Aegis A Novel Cyber-Insurance Model

Aegis A Novel Cyber-Insurance Model
复制标题

Aegis 新型网络保险模式

DOI:
--
复制
发表时间:
2011
期刊:
Decision and Game Theory for Security
影响因子:
--
通讯作者:
K. Psounis
K. Psounis
中科院分区:
--
文献类型:
--
作者:
R. Pal;L. Golubchik;K. Psounis

文献摘要

被引文献

相似文献

最近关于互联网风险管理的工作提出了网络保险的想法,以消除由于安全威胁而造成的风险,这些风险无法通过传统手段(如使用防病毒和防病毒软件)来解决。实际上,互联网用户面临由于安全攻击的风险以及由于非安全相关故障(例如,硬件崩溃、缓冲区溢出等形式的可靠性故障)。这些风险类型通常是无法区分的一个天真的用户。然而,网络保险机构很可能只为安全攻击带来的风险提供保险。在这种情况下,对于互联网用户来说,选择正确类型的网络保险合同作为传统的最优合同,即,合同的安全攻击,可能会证明是次优为自己。 在本文中,我们解决的问题,分析网络保险解决方案时,用户面临的风险,由于这两个,安全以及非安全相关的故障。我们提出了Aegis,一个简单而新颖的网络保险模型,在该模型中,用户接受自己的损失恢复的一小部分(严格为正),并将损失恢复的其余部分转移到网络保险机构。我们的数学表明,只有在购买网络保险是强制性的条件下,给予选择,风险厌恶的互联网用户会更喜欢神盾合同传统的网络保险合同,在所有的保费类型。这一结果坚定地证明,当向用户提供Aegis合同时,传统的网络保险市场不存在。我们还得到一个有趣的反直觉的结果有关的宙斯盾框架:我们表明,增加(减少)的保费的宙斯盾合同可能并不总是导致减少(增加)的用户需求。在这个过程中,我们还陈述了后一种趋势及其匡威趋势出现的条件。我们的工作提出了一种新的网络保险模式,互联网安全,扩展了所有以前的相关模型,占非保险风险的额外维度。Aegis还鼓励互联网用户承担更多的个人责任来保护他们的系统。
Recent works on Internet risk management have proposed the idea of cyber-insurance to eliminate risks due to security threats, which cannot be tackled through traditional means such as by using antivirus and antivirus softwares. In reality, an Internet user faces risks due to security attacks as well as risks due to non-security related failures (e.g., reliability faults in the form of hardware crash, buffer overflow, etc.). These risk types are often indistinguishable by a naive user. However, a cyber-insurance agency would most likely insure risks only due to security attacks. In this case, it becomes a challenge for an Internet user to choose the right type of cyber-insurance contract as traditional optimal contracts, i.e., contracts for security attacks only, might prove to be sub-optimal for himself. In this paper, we address the problem of analyzing cyber-insurance solutions when a user faces risks due to both, security as well as non-security related failures. We propose Aegis, a simple and novel cyber-insurance model in which the user accepts a fraction (strictly positive) of loss recovery on himself and transfers rest of the loss recovery on the cyber-insurance agency. We mathematically show that only under conditions when buying cyber-insurance is mandatory, given an option, risk-averse Internet users would prefer Aegis contracts to traditional cyber-insurance contracts, under all premium types. This result firmly establishes the non-existence of traditional cyber-insurance markets when Aegis contracts are offered to users. We also derive an interesting counterintuitive result related to the Aegis framework: we show that an increase(decrease) in the premium of an Aegis contract may not always lead to decrease(increase) in its user demand. In the process, we also state the conditions under which the latter trend and its converse emerge. Our work proposes a new model of cyber-insurance for Internet security that extends all previous related models by accounting for the extra dimension of non-insurable risks. Aegis also incentivizes Internet users to take up more personal responsibility for protecting their systems.