...
首页> 外文期刊>Procedia Computer Science >Economics of Privacy: A Model for Protecting Against Cyber Data Disclosure Attacks
【24h】

Economics of Privacy: A Model for Protecting Against Cyber Data Disclosure Attacks

机译:隐私的经济学:防范网络数据泄露攻击的模型

获取原文
           

摘要

The majority of research works on the the economics of data privacy are not suitable for firms that outsource their business operations. In particular, the computation of security investment does not consider the bilateral security risk, and the used threat models do not consider the particular aspects of privacy threats and attacks, which show the use of multiple steps to thief and misuse the information, and depend on the type of the stolen information and its lifetime. We provide in this work an economic security investment model, allowing firms, which outsource their IT business functions, to determine their optimal security investment and the related residual risk. In this work, threats on data privacy are modeled considering the particular aspects of privacy attacks. A numerical analysis is conducted to analyze the impact of the quality of detection and reaction to privacy breaches, on optimal investment and residual risk. The analysis shows that the amount of optimal investment depends on the minimal time period to detect a security breach, the ability of the customer firm to react to such an attack as quickly as possible, and also on the type of threat on private data. In particular it has been shown that for threats related to private information theft, the customer firm can take advantage from the delay in detecting attacks at the outsourcing provider side. Moreover, it should not also put a lot of security investment effort in reducing the reaction time to these privacy attacks. In the contrary, for threats related to privacy exploitation by self-propagating malware, the customer firm has not to contact with an outsourcing company which is not committed to report an attack occurrence within a short delay, and should not to put a lot of security investment effort in reducing the reaction time to these attacks.
机译:关于数据隐私经济学的大多数研究工作都不适合将业务运营外包的公司。特别是,安全投资的计算不考虑双边安全风险,使用的威胁模型也没有考虑隐私威胁和攻击的特定方面,这表明使用了多个步骤来窃贼和滥用信息,并且取决于被盗信息的类型及其寿命。我们在这项工作中提供了经济安全投资模型,允许将IT业务职能外包的公司确定其最佳安全投资和相关的剩余风险。在这项工作中,考虑到隐私攻击的特定方面,对数据隐私威胁进行了建模。进行了数值分析,以分析检测质量和对隐私泄露的反应对最佳投资和剩余风险的影响。分析表明,最佳投资的数量取决于检测安全漏洞的最短时间,客户公司尽快对此类攻击做出反应的能力以及私有数据受到威胁的类型。特别是,已经表明,对于与私人信息盗窃有关的威胁,客户公司可以从外包提供商端检测攻击的延迟中获得好处。此外,在减少对这些隐私攻击的响应时间方面,也不应投入大量安全投资。相反,对于与自我传播的恶意软件利用隐私相关的威胁,客户公司不必与不承诺在短时间内报告攻击发生的外包公司联系,并且不应提供过多的安全性在减少对这些攻击的反应时间方面进行了投入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号