A statistical approach for assessing cyber risk via ordered response models

被引:0
|
作者
Facchinetti, Silvia [1 ]
Osmetti, Silvia Angela [1 ,3 ]
Tarantola, Claudia [2 ]
机构
[1] Univ Cattolica Sacro Cuore, Dept Stat Sci, Milan, Italy
[2] Univ Pavia, Dept Econ & Management, Pavia, Italy
[3] Univ Cattolica Sacro Cuore, Dept Stat Sci, Largo Gemelli 1, I-20123 Milan, Italy
关键词
cumulative link model; cyber risk; marginal effect; social network analysis; GOODNESS-OF-FIT; LOGISTIC-REGRESSION; SECURITY EVENTS; IMPACT; FIRMS; TESTS;
D O I
10.1111/risa.14186
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Proper evaluation of the risk associated to a cyber attack is a crucial aspect for many companies. There is an increasing need to plan for and implement effective ways to address cyber security, data security, and privacy protection. Estimating the risk of a successful cyber attack is an important issue, since this type of threat is proliferating and thus poses increasing danger to companies and the customers who use their services. While quantitative loss data are rarely available, it is possible to obtain a qualitative evaluation on an ordinal scale of severity of cyber attacks from experts of the sector. Hence, it is natural to apply order response models for the analysis of cyber risk. In particular, we rely on cumulative link models. We explain the experts' assessment of the severity of a cyber attack as a function of a set of explanatory variables describing the characteristics of the attack under consideration. A measure of diffusion of the effects of the attacks obtained via the use of a network structure is also incorporated into the set of explanatory variables of the model. Along with the description of the methodology, we present a detailed analysis of a real data set that includes information on serious cyber attacks occurred worldwide in the period 2017-2018.
引用
收藏
页码:425 / 438
页数:14
相关论文
共 50 条
  • [31] Statistical Approach to Architecture Modes in Smart Cyber Physical Systems
    Bures, Tomas
    Hnetynka, Petr
    Kofron, Jan
    Al Ali, Rima
    Skoda, Dominik
    2016 13TH WORKING IEEE/IFIP CONFERENCE ON SOFTWARE ARCHITECTURE (WICSA), 2016, : 168 - 177
  • [32] Cyber-risk management not feasible - Response
    不详
    COMMUNICATIONS OF THE ACM, 2003, 46 (05) : 13 - 13
  • [33] A Method for Developing Algorithms for Assessing Cyber-Risk Cost
    Erdogan, Gencer
    Refsdal, Atle
    Seehusen, Fredrik
    Gonzalez, Alejandra
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS), 2017, : 192 - 199
  • [34] Assessing the predictive value of facial biometrics for genomic health traits via a statistical learning approach
    McVey, C.
    Pinedo, P.
    JOURNAL OF DAIRY SCIENCE, 2019, 102 : 257 - 257
  • [35] Cyber incident response and planning: a flexible approach
    Shinde N.
    Kulkarni P.
    Computer Fraud and Security, 2021, 2021 (01): : 14 - 19
  • [36] Assessing Cyber Risk in Cyber-Physical Systems Using the ATT&CK Framework
    Amro, Ahmed
    Gkioulos, Vasileios
    Katsikas, Sokratis
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (02)
  • [37] Specification test in panel ordered response models
    Chen, Yongwei
    Li, Kunpeng
    Zhang, Jie
    COMMUNICATIONS IN STATISTICS-SIMULATION AND COMPUTATION, 2023,
  • [38] Ordered response models for sovereign debt ratings
    Afonso, Antonio
    Gomes, Pedro
    Rother, Philipp
    APPLIED ECONOMICS LETTERS, 2009, 16 (08) : 769 - 773
  • [39] SIMPLE SEMIPARAMETRIC ESTIMATION OF ORDERED RESPONSE MODELS
    Liu, Ruixuan
    Yu, Zhengfei
    ECONOMETRIC THEORY, 2024, 40 (01) : 1 - 36
  • [40] Estimation of ordered response models with sample selection
    De Luca, Giuseppe
    Perotti, Valeria
    STATA JOURNAL, 2011, 11 (02): : 213 - 239