首页> 外文期刊>Information systems frontiers >Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance
【24h】

Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance

机译:使用Logit和Probit模型进行网络保险的网络风险评估和缓解(CRAM)框架

获取原文
获取原文并翻译 | 示例
           

摘要

Malicious external attackers commonly use cyber threats (such as virus attacks, denial-of-service (DoS) attacks, financial fraud, system penetration, and theft of proprietary information), while internal attackers resort to unauthorized access to compromise the confidentiality, integrity, and availability (CIA) of the data of individuals, organizations, and nations. This results in an opportunity cost, a loss of market capitalization, and a loss of brand equity for organizations. Organizations and nations spend a substantial portion of their information technology (IT) budgets on IT security (such as perimeter and core security technologies). Yet, security breaches are common. In this paper, we propose a cyber-risk assessment and mitigation (CRAM) framework to (i) estimate the probability of an attack using generalized linear models (GLM), namely logit and probit, and validate the same using Computer Security Institute-Federal Bureau of Investigation (CSI-FBI) time series data, (ii) predict security technology required to reduce the probability of attack to a given level in the next year, (iii) use gamma and exponential distribution to best approximate the average loss data for each malicious attack, (iv) calculate the expected loss due to cyber-attacks using collective risk modeling, (v) compute the net premium to be charged by cyber insurers to indemnify losses from a cyber-attack, and (vi) propose either cyber insurance or self-insurance, or self-protection, as a strategy for organizations to minimize losses.
机译:恶意外部攻击者通常会使用网络威胁(例如病毒攻击,拒绝服务(DoS)攻击,财务欺诈,系统渗透和专有信息盗窃),而内部攻击者会采取未经授权的访问方式来破坏机密性,完整性,个人,组织和国家/地区数据的可用性(CIA)。这会导致机会成本,市场资本损失以及组织的品牌资产损失。组织和国家/地区将其信息技术(IT)预算的很大一部分用于IT安全(例如外围和核心安全技术)。但是,安全漏洞很常见。在本文中,我们提出了一种网络风险评估和缓解(CRAM)框架,用于(i)使用广义线性模型(GLM)(即logit和probit)估计攻击的可能性,并使用美国计算机安全协会(Computer Security Institute-Federal)进行验证美国调查局(CSI-FBI)的时间序列数据,(ii)预测将在明年将攻击概率降低到给定水平所需的安全技术,(iii)使用伽马和指数分布来最好地估计以下情况的平均损失数据每次恶意攻击,(iv)使用集体风险模型计算由于网络攻击而造成的预期损失,(v)计算网络保险公司收取的净保费,以补偿网络攻击造成的损失,并且(vi)保险,自我保险或自我保护,作为组织将损失降到最低的策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号