首页> 外文会议>Information Security Solutions Europe conference >Economic Incentives for Cybersecurity: Using Economics to Design Technologies Ready for Deployment
【24h】

Economic Incentives for Cybersecurity: Using Economics to Design Technologies Ready for Deployment

机译:网络安全的经济激励措施:使用经济学来设计可部署的技术

获取原文

摘要

Cybersecurity practice lags behind cyber technology achievements. Solutions designed to address many problems may and do exist but frequently cannot be broadly deployed due to economic constraints. Whereas security economics focuses on the cost/benefit analysis and supply/demand, we believe that more sophisticated theoretical approaches, such as economic modeling, rarely utilized, would derive greater societal benefits. Unfortunately, today technologists pursuing interesting and elegant solutions have little knowledge of the feasibility for broad deployment of their results and cannot anticipate the influences of other technologies, existing infrastructure, and technology evolution, nor bring the solutions lifecycle into the equation. Additionally, potentially viable solutions are not adopted because the risk perceptions by potential providers and users far outweighs the economic incentives to support introduction/adoption of new best practices and technologies that are not well enough defined. In some cases, there is no alignment with predominant and future business models as well as regulatory and policy requirements. This paper provides an overview of the economics of security, reviewing work that helped to define economic models for the Internet economy from the 1990s. We bring forward examples of potential use of theoretical economics in defining metrics for emerging technology areas, positioning infrastructure investment, and building real-time response capability as part of software development. These diverse examples help us understand the gaps in current research. Filling these gaps will be instrumental for defining viable economic incentives, economic policies, regulations as well as early-stage technology development approaches, that can speed up commercialization and deployment of new technologies in cybersecurity.
机译:网络安全实践落后于网络技术成就。设计用于解决许多问题的解决方案可能并且确实存在,但由于经济限制,经常无法广泛部署。安全经济学侧重于成本/收益分析和供应/需求,但我们认为,很少使用的更为复杂的理论方法(例如经济模型)会带来更大的社会效益。不幸的是,如今,追求有趣而优雅的解决方案的技术人员几乎不了解广泛部署其结果的可行性,并且无法预期其他技术,现有基础架构和技术发展的影响,也无法将解决方案的生命周期纳入方程式。此外,未采用可能可行的解决方案,因为潜在提供者和用户的风险感知远远超过了经济动机,无法支持引入/采用尚未充分定义的新最佳实践和技术。在某些情况下,无法与主要和未来的业务模型以及法规和政策要求保持一致。本文提供了安全性经济学的概述,回顾了有助于定义1990年代互联网经济模型的工作。我们提出了一些理论经济学的示例,这些示例可用于定义新兴技术领域的指标,定位基础架构投资以及建立实时响应能力,作为软件开发的一部分。这些不同的例子有助于我们理解当前研究的差距。填补这些空白将有助于定义可行的经济激励措施,经济政策,法规以及早期技术开发方法,从而加快网络安全中新技术的商业化和部署。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号