课题基金 / 基金详情

EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape

EAGER: Theory and Practice of Risk-Informed Cyber Insurance Policies: Risk Dependency, Risk Aggregation, and Active Threat Landscape
EAGER:风险知情网络保险政策的理论与实践:风险依赖性、风险聚合和主动威胁格局
批准号:
1939006
负责人:
Mingyan Liu
金额:
$20.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2022-09-30

项目摘要

项目成果

Mingyan Liu的其他基金

相似基金

相关文献

中文摘要
翻译
该项目旨在解决设计和采用风险知情的网络保险保单所面临的一些最重大的挑战;这些挑战包括网络风险相互依存、相互关联的风险和风险价值以及快速变化的威胁格局。这项研究有可能带来网络保险保单设计的范式转变,使其被用作符合网络风险现实的有效经济和激励机制;在这样做的同时,它还引入了在整体风险管理背景下思考网络安全的新方法。因此,这项研究对网络保险公司目前的做法产生了直接影响,从而有可能极大地改变现状。它对旨在鼓励采用更好的网络安全框架的公共政策和激励机制设计产生了更广泛的影响。研究议程侧重于挑战,包括风险相互依存、相互关联的风险和风险价值以及快速变化的威胁格局,并分为四个主要领域。首先是关于风险知情保单,重点是利用契约理论和相依风险的建模为新的网络保单家族建立坚实的理论基础。第二个是关于相关风险和风险聚合的建模,目的是通过使用金融工程领域发展起来的条件风险价值(CVaR)的概念来量化保单组合的聚合风险。第三个是关于制定一套压力测试基准,目的是标准化如何根据保单的风险敞口评估保单。第四个是关于技术过渡和采用的努力,其中包括对保险从业者进行教育,建立合作伙伴关系,并确定我们的方法的早期采用者作为试点。这项研究有可能带来网络保险保单设计的范式转变,使它们被用作与网络风险现实相匹配的有效经济和激励机制,并在整体、风险管理的背景下引入关于网络安全的新思维方式。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
This project aims to tackle some of the most significant challenges facing the design and adoption of risk-informed cyber insurance policies; these challenges include cyber risk interdependence, correlated risk and value-at-risk, and a fast-changing threat landscape. The research has the potential to bring about a paradigm shift in the design of cyber insurance policies so that they are used as effective economic and incentive mechanisms consistent with cyber risk realities; in doing so it also introduces new ways of thinking about cybersecurity in a holistic, risk management context. Consequently, the research has a direct impact on the current practice by cyber insurance carriers and thus the potential to dramatically change the status quo. It has broader impacts on public policy and incentive mechanism design aimed at encouraging the adoption of better cybersecurity frameworks.The research agenda focuses on challenges including risk interdependence, correlated risk and value-at-risk, and a fast-changing threat landscape, and is organized into four thrust areas. The first is on risk-informed insurance policies, which is focused on establishing a solid theoretical foundation for a new family of cyber insurance policies by using contract theory and the modeling of dependent risks. The second is on the modeling of correlated risk and risk aggregation, aimed at quantifying the aggregated risk of a portfolio of insurance policies, by using the notion of conditional value-at-risk (CVaR) developed in the financial engineering field. The third is on the development of a set of stress test benchmarks, with the goal of standardizing how insurance policies should be evaluated in terms of their risk exposure. The fourth is on technology transition and adoption efforts, which includes the education of insurance practitioners, building partnerships and identifying early adopters of our methods as pilots. The research has the potential to bring about a paradigm shift in the design of cyber insurance policies so that they are used as effective economic and incentive mechanisms matched with cyber risk realities, and in introducing new ways of thinking about cybersecurity in a holistic, risk management context.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1145/3446635
发表时间: 2021
期刊: ACM Transactions on Management Information Systems
影响因子: 2.5
作者: [Pal, Ranjan, Huang, Ziyuan, Lototsky, Sergey, Yin, Xinlong, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth, De, Swades, Nag, Bodhibrata]
通讯作者: Nag, Bodhibrata
Preference-Based Privacy Markets
基于偏好的隐私市场
DOI: 10.1109/access.2020.3014882
发表时间: 2020
期刊: IEEE Access
影响因子: 3.9
作者: [Pal, Ranjan, Crowcroft, Jon, Wang, Yixuan, Li, Yong, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Nag, Bodhibrata, Kumar, Abhishek, Hui, Pan]
通讯作者: Hui, Pan
Aggregate Cyber-Risk Management in the IoT Age: Cautionary Statistics for (Re)Insurers and Likes
物联网时代的总体网络风险管理:(再)保险公司和类似机构的警示统计数据
DOI: 10.1109/jiot.2020.3039254
发表时间: 2021
期刊: IEEE Internet of Things Journal
影响因子: 10.6
作者: [Pal, Ranjan, Huang, Ziyuan, Yin, Xinlong, Lototsky, Sergey, De, Swades, Tarkoma, Sasu, Liu, Mingyan, Crowcroft, Jon, Sastry, Nishanth]
通讯作者: Sastry, Nishanth
Deterrence, Backup, or Insurance: A Game-Theoretic Analysis of Ransomware
威慑、备份或保险:勒索软件的博弈论分析
DOI: --
发表时间: 2021
期刊: The Annual Workshop on the Economics of Information Security (WEIS
影响因子: --
作者: [Yin, Tongxin, Sarabi, Armin, Liu, Mingyan]
通讯作者: Liu, Mingyan
CPS:Small:Collaborative Research: Incentivizing Desirable User Behavior in a Class of CPS
TTP: Small: Network-Level Security Posture Assessment and Predictive Analytics: From Theory to Practice
CI-NEW: Collaborative Research: COVE-Computer Vision Exchange for Data, Annotations and Tools
TWC: Small: Understanding Network Level Malicious Activities: Classification, Community Detection and Inference of Security Interdependence
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
基于isomorph theory研究尘埃等离子体物理量的微观动力学机制
  • 批准号:
    12247163
  • 项目类别:
    专项项目
  • 资助金额:
    18.00万元
  • 批准年份:
    2022
  • 负责人:
    黄栋
  • 依托单位:
Toward a general theory of intermittent aeolian and fluvial nonsuspended sediment transport
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    55万元
  • 批准年份:
    2022
  • 负责人:
    Thomas Pahtz
  • 依托单位:
英文专著《FRACTIONAL INTEGRALS AND DERIVATIVES: Theory and Applications》的翻译
  • 批准号:
    12126512
  • 项目类别:
    数学天元基金项目
  • 资助金额:
    12.0万元
  • 批准年份:
    2021
  • 负责人:
    李常品
  • 依托单位: