Target Information Trading - An Economic Perspective of Security

被引:1
|
作者
Hou, Jing [1 ]
Sun, Li [1 ]
Shu, Tao [1 ]
Li, Husheng [2 ]
机构
[1] Auburn Univ, Dept Comp Sci & Software Engn, Auburn, AL 36849 USA
[2] Univ Tennessee, Dept Elect Engn & Comp Sci, Knoxville, TN 37996 USA
关键词
Security; Information market; Game theory; Economics;
D O I
10.1007/978-3-030-37231-6_7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ample evidence has confirmed the importance of information in security. While much research on security game has assumed the attackers' limited observation capabilities to obtain target information, few work considers the possibility that the information can be acquired from a data broker, not to mention exploring the profit-seeking behaviors of such an information service in the shrouded underground society. This paper studies the role of information in security problem when the target information is sold by a data broker to multiple competitive attackers. We formulate a novel multi-stage game model to characterize both the cooperative and competitive interactions of the data broker and attackers. Specifically, the attacker competition with correlated purchasing and attacking decisions is modeled as a two-stage stochastic model; and the bargaining process between the data broker and the attackers is analyzed in a Stackelberg game. Both the attackers' competitive equilibrium solutions and data broker's optimal pricing strategy are obtained. Our results show that with information trading, the target suffers from larger risks even when the information price is too high to benefit the attackers; and the information accuracy is more valuable when the target value is higher. Furthermore, the competition may weaken the information value to the attackers but benefit the data broker. The study contributes to the literature by characterizing the co-opetitive behaviors of the attackers with labor specialization, providing quantitative measures of information value from an economic perspective, and thus promoting a better understanding of the profit-seeking underground community.
引用
收藏
页码:126 / 145
页数:20
相关论文
共 50 条
  • [1] Economic perspective of information security
    Zhu, G
    Dai, J
    [J]. SAM'03: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND MANAGEMENT, VOLS 1 AND 2, 2003, : 527 - 533
  • [2] Why information security is hard - An economic perspective
    Anderson, R
    [J]. 17TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2001, : 358 - 365
  • [3] INFORMATION-SYSTEMS FOR SECURITY TRADING
    TAM, KY
    [J]. INFORMATION & MANAGEMENT, 1989, 16 (02) : 105 - 114
  • [4] Economic Security Perspective
    Shigeru, Kitamura
    [J]. ASIA-PACIFIC REVIEW, 2022, 29 (03) : 56 - 77
  • [5] Trading with the enemy - Security and relative economic gains
    Liberman, P
    [J]. INTERNATIONAL SECURITY, 1996, 21 (01) : 147 - 175
  • [6] Trading for security: Military alliances and economic agreements
    Long, Andrew G.
    Leeds, Brett Ashley
    [J]. JOURNAL OF PEACE RESEARCH, 2006, 43 (04) : 433 - 451
  • [7] Information security: The moving target
    Dlamini, M. T.
    Eloff, J. H. P.
    Eloff, M. M.
    [J]. COMPUTERS & SECURITY, 2009, 28 (3-4) : 189 - 198
  • [8] An Economic Perspective on Water Security
    Garrick, Dustin E.
    Hahn, Robert W.
    [J]. REVIEW OF ENVIRONMENTAL ECONOMICS AND POLICY, 2021, 15 (01) : 45 - 66
  • [9] The economic approach of information security
    Tsiakis, T
    Stephanides, G
    [J]. COMPUTERS & SECURITY, 2005, 24 (02) : 105 - 108
  • [10] INFORMATION RISKS AND ECONOMIC SECURITY
    Okhrimenko, S. A.
    Solonenko, O.
    [J]. FINANCIAL AND CREDIT ACTIVITY-PROBLEMS OF THEORY AND PRACTICE, 2010, 1 (08): : 200 - 204