课题基金 / 基金详情

SaTC: CORE: Small: Collaborative: Information Disclosure and Security Policy Design: A Large-Scale Randomization Experiment in Trans-Pacific Region

SaTC: CORE: Small: Collaborative: Information Disclosure and Security Policy Design: A Large-Scale Randomization Experiment in Trans-Pacific Region
SaTC:核心:小型:协作:信息披露和安全政策设计:跨太平洋地区的大规模随机化实验
批准号:
1718360
负责人:
Shu He
金额:
$9.15万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2020-07-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
随着数据泄露和网络安全事件的日益突出,网络不安全正成为每个人和社会的严重问题。此类安全事件的部分原因是缺乏相关的政府政策,以及管理信息资产的组织的安全保护不足。调查人员将设计一个独立的跨太平洋网络安全评估机构,衡量和报告组织的安全弱点。拟议的机构旨在有效地激励各组织实现理想的网络安全水平。采用严谨设计的选择加入现场实验,对跨太平洋地区组织的绩效进行经验性评估,以了解它们将如何应对恶意网络犯罪的多样化安全性能报告,包括垃圾邮件、网络钓鱼和分布式拒绝服务(DDoS)攻击。作为数据分析的方法,研究人员将使用潜在有用的理论和经验模型:(I)允许内生实验的模型,(Ii)具有防御者和攻击者之间战略交互的静态和动态模型,以及(Iii)利用PI的综合安全评估度量的网络保险和再保险模型。PI将使用实验和观测数据来估计这些模型中与政策相关的参数。除了关于防御者的现有数据集之外,已收集并将用于分析攻击者数据的重要数据集,例如网络钓鱼活动、传出垃圾邮件和实时DDoS信息的数据。由于PI试图恢复政策的灵活异质影响,而网络安全数据通常表现出很大的异质性,因此它们引入了最近的计量经济学文献中开发的半参数识别和估计方法。这项工作从几个方面促进了关于随机化现场实验的文献:(I)确定由于外部影响的存在而导致的随机化现场实验的内生性问题;(Ii)在网络安全的背景下,重新设计先前的实验,并通过在攻击者身上使用新的数据集来控制内生性的经验策略;(Iii)恢复处理的完全异质效果,这与文献中通常采用的简单和受限的方法不同;(Iv)由于一些数据集是高频的(例如DDoS实时攻击),以制定处理大数据问题的估计方法。该项目的理论模型通过以下新颖的特征为网络安全文献做出了贡献:(I)使用随机分析在连续时间框架内的动态网络安全博弈;(Ii)具有再保险机会的网络保险模型,以及指定政府作为最终过度冒险者的角色,以及政府通过改变保费来控制组织的网络安全投资水平的方法。
英文摘要
With more prominent data breaches and cybersecurity incidents, cyber insecurity is becoming a serious problem for every individual and the society. Such security incidents are partially due to the lack of relevant governmental polices and the insufficient security protection by organizations managing information assets. The investigators will design an independent Trans-Pacific cybersecurity evaluation institution that measures and reports organizations' security weaknesses. The proposed institution aims at effectively motivating organizations to achieve a desirable level of cybersecurity. An opt-in field experiment with a rigorous design will be employed to empirically evaluate the performance of organizations in the Trans-Pacific region to see how they will respond to the diversified security performance reports of malicious cybercrimes, including spam, phishing, and distributed denial of service (DDoS) attacks. Based on the experimental results, the project will provide practical and credible suggestions to policy makers and companies improve their security preparedness.As methods of data analyses, the researchers will employ potentially useful theoretical and empirical models: (i) a model that allows endogenous experiments, (ii) static and dynamic models with strategic interaction between defenders and attackers, and (iii) a cyber-insurance and reinsurance model which utilizes the PIs' comprehensive security evaluation metric. The PIs will estimate the policy relevant parameters in these models using both experimental and observational data. In addition to the existing dataset on defenders, important data sets that have been collected and will be used in the analyses of the data for attackers, such as data for phishing activity, outgoing spam mails, and real time DDoS information. Since the PIs seek to recover flexible heterogeneous effects of policies, as cybersecurity data typically exhibit a great deal of heterogeneity, they introduce semi-parametric identification and estimation methods developed in the recent econometrics literature. This work contributes to the literature on randomized field experiments in several ways: (i) to identify the problem of endogeneity in randomized field experiments due to the existence of external impact; (ii) in the context of cybersecurity, to redesign a previous experiment and by introducing empirical strategies that control for endogeneity using novel datasets on the attackers; (iii) to recover fully heterogeneous effects of treatments, which departs from a simple and restricted approach commonly taken in the literature; (iv) as some of the datasets are of high frequency (e.g., DDoS real time attack), to develop estimation methods that deal with big data issues. Theoretical models of this project contribute to cybersecurity literature by following novel features: (i) a dynamic cybersecurity game in the continuous-time framework by using stochastic analysis; (ii) a cyber-insurance model with reinsurance opportunity, and specification of the role of governments as the ultimate excessive risk taker, and a method for governments to control organization's cybersecurity investment level by altering the premium.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
  • 批准号:
    82371765
  • 项目类别:
    面上项目
  • 资助金额:
    50万元
  • 批准年份:
    2023
  • 负责人:
    谭广云
  • 依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
  • 批准号:
    22303037
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2023
  • 负责人:
    鲁俊波
  • 依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    52万元
  • 批准年份:
    2022
  • 负责人:
    孙丙军
  • 依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
  • 批准号:
    --
  • 项目类别:
    青年科学基金项目
  • 资助金额:
    30万元
  • 批准年份:
    2022
  • 负责人:
    叶成林
  • 依托单位: