Attackers’ Motivation and Security Investment
Contributions to game theory and management, Tome 1 (2007), pp. 43-67

Voir la notice de l'article provenant de la source Math-Net.Ru

We model economic behavior of attackers when they are able to obtain complete information about the security characteristics of targets and when such information is unavailable. We find that when attackers are able to distinguish targets by their security characteristics and switch between multiple alternative targets, the effect of a given security measure is stronger. That is due to the fact that attackers rationally put more effort into attacking systems with low security levels. Ignoring that effect would result in underinvestment in security or misallocation of security resources. We also find that systems with better levels of protection have stronger incentives to reveal their security characteristics to attackers than poorly protected systems. Those results have important implications for security practices and policy issues.
Keywords: Economics of information systems, information system security, perceived security, investment evaluation, attacker behavior.
@article{CGTM_2007_1_a4,
     author = {Marco Cremonini and Dmitri Nizovtsev},
     title = {Attackers{\textquoteright} {Motivation} and {Security} {Investment}},
     journal = {Contributions to game theory and management},
     pages = {43--67},
     publisher = {mathdoc},
     volume = {1},
     year = {2007},
     language = {en},
     url = {http://geodesic.mathdoc.fr/item/CGTM_2007_1_a4/}
}
TY  - JOUR
AU  - Marco Cremonini
AU  - Dmitri Nizovtsev
TI  - Attackers’ Motivation and Security Investment
JO  - Contributions to game theory and management
PY  - 2007
SP  - 43
EP  - 67
VL  - 1
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CGTM_2007_1_a4/
LA  - en
ID  - CGTM_2007_1_a4
ER  - 
%0 Journal Article
%A Marco Cremonini
%A Dmitri Nizovtsev
%T Attackers’ Motivation and Security Investment
%J Contributions to game theory and management
%D 2007
%P 43-67
%V 1
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CGTM_2007_1_a4/
%G en
%F CGTM_2007_1_a4
Marco Cremonini; Dmitri Nizovtsev. Attackers’ Motivation and Security Investment. Contributions to game theory and management, Tome 1 (2007), pp. 43-67. http://geodesic.mathdoc.fr/item/CGTM_2007_1_a4/