ZETAR: Modeling and Computational Design of Strategic and Adaptive Compliance Policies

被引:0
|
作者
Huang, Linan [1 ]
Zhu, Quanyan [2 ]
机构
[1] Tsinghua Univ, Beijing Natl Res Ctr Informat Sci & Technol BNRist, Beijing 100084, Peoples R China
[2] NYU, Dept Elect & Comp Engn, Brooklyn, NY 11201 USA
基金
美国国家科学基金会;
关键词
Bayesian persuasion; incentive learning; incentive mechanism; information design; insider threat; zero-trust; INCENTIVE MECHANISM DESIGN;
D O I
10.1109/TCSS.2023.3323539
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Compliance management plays an important role in mitigating insider threats. Incentive design is a proactive and noninvasive approach to achieving compliance by aligning an insider's incentive with the defender's security objective, which motivates (rather than commands) an insider to act in the organization's interests. Controlling insiders' incentives for population-level compliance is challenging because they are neither precisely known nor directly controllable. To this end, we develop ZEro-Trust Audit with strategic Recommendation (ZETAR), a zero-trust audit and recommendation framework, to provide a quantitative approach to model insiders' incentives and design customized recommendation policies to improve their compliance. We formulate primal and dual convex programs to compute the optimal bespoke recommendation policies. We create the theoretical underpinning for understanding trust, compliance, and satisfaction, which leads to scoring mechanisms of how compliant and persuadable an insider is. After classifying insiders as malicious, self-interested, or amenable based on their incentive misalignment levels with the defender, we establish bespoke information disclosure principles for these insiders of different incentive categories. We identify the policy separability principle and the set convexity, which enable finite-step algorithms to efficiently learn the completely trustworthy (CT) policy set when insiders' incentives are unknown. Finally, we present a case study to corroborate the design. Our results show that ZETAR can well adapt to insiders with different risk and compliance attitudes and significantly improve compliance. Moreover, trustworthy recommendations can provably promote cyber hygiene and insiders' satisfaction.
引用
收藏
页码:4001 / 4015
页数:15
相关论文
共 50 条
  • [1] A strategic approach to managerial compliance with equal pay policies
    Julien Picault
    [J]. SN Business & Economics, 3 (8):
  • [2] Strategic Materials and Computational Design Introduction
    Mathur, Sanjay
    Ohji, Tatsuki
    [J]. STRATEGIC MATERIALS AND COMPUTATIONAL DESIGN, 2010, 31 (10): : XI - XII
  • [3] Elucidating strategic network dynamics through computational modeling
    Zhiang (John) Lin
    James A. Kitts
    Haibin Yang
    J. Richard Harrison
    [J]. Computational and Mathematical Organization Theory, 2008, 14 : 175 - 208
  • [4] Elucidating strategic network dynamics through computational modeling
    Lin, Zhiang
    Kitts, James A.
    Yang, Haibin
    Harrison, J. Richard
    [J]. COMPUTATIONAL AND MATHEMATICAL ORGANIZATION THEORY, 2008, 14 (03) : 175 - 208
  • [5] Computational modeling for formulation design
    Mehta, Chetan Hasmukh
    Narayan, Reema
    Nayak, Usha Y.
    [J]. DRUG DISCOVERY TODAY, 2019, 24 (03) : 781 - 788
  • [6] MODELING STRATEGIC ACQUISITION POLICIES - A SIMULATION OF EXECUTIVES ACQUISITION DECISIONS
    STAHL, MJ
    ZIMMERER, TW
    [J]. ACADEMY OF MANAGEMENT JOURNAL, 1984, 27 (02): : 369 - 383
  • [7] Adaptive Modeling and Compliance Control for RC Servo Motor
    Hayashi, Mikiya
    Koide, Yusuke
    Matsuhara, Kouhei
    Ushida, Shun
    Oku, Hiroshi
    Kongprawechnon, Waree
    [J]. 2017 56TH ANNUAL CONFERENCE OF THE SOCIETY OF INSTRUMENT AND CONTROL ENGINEERS OF JAPAN (SICE), 2017, : 664 - 667
  • [8] Exoskeleton design and adaptive compliance control for hand rehabilitation
    Akgun, Gazi
    Cetin, Ahmet Emre
    Kaplanoglu, Erkan
    [J]. TRANSACTIONS OF THE INSTITUTE OF MEASUREMENT AND CONTROL, 2020, 42 (03) : 493 - 502
  • [9] Computational modeling and design of renin inhibitors
    Subramanian, Govindan
    [J]. BIOORGANIC & MEDICINAL CHEMISTRY LETTERS, 2013, 23 (02) : 460 - 465
  • [10] Design of Adaptive Compliance Controllers for Safe Robotic Assembly
    Jha, Devesh K.
    Romeres, Diego
    Jain, Siddarth
    Yerazunis, William
    Nikovski, Daniel
    [J]. 2023 EUROPEAN CONTROL CONFERENCE, ECC, 2023,