Three Layer Game Theoretic Decision Framework for Cyber-Investment and Cyber-Insurance

Three Layer Game Theoretic Decision Framework for Cyber-Investment and Cyber-Insurance
复制标题

网络投资和网络保险的三层博弈论决策框架

DOI:
--
复制
发表时间:
2017
期刊:
Decision and Game Theory for Security
影响因子:
--
通讯作者:
K. Kwiat
K. Kwiat
中科院分区:
--
文献类型:
--
作者:
Deepak K. Tosh;Iman Vakilinia;S. Shetty;S. Sengupta;Charles A. Kamhoua;Laurent L. Njilla;K. Kwiat

文献摘要

被引文献

相似文献

网络威胁形势已经变得非常复杂,因此,孤立地尝试理解、检测和解决网络安全问题在做出时间受限的决策时是不可行的。引入网络威胁信息(CTI)共享有可能在一定程度上处理这个问题,其中收集有关安全事件的知识,在组织之间交换,以获得有关威胁行为者和漏洞的有用信息。虽然共享安全信息可以让组织做出明智的决策,但它可能无法完全消除风险。因此,组织也倾向于考虑将风险转移给保险公司的网络保险。此外,在网络环境中,对手可以利用信息共享成功地突破参与组织。在本文中,我们考虑这些球员,即组织,对手,和保险,模型的三层游戏,球员发挥顺序,以找出他们的最佳策略。组织在参与CTI共享和网络保险时确定其最佳自卫投资。对手寻找一个最佳的攻击率,而保险公司的目标是通过提供适当的覆盖范围,以最大限度地提高其利润的组织。利用逆向归纳法,我们进行子博弈完美均衡分析,以找到参与者的最佳策略。我们观察到,当不考虑网络保险,攻击者更喜欢增加其攻击率。这促使组织考虑网络保险选项,以转移其关键资产上的风险。
Cyber-threat landscape has become highly complex, due to which isolated attempts to understand, detect, and resolve cybersecurity issues are not feasible in making a time constrained decisions. Introduction of cyber-threat information (CTI) sharing has potential to handle this issue to some extent, where knowledge about security incidents is gathered, exchanged across organizations for deriving useful information regarding the threat actors and vulnerabilities. Although, sharing security information could allow organizations to make informed decision, it may not completely eliminate the risks. Therefore, organizations are also inclined toward considering cyber-insurance for transferring risks to the insurers. Also, in networked environment, adversaries may exploit the information sharing to successfully breach the participating organizations. In this paper, we consider these players, i.e. organizations, adversary, and insure, to model a three layer game, where players play sequentially to find out their optimal strategies. Organizations determine their optimal self-defense investment to make while participating in CTI sharing and cyber-insurance. The adversary looks for an optimal attack rate while the insurer targets to maximize its profit by offering suitable coverage level to the organizations. Using backward induction approach, we conduct subgame perfect equilibrium analysis to find optimal strategies for the involved players. We observe that when cyber-insurance is not considered, attacker prefers to increase its rate of attack. This motivates the organizations to consider cyber-insurance option for transferring the risks on their critical assets.