Cyber-Investment and Cyber-Information Exchange Decision Modeling

Abstract

Inefficiency of addressing cybersecurity problems can be settled by the corporations if they work in a collaborative manner, exchanging security information with each other. However, without any incentive and also due to the possibility of information exploitation, the firms may not be willing to share their breach/vulnerability information with the external agencies. Hence it is crucial to understand how the firms can be encouraged, so that they become self-enforced towards sharing their threat intelligence, which will not only increase their own payoff but also their peers' too, creating a win-win situation. In this research, we study the incentives and costs behind such crucial information sharing and security investments made by the firms. Specifically, a non-cooperative game between N-firms is formulated to analyze the participating firms' decisions about the information sharing and security investments. We analyze the probability of successful cyber attack using the famous dose-response immunity model. We also design an incentive model for CYBEX, which can incentivize/punish the firms based on their sharing/free-riding nature in the framework. Using negative definite Hessian condition, we find the conditions under which the social optimal values of the coupled constraint tuple (security investment and sharing quantity) can be found, which will maximize the firms' net payoff.

DOI: 10.1109/HPCC-CSS-ICESS.2015.264

Extracted Key Phrases

1 Figure or Table

Cite this paper

@article{Tosh2015CyberInvestmentAC, title={Cyber-Investment and Cyber-Information Exchange Decision Modeling}, author={Deepak K. Tosh and Matthew Molloy and Shamik Sengupta and Charles A. Kamhoua and Kevin A. Kwiat}, journal={2015 IEEE 17th International Conference on High Performance Computing and Communications, 2015 IEEE 7th International Symposium on Cyberspace Safety and Security, and 2015 IEEE 12th International Conference on Embedded Software and Systems}, year={2015}, pages={1219-1224} }