A statistical approach for assessing cyber risk via ordered response models

被引:0
|
作者
Facchinetti, Silvia [1 ]
Osmetti, Silvia Angela [1 ,3 ]
Tarantola, Claudia [2 ]
机构
[1] Univ Cattolica Sacro Cuore, Dept Stat Sci, Milan, Italy
[2] Univ Pavia, Dept Econ & Management, Pavia, Italy
[3] Univ Cattolica Sacro Cuore, Dept Stat Sci, Largo Gemelli 1, I-20123 Milan, Italy
关键词
cumulative link model; cyber risk; marginal effect; social network analysis; GOODNESS-OF-FIT; LOGISTIC-REGRESSION; SECURITY EVENTS; IMPACT; FIRMS; TESTS;
D O I
10.1111/risa.14186
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Proper evaluation of the risk associated to a cyber attack is a crucial aspect for many companies. There is an increasing need to plan for and implement effective ways to address cyber security, data security, and privacy protection. Estimating the risk of a successful cyber attack is an important issue, since this type of threat is proliferating and thus poses increasing danger to companies and the customers who use their services. While quantitative loss data are rarely available, it is possible to obtain a qualitative evaluation on an ordinal scale of severity of cyber attacks from experts of the sector. Hence, it is natural to apply order response models for the analysis of cyber risk. In particular, we rely on cumulative link models. We explain the experts' assessment of the severity of a cyber attack as a function of a set of explanatory variables describing the characteristics of the attack under consideration. A measure of diffusion of the effects of the attacks obtained via the use of a network structure is also incorporated into the set of explanatory variables of the model. Along with the description of the methodology, we present a detailed analysis of a real data set that includes information on serious cyber attacks occurred worldwide in the period 2017-2018.
引用
收藏
页码:425 / 438
页数:14
相关论文
共 50 条
  • [41] Duality in ruin problems for ordered risk models
    Goffard, Pierre-Olivier
    Lefevre, Claude
    INSURANCE MATHEMATICS & ECONOMICS, 2018, 78 : 44 - 52
  • [42] Executive decision-makers: a scenario-based approach to assessing organizational cyber-risk perception
    Parkin, Simon
    Kuhn, Kristen
    Shaikh, Siraj A.
    JOURNAL OF CYBERSECURITY, 2023, 9 (01):
  • [43] Assessing the risk of cryptosporidiosis - Response
    不详
    JOURNAL AMERICAN WATER WORKS ASSOCIATION, 1999, 91 (03): : 116 - 116
  • [44] Assessing osteoporosis risk - Response
    Kendler, D
    CANADIAN MEDICAL ASSOCIATION JOURNAL, 1998, 159 (11) : 1356 - 1356
  • [45] A Developmental Approach to Learning Causal Models for Cyber Security
    Mugan, Jonathan
    MACHINE INTELLIGENCE AND BIO-INSPIRED COMPUTATION: THEORY AND APPLICATIONS VII, 2013, 8751
  • [46] An Integrated Cyber Security Risk Management Approach for a Cyber-Physical System
    Kure, Halima Ibrahim
    Islam, Shareeful
    Razzaque, Mohammad Abdur
    APPLIED SCIENCES-BASEL, 2018, 8 (06):
  • [47] Examination of Market Risk Estimation Models via DEA Approach Modelling
    Kresta, Ales
    Tichy, Tomas
    Toloo, Mehdi
    POLITICKA EKONOMIE, 2017, 65 (02) : 161 - 178
  • [48] ASSESSING CANCER RISKS - FROM STATISTICAL TO BIOLOGICAL MODELS
    COX, LA
    JOURNAL OF ENERGY ENGINEERING-ASCE, 1990, 116 (03): : 189 - 210
  • [49] Assessing Hydrological Simulations with Machine Learning and Statistical Models
    Rozos, Evangelos
    HYDROLOGY, 2023, 10 (02)
  • [50] Statistical methods in assessing agreement: Models, issues, and tools
    Lin, L
    Hedayat, AS
    Sinha, B
    Yang, M
    JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2002, 97 (457) : 257 - 270