首页> 外文会议>European symposium on research in computer security >Should Cyber-Insurance Providers Invest in Software Security?
【24h】

Should Cyber-Insurance Providers Invest in Software Security?

机译:网络保险提供商是否应该投资软件安全?

获取原文

摘要

Insurance is based on the diversifiability of individual risks: if an insurance provider maintains a large portfolio of customers, the probability of an event involving a large portion of the customers is negligible. However, in the case of cyber-insurance, not all risks are diversi-fiable due to software monocultures. If a vulnerability is discovered in a widely used software product, it can be used to compromise a multitude of targets until it is eventually patched, leading to a catastrophic event for the insurance provider. To lower their exposure to non-diversifiable risks, insurance providers may try to influence the security of widely used software products in their customer population, for example, through vulnerability reward programs. We explore the proposal that insurance providers should take a proactive role in improving software security, and provide evidence that this approach is viable for a monopolistic provider. We develop a model which captures the supply and demand sides of insurance, provide computational complexity results on the provider's investment decisions, and propose different heuristic investment strategies. We demonstrate that investments can reduce non-diversifiable risks and can lead to a more profitable cyber-insurance market. Finally, we detail the relative merits of the different heuristic strategies with numerical results.
机译:保险是根据个人风险diversifiability:如果保险供应商维护客户的大型组合,涉及到客户的大部分事件的概率可以忽略不计。然而,在网络保险的情况下,并不是所有的风险都diversi-fiable由于软件单一种植。如果某个漏洞被广泛使用的软件产品发现,它可以被用来攻击目标众多,直到它最终被修补,导致对保险提供商灾难性事件。为了降低他们接触到不可分散风险,保险机构可能试图影响的广泛使用的软件产品的安全性在他们的客户群,例如通过漏洞奖励计划。我们探索保险机构应在提高软件安全方面发挥积极作用,并提供证据证明这种方法是可行的垄断供应商的建议。我们开发捕捉保险供需双方的模型,提供对供应商的投资决策计算复杂性,并提出了不同的启发式的投资策略。我们表明,投资可以减少不可分散的风险,并可能导致一个更有利可图的网络保险市场。最后,我们详细的数值结果不同启发式策略的相对优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号