Economics of Industrial Cyberespionage
Economics of Industrial Cyberespionage
批准号:
2377496
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2016
资助国家:
英国
项目状态:
已结题
起止时间:
2016 至 --
中文摘要
该项目属于EPSRC数字经济和全球不确定性研究领域。工业网络间谍是一种普遍现象,每年给全球经济造成高达6万亿美元的损失。它影响我们投资创新、存储数据和制定法律的方式,并最终影响社会福利。然而,经济学界对它的关注有限。我的研究为新兴的信息安全经济学跨学科领域做出了贡献,从经济学的角度来看待这一问题,并从三个不同的角度考虑了工业网络间谍活动。第一个项目研究了一场动态的研发竞赛,在这场竞赛中,竞争对手可以相互进行网络间谍活动。我们开发了一个框架,分析网络间谍活动对创新激励、公司收益和最终产品质量的影响。我们证明,工业间谍活动对竞争中的整体投资和公司的预期回报具有模糊的影响,在某些情况下甚至可能有利于创新最终产品的质量。第二个项目提供了新的经验证据,表明研究密集型行业特别容易受到信息泄露攻击。基于欧盟统计局汇总的企业创新和数字化活动数据,我们构建了一个定制的数据集,使我们能够实现稳健的统计推断,并研究信息泄露攻击率、研究强度和企业数据依赖之间的关系。这项研究使用多元分数回归分析来区分两个特定行业的关联:高科技制造业容易遭受有针对性的攻击,而知识密集型服务公司更有可能成为机会主义攻击的受害者。第三个项目旨在了解在智能攻击者在场的情况下高效的网络形成和最佳的防御资源分配。我们提出了一个两人动态框架,在这个框架中,防御者和攻击者在一个具有不同顶点价值的网络编队和防御博弈中竞争。这样的模型允许研究网络效率和安全性之间的权衡。与文献相反,我们发现,在大多数情况下,中央保护的星型网络并不能为防御方带来最大收益,即使是最安全的网络编队也是如此。此外,它还揭示了一种新的网络类型,这种网络通常出现在防守资源有限的博弈均衡中-最大核心网络。
英文摘要
This project falls within the EPSRC Digital Economy and Global Uncertainties research areas.Industrial cyberespionage is a widespread phenomenon that costs the global economy up to \$6 trillion annually. It influences how we invest in innovation, store data, and create laws, and ultimately the welfare of society. Yet, it has received limited attention from the economics community. My research contributes to the emerging interdisciplinary field of economics of information security, bringing an economic perspective to the matter and considering industrial cyberespionage from three different angles.The first project examines a dynamic R\&D race in which competitors can conduct cyberespionage against each other. We develop a framework that analyses the influence of cyberespionage on innovative incentives, companies' payoffs and the quality of the end product. We demonstrate that industrial espionage has an ambiguous influence on the overall investments exerted in the race and companies' expected payoffs and might even be beneficial for the quality of innovative end-products under certain circumstances.The second project provides new empirical evidence that research-intensive industries are particularly susceptible to information leakage attacks. Based on Eurostat aggregated data on enterprises' innovative and digital activity, we construct a tailored data set that allows us to achieve robust statistical inference and study the relationship between information leakage attack rate, research-intensity, and companies' data reliance. The study uses multivariate fractional regression analysis to distinguish two industry-specific associations: high-tech manufacturing industries are prone to experience targeted attacks, while knowledge-intensive service companies are more likely to fall victim to opportunistic attacks. The third project aims to understand efficient network formation and optimal defensive resource distribution in the presence of an intelligent attacker. We present a two-player dynamic framework in which the Defender and the Attacker compete in a network formation and defence game with heterogeneous vertices' values. Such a model allows for studying the trade-off between network efficiency and security. Contrary to the literature, we find that a centrally protected star network does not yield the maximum payoff for the defending side in most circumstances, even being the most secure network formation. Additionally, it reveals a new type of network that often arises in an equilibrium of the games with limited defensive resources---a maxi-core network.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金