期刊文献+

基于网络安全保险的信息系统安全投资激励机制 被引量:23

Cyber insurance as an incentive for information system security
原文传递
导出
摘要 网络互联环境下企业被黑客入侵的概率受其自身信息系统安全水平和整个网络安全水平的共同影响.通过研究企业非合作博弈下的个体最优选择的均衡结果和合作下的社会最优投资选择,发现非合作企业在信息系统安全投资时会忽略其他企业的边际外部成本或收益,这种负外部性特征会导致企业自我防御投资额低于社会最优投资水平,从而影响社会福利最大化的实现.为解决这种非合作下的安全投资不足问题,根据网络安全保险设计了一种信息系统安全投资激励机制.结果表明,适当的保险免赔额可以在一定程度上将这种负外部性内部化,进而改善了企业安全水平,并有效提高了社会福利. A firm's probability to incur loss (from being attacked) depends on both his security level and the network security level. We fully characterize equilibria of the noncooperative game, which give us the individually optimal security choices. And we also get the socially choices. After comparing these two equilibrium results, it is found that the nature of interdependent causes a negative externality that results in under-investment in self-defense relative to the socially efficient level by ignoring marginal external costs or benefits conferred on others. To solve the above mentioned problem, we design cyber insurance as an incentive for information system security investment. The key result is that limiting insurance coverage through deductibles can partially internalize this externality and thereby improve individual and social welfare.
出处 《系统工程理论与实践》 EI CSSCI CSCD 北大核心 2015年第4期1057-1062,共6页 Systems Engineering-Theory & Practice
基金 国家自然科学基金(71071033)
关键词 保险 信息系统安全 自我防御投资 激励 insurance information system security self-defense investment incentive
作者简介 顾建强(1979-),男,江苏泰州人,博士研究生,研究方向:信息系统安全投资策略及风险管理,E—mail:gujianqiang@126.com; 梅姝娥(1968-),女,江苏南通人,博士生导师,教授,研究方向:信息安全经济学,电子商务; 仲伟俊(1962-),男,江苏南通人,博士生导师,教授,研究方向:信息管理与信息系统.
  • 相关文献

参考文献14

  • 1Gao X, Zhong W J, Mei S E. A game-theory approach to configuration of detection software with decision[J]. Reliability Engineering and System Safety, 2013, 119: 35-43.
  • 2Cavusoglu H, Raghunathan S. Configuration of and interaction between information security technologies: The case of firewalls and intrusion detection systems[J]. Information Systems Research, 2009, 20(2): 198-217.
  • 3Amin S, Schwartz G A, Sastry S S. Security of interdependent and identical networked control systems[J]. Automatica, 2013, 49(1): 186-192.
  • 4Shetty N, Schwartz G, Walrand J. Can competitive insurers improve network security[C]//Trust and Trustworthy Computing, Berlin: Springer-Verlag, 2010: 308-322.
  • 5Kunreuther H, Heal G. Interdependent security[J]. Journal of Risk and Uncertainty, 2003, 26(2-3): 231-249.
  • 6Garcia A, Horowitz B. The potential for underinvestment in internet security: Implications for regulatory pol- icy[J]. Journal of Regulatory Economics, 2007, 31: 37-55.
  • 7Zhuang J, Bier V MI Gupta A. Subsidies in interdependent security with heterogeneous discount rates[J]. The Engineering Economist, 2007, 52(1): 1-19.
  • 8Zhuang J. Impacts of subsidized security on stability and total social costs of equilibrium solutions in an n-player game with errors[J]. The Engineering Economist, 2010, 55(2): 131-149.
  • 9Radosavac S, Kempf J, Kozat U. Using insurance to increase internet security[C]// Proceedings of NetEcon, Seattle: ACM, 2008: 43-48.
  • 10Lelarge M, Bolot J. Economic incentives to increase security in the internet: The case for insurance[C]// INFO- COM, Los Alamitos: IEEE, 2009: 1494-1502.

同被引文献156

引证文献23

二级引证文献90

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部