EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape
EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape
批准号:
1939006
负责人:
Mingyan Liu
金额:
$20.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2022-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
This project aims to tackle some of the most significant challenges facing the design and adoption of risk-informed cyber insurance policies; these challenges include cyber risk interdependence, correlated risk and value-at-risk, and a fast-changing threat landscape. The research has the potential to bring about a paradigm shift in the design of cyber insurance policies so that they are used as effective economic and incentive mechanisms consistent with cyber risk realities; in doing so it also introduces new ways of thinking about cybersecurity in a holistic, risk management context. Consequently, the research has a direct impact on the current practice by cyber insurance carriers and thus the potential to dramatically change the status quo. It has broader impacts on public policy and incentive mechanism design aimed at encouraging the adoption of better cybersecurity frameworks.The research agenda focuses on challenges including risk interdependence, correlated risk and value-at-risk, and a fast-changing threat landscape, and is organized into four thrust areas. The first is on risk-informed insurance policies, which is focused on establishing a solid theoretical foundation for a new family of cyber insurance policies by using contract theory and the modeling of dependent risks. The second is on the modeling of correlated risk and risk aggregation, aimed at quantifying the aggregated risk of a portfolio of insurance policies, by using the notion of conditional value-at-risk (CVaR) developed in the financial engineering field. The third is on the development of a set of stress test benchmarks, with the goal of standardizing how insurance policies should be evaluated in terms of their risk exposure. The fourth is on technology transition and adoption efforts, which includes the education of insurance practitioners, building partnerships and identifying early adopters of our methods as pilots. The research has the potential to bring about a paradigm shift in the design of cyber insurance policies so that they are used as effective economic and incentive mechanisms matched with cyber risk realities, and in introducing new ways of thinking about cybersecurity in a holistic, risk management context.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Will Catastrophic Cyber-Risk Aggregation Thrive in the IoT Age? A Cautionary Economics Tale for (Re-)Insurers and Likes
灾难性网络风险聚合会在物联网时代蓬勃发展吗?
DOI:
10.1145/3446635
发表时间:
2021
期刊:
ACM Transactions on Management Information Systems
影响因子:
2.5
作者:
[Pal, Ranjan, Huang, Ziyuan, Lototsky, Sergey, Yin, Xinlong, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth, De, Swades, Nag, Bodhibrata]
通讯作者:
Nag, Bodhibrata
Preference-Based Privacy Markets
基于偏好的隐私市场
DOI:
10.1109/access.2020.3014882
发表时间:
2020
期刊:
IEEE Access
影响因子:
3.9
作者:
[Pal, Ranjan, Crowcroft, Jon, Wang, Yixuan, Li, Yong, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Nag, Bodhibrata, Kumar, Abhishek, Hui, Pan]
通讯作者:
Hui, Pan
Aggregate Cyber-Risk Management in the IoT Age: Cautionary Statistics for (Re)Insurers and Likes
物联网时代的总体网络风险管理:(再)保险公司和类似机构的警示统计数据
DOI:
10.1109/jiot.2020.3039254
发表时间:
2021
期刊:
IEEE Internet of Things Journal
影响因子:
10.6
作者:
[Pal, Ranjan, Huang, Ziyuan, Yin, Xinlong, Lototsky, Sergey, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth]
通讯作者:
Sastry, Nishanth
Deterrence, Backup, or Insurance: A Game-Theoretic Analysis of Ransomware
威慑、备份或保险:勒索软件的博弈论分析
DOI:
--
发表时间:
2021
期刊:
The Annual Workshop on the Economics of Information Security (WEIS
影响因子:
--
作者:
[Yin, Tongxin, Sarabi, Armin, Liu, Mingyan]
通讯作者:
Liu, Mingyan
CPS:Small:Collaborative Research: Incentivizing Desirable User Behavior in a Class of CPS
-
批准号:1739517
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2017
-
负责人:Mingyan Liu
-
依托单位:
TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice
-
批准号:1616575
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2016
-
负责人:Mingyan Liu
-
依托单位:
CI-NEW: Collaborative Research: COVE-Computer Vision Exchange for Data, Annotations and Tools
-
批准号:1628987
-
项目类别:Standard Grant
-
资助金额:$34.3万
-
财政年份:2016
-
负责人:Mingyan Liu
-
依托单位:
TWC: Small: Understanding Network Level Malicious Activities: Classification, Community Detection and Inference of Security Interdependence
-
批准号:1422211
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2014
-
负责人:Mingyan Liu
-
依托单位:
NeTS: Small: Collaborative Research: Playing the Devil's Advocate: The Profit Perspective in Secondary Spectrum Markets
-
批准号:1217689
-
项目类别:Standard Grant
-
资助金额:$21.48万
-
财政年份:2012
-
负责人:Mingyan Liu
-
依托单位:
CAREER: Capacity-Driven Design of Large-Scale Wireless Sensor Networks
-
批准号:0238035
-
项目类别:Continuing Grant
-
资助金额:$42.19万
-
财政年份:2003
-
负责人:Mingyan Liu
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
基于isomorph theory研究尘埃等离子体物理量的微观动力学机制
-
批准号:12247163
-
项目类别:专项项目
-
资助金额:18.00万元
-
批准年份:2022
-
负责人:黄栋
-
依托单位:
Toward a general theory of intermittent aeolian and fluvial nonsuspended sediment transport
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2022
-
负责人:Thomas Pahtz
-
依托单位:
英文专著《FRACTIONAL INTEGRALS AND DERIVATIVES: Theory and Applications》的翻译
-
批准号:12126512
-
项目类别:数学天元基金项目
-
资助金额:12.0万元
-
批准年份:2021
-
负责人:李常品
-
依托单位:
基于Restriction-Centered Theory的自然语言模糊语义理论研究及应用
-
批准号:61671064
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2016
-
负责人:史树敏
-
依托单位: