A statistical approach for assessing cyber risk via ordered response models

被引:0
|
作者
Facchinetti, Silvia [1 ]
Osmetti, Silvia Angela [1 ,3 ]
Tarantola, Claudia [2 ]
机构
[1] Univ Cattolica Sacro Cuore, Dept Stat Sci, Milan, Italy
[2] Univ Pavia, Dept Econ & Management, Pavia, Italy
[3] Univ Cattolica Sacro Cuore, Dept Stat Sci, Largo Gemelli 1, I-20123 Milan, Italy
关键词
cumulative link model; cyber risk; marginal effect; social network analysis; GOODNESS-OF-FIT; LOGISTIC-REGRESSION; SECURITY EVENTS; IMPACT; FIRMS; TESTS;
D O I
10.1111/risa.14186
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Proper evaluation of the risk associated to a cyber attack is a crucial aspect for many companies. There is an increasing need to plan for and implement effective ways to address cyber security, data security, and privacy protection. Estimating the risk of a successful cyber attack is an important issue, since this type of threat is proliferating and thus poses increasing danger to companies and the customers who use their services. While quantitative loss data are rarely available, it is possible to obtain a qualitative evaluation on an ordinal scale of severity of cyber attacks from experts of the sector. Hence, it is natural to apply order response models for the analysis of cyber risk. In particular, we rely on cumulative link models. We explain the experts' assessment of the severity of a cyber attack as a function of a set of explanatory variables describing the characteristics of the attack under consideration. A measure of diffusion of the effects of the attacks obtained via the use of a network structure is also incorporated into the set of explanatory variables of the model. Along with the description of the methodology, we present a detailed analysis of a real data set that includes information on serious cyber attacks occurred worldwide in the period 2017-2018.
引用
收藏
页码:425 / 438
页数:14
相关论文
共 50 条
  • [1] Cyber risk ordering with rank-based statistical models
    Paolo Giudici
    Emanuela Raffinetti
    AStA Advances in Statistical Analysis, 2021, 105 : 469 - 484
  • [2] Cyber risk ordering with rank-based statistical models
    Giudici, Paolo
    Raffinetti, Emanuela
    ASTA-ADVANCES IN STATISTICAL ANALYSIS, 2021, 105 (03) : 469 - 484
  • [3] Assessing the Responses of Physical Parameters in Ocean via Statistical Approach
    Hamzah, Firdaus Mohamad
    Jaafar, Othman
    Nawawi, Mohd Kamal Mohd
    Ismail, Mohd Tahir
    Arbin, Norazman
    INTERNATIONAL CONFERENCE ON QUANTITATIVE SCIENCES AND ITS APPLICATIONS (ICOQSIA 2014), 2014, 1635 : 551 - 557
  • [4] Ordered response models
    Boes S.
    Winkelmann R.
    Allgemeines Statistisches Archiv, 2006, 90 (1): : 167 - 181
  • [5] Assessing Risk Factors for Dental Caries: A Statistical Modeling Approach
    Trottini, Mario
    Bossu, Maurizio
    Corridore, Denise
    Ierardo, Gaetano
    Luzzi, Valeria
    Saccucci, Matteo
    Polimeni, Antonella
    CARIES RESEARCH, 2015, 49 (03) : 226 - 235
  • [6] ASSESSING THE IMPACT OF CYBERLOAFING ON CYBER RISK
    Vernon-Bido, Daniele
    Grigoryan, Gayane
    Kavak, Hamdi
    Padilla, Jose
    PROCEEDINGS OF THE ANNUAL SIMULATION SYMPOSIUM (ANSS 2018), 2018, 50 (02):
  • [7] Employing Graphical Risk Models to Facilitate Cyber-Risk Monitoring - the WISER Approach
    Cernivec, Ales
    Erdogan, Gencer
    Gonzalez, Alejandra
    Refsdal, Atle
    Alvarez Romero, Antonio
    GRAPHICAL MODELS FOR SECURITY, 2018, 10744 : 127 - 146
  • [8] Cyber risk measurement via loss distribution approach and GARCH model
    Kim, Sanghee
    Song, Seongjoo
    COMMUNICATIONS FOR STATISTICAL APPLICATIONS AND METHODS, 2023, 30 (01) : 75 - 94
  • [9] Statistical models for the number of successful cyber intrusions
    Leslie, Nandi O.
    Harang, Richard E.
    Knachel, Lawrence P.
    Kott, Alexander
    JOURNAL OF DEFENSE MODELING AND SIMULATION-APPLICATIONS METHODOLOGY TECHNOLOGY-JDMS, 2018, 15 (01): : 49 - 63
  • [10] An Approach to Train and Evaluate the Cybersecurity Skills of Participants in Cyber Ranges based on Cyber-Risk Models
    Erdogan, Gencer
    Hugo, Asmund
    Romero, Antonio Alvarez
    Varano, Dario
    Zazzeri, Niccolo
    Zitnik, Anze
    ICSOFT: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON SOFTWARE TECHNOLOGIES, 2020, : 509 - 520