作者
Yong Wu, Gengzhong Feng, Nengmin Wang, Huigang Liang
发表日期
2015/9/1
期刊
Expert Systems with Applications
卷号
42
期号
15-16
页码范围
6132-6146
出版商
Pergamon
简介
The level of firms’ information security investment has recently become a critical issue in the management of IT infrastructure. Prior studies have not considered attack types and firms interconnection simultaneously when investigating the optimisation of such investment. Using game theory, we demonstrate that the optimal security investment level of an interconnected firm against targeted attacks is different from that against opportunistic attacks. Our model shows that not all information security risks are worth fighting against. As the potential loss increases, it is unadvisable to increase the security investment proportionately. Firms should increase investments with intrinsic vulnerability when facing target attacks, but focus on those systems that fall into the midrange of intrinsic vulnerability when facing opportunistic attacks. Firms are unwilling to invest in security and often offload reliability problems onto others when …
引用总数
201520162017201820192020202120222023202421691179151255
学术搜索中的文章