"11","author":"Wen","year":"2014","journal-title":"IEEE Trans. Dependable. Secure. Comput."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"509","DOI":"10.1126\/science.286.5439.509","article-title":"Emergence of scaling in random networks","volume":"286","author":"Albert","year":"1999","journal-title":"Science"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Tsai, J., Yin, Z., Kwak, J.Y., Kempe, D., Kiehintveld, C., and Tambe, M. (2010, January 11\u201315). Urban Security: Game-Theoretic Resource Allocation in Networked Domains. Proceedings of the 24th AAAI Conference on Artificial Intelligence, Atlanta, GA, USA.","DOI":"10.1609\/aaai.v24i1.7612"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/3\/804\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T08:53:50Z","timestamp":1760172830000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/3\/804"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,2,1]]},"references-count":53,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2020,2]]}},"alternative-id":["s20030804"],"URL":"https:\/\/doi.org\/10.3390\/s20030804","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2020,2,1]]}}}