Cyber-Insurance: Missing Market Driven by User Heterogeneity

Cyber-Insurance: Missing Market Driven by User Heterogeneity
复制标题

网络保险:用户异质性导致市场缺失

DOI:
--
复制
发表时间:
2010
期刊:
影响因子:
--
通讯作者:
J. Walrand
J. Walrand
中科院分区:
--
文献类型:
--
作者:
G. Schwartz;Nikhil Shetty;J. Walrand

文献摘要

被引文献

相似文献

在本文中,我们解释了为什么现有的网络保险合同的条件,他们的保费只对客户的一般特征(如员工人数,销售量),但不反映客户的安全实践。事实上,我们表明,即使一个竞争的保险公司可以监控(和执行)安全要求,为绝大多数的客户,与th只有一小部分的客户能够颠覆监控,没有均衡合同将包括安全要求。我们考虑任意风险厌恶的用户,其提高安全性的成本由任意凸函数给出。在我们的模型中,用户遭受损害(从被攻击)的概率取决于他自己的安全和网络安全:因此,安全是相互依存的。我们引入了两种用户类型(正常和恶意),并允许其中一种用户类型(恶意用户)能够破坏保险公司的监控,即使正常用户的安全级别对保险公司来说是完全可执行的(零成本)。这种信息不对称导致了逆向选择问题(即,恶意用户将购买保险,这导致更高的保险成本)。我们证明了无论恶意用户的比例有多小,指定使用r安全的均衡合同不存在。因此,我们证明,在一般情况下,网络保险市场承保合同的用户保费用户安全的失败。
In this paper, we explain why existing cyber-insurance contracts condition their premiums only on a client’s general features (suc h as the number of employees, sales volume) but do not reflect the client’s se curity practices. Indeed, we show that even if a competitive insurer can monitor (and enforce) security requirements for a vast majority of his clients, wi th only a minor fraction of the clients being able to subvert monitoring, no equilibrium contract would include security requirements. We consider arbitrary risk-averse users, whose costs of improving security are given by an arbitrary convex function. In our model, a user’s probability to incur damage (from being attacked) depends on both his own security and network security: thus, security is interdependent. We introduce two user types (normal and malicious), and allow one of the user types (malicious users) to be able to subvert insurer monitoring, even when security levels of normal users are perfectly enforceable (zero cost) for insurers. This asymmetric information causes adverse selection problem (i.e., malicious users will buy insuranc e, which leads to higher insurer costs). We prove that no matter how small the fraction of malicious users is, equilibrium contract that specifies use r security does not exist. Thus, we demonstrate, in a general setting, a failure of cyber-insurance market to underwrite contracts conditioning user premium on user security.