Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes

Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes
复制标题

灾难性网络风险聚合会在物联网时代蓬勃发展吗?

DOI:
10.1145/3446635
复制
发表时间:
2021
影响因子:
2.5
通讯作者:
Nag, Bodhibrata
Nag, Bodhibrata
中科院分区:
--
文献类型:
--
作者:
Pal, Ranjan;Huang, Ziyuan;Lototsky, Sergey;Yin, Xinlong;Liu, Mingyan;Crowcroft, Jon;Sastry, Nishanth;De, Swades;Nag, Bodhibrata

文献摘要

参考文献

被引文献

相似文献

网络IT和物联网驱动的服务组织之间的服务责任互连为DDoS、APT和勒索软件攻击等现代网络犯罪造成的级联服务中断创造了潜在渠道。众所周知,这些攻击会在地球仪的组织和关键基础设施中造成价值数十亿美元的连锁灾难性服务中断。网络保险是一种风险管理机制,在行业中越来越受欢迎,以在网络攻击后覆盖客户(组织)风险。然而,有一定的可能性,成功攻击的性质是如此之大,以至于组织客户的保险提供商无法覆盖其客户及其供应链中的后代对其自身造成的多方合计损失,从而需要通过其他网络保险公司重新保险。为此,首先值得研究的一个问题是,一个由一系列以盈利为目的的网络保险公司组成的生态系统,每个公司都能够为服务网络化的IT环境提供再保险服务,在经济上是可行的,以涵盖由于网络攻击所产生的总网络损失。我们的研究集中在一个经验上有趣的情况下,极端重尾网络,风险分布可能会以灾难性服务中断的形式呈现给现代互联网时代的网络保险公司,并可能成为近物联网时代处理的标准风险分布。令人惊讶的是,作为一个负面的结果,社会在这种灾难的情况下,我们通过博弈论分析证明,它可能不是经济激励兼容,即使在i.i.d.尽管存在足够大的市场容量来实现完全的网络风险分担,但我们的分析在理论上支持了流行的观点,即传播i.i.d.非灾难性的网络风险是集合网络风险管理者的有效做法,这是过去在理论和经验上建立的结果。在灾难性网络风险事件发生后,在苛刻的情况下未能实现有效的再保险市场,这强烈要求政府采取集中的监管行动/干预措施,通过再保险活动促进风险分担,以造福物联网时代的服务网络社会。
Service liability interconnections among networked IT and IoT-driven service organizations create potential channels for cascading service disruptions due to modern cybercrimes such as DDoS, APT, and ransomware attacks. These attacks are known to inflict cascading catastrophic service disruptions worth billions of dollars across organizations and critical infrastructure around the globe. Cyber-insurance is a risk management mechanism that is gaining increasing industry popularity to cover client (organization) risks after a cyber-attack. However, there is a certain likelihood that the nature of a successful attack is of such magnitude that an organizational client’s insurance provider is not able to cover the multi-party aggregate losses incurred upon itself by its clients and their descendants in the supply chain, thereby needing to re-insure itself via other cyber-insurance firms. To this end, one question worth investigating in the first place iswhether an ecosystem comprising a set of profit-minded cyber-insurance companies, each capable of providing re-insurance services for a service-networked IT environment, is economically feasible to cover the aggregate cyber-losses arising due to a cyber-attack.Our study focuses on an empirically interesting case ofextreme heavy tailed cyber-risk distributionsthat might be presenting themselves to cyber-insurance firms in the modern Internet age in the form of catastrophic service disruptions, and could be a possible standard risk distribution to deal with in the near IoT age. Surprisingly, as a negative result for society in the event of such catastrophes,we prove via a game-theoretic analysisthat itmay not be economically incentive compatible,even under i.i.d. statistical conditionsoncatastrophiccyber-risk distributions, for limited liability-taking risk-averse cyber-insurance companies to offer cyber re-insurance solutionsdespite the existence of large enough market capacity to achieve full cyber-risk sharing.However, our analysistheoretically endorsesthe popular opinion thatspreading i.i.d. cyber-risksthat arenot catastrophicis an effective practice for aggregate cyber-risk managers, a result established theoretically and empirically in the past. A failure to achieve a working re-insurance market in critically demanding situations after catastrophic cyber-risk events strongly calls for centralized government regulatory action/intervention to promote risk sharing through re-insurance activities for the benefit of service-networked societies in the IoT age.
物联网社会中可持续的灾难性网络风险管理
DOI: --
发表时间: 2020
期刊: Online World Conference on Soft Computing in Industrial Applications
影响因子: --
作者:
Ranjan Pal;Ziyuan Huang;Xinlong Yin;Mingyan Liu;S. Lototsky;Jon Crowcroft
通讯作者: Jon Crowcroft
DOI: --
发表时间: 2014
期刊:
影响因子: --
作者:
Parinaz Naghizadeh;M. Liu
通讯作者: M. Liu
Aegis 新型网络保险模式
DOI: --
发表时间: 2011
期刊: Decision and Game Theory for Security
影响因子: --
作者:
R. Pal;L. Golubchik;K. Psounis
通讯作者: K. Psounis
政府作为巨灾风险的再保险人?
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者:
Véronique Bruggeman;M. Faure;Karine Fiore
通讯作者: Karine Fiore
系统性网络风险和总体影响
DOI: --
发表时间: 2021
期刊: Risk Analysis
影响因子: 3.8
作者:
Jonathan W. Welburn;Aaron Strong
通讯作者: Aaron Strong