
We investigate the impact of an information shock { the public exposure of the names and addresses of holders of handgun carry permits { on criminals’ propensity to commit crimes. In December 2008, a Memphis, TN newspaper published a searchable online database of names, zip codes, and ages of Tennessee handgun carry permit holders. Once news of the database publication spread, an intense and acrimonious debate arose. Permit holders ooded the newspaper demanding its removal, on the grounds that the database invaded their privacy. Gun rights associations argued that the newspaper had put law-abiding gun owners at risk, giving criminals a pathway to burglarize their homes. The newspaper responded by suggesting that any criminal who perused the database would, in fact, be more likely to avoid households they believed to contain guns. We use detailed crime and handgun carry permit data for Memphis to estimate the impact of the database publication on dierent types of crime. We nd
Insurance premiums reflect expectations about the future losses of each insured. Given the dearth of cyber security loss data, market premiums could shed light on the true magnitude of cyber losses despite noise from factors unrelated to losses. To that end, we extract cyber insurance pricing information from the regulatory filings of 26 insurers. We provide empirical observations on how premiums vary by coverage type, amount, and policyholder type and over time. A method using particle swarm optimisation and the expected value premium principle is introduced to iterate through candidate parameterised distributions with the goal of reducing error in predicting observed prices. We then aggregate the inferred loss models across 6,828 observed prices from all 26 insurers to derive the County Fair Cyber Loss Distribution . We demonstrate its value in decision support by applying it to a theoretical retail firm with annual revenue of $50M. The results suggest that the expected cyber liability loss is $428K and that the firm faces a 2.3% chance of experiencing a cyber liability loss between $100K and $10M each year. The method and resulting estimates could help organisations better manage cyber risk, regardless of whether they purchase insurance.
In spite of the growing importance of software security and the industry demand for more cyber security expertise in the workforce, the effect of security education and experience on the ability to assess complex software security problems has only been recently investigated. As proxy for the full range of software security skills, we considered the problem of assessing the severity of software vulnerabilities by means of a structured analysis methodology widely used in industry (i.e. the Common Vulnerability Scoring System (\CVSS) v3), and designed a study to compare how accurately individuals with background in information technology but different professional experience and education in cyber security are able to assess the severity of software vulnerabilities. Our results provide some structural insights into the complex relationship between education or experience of assessors and the quality of their assessments. In particular we find that individual characteristics matter more than professional experience or formal education; apparently it is the \emph{combination} of skills that one owns (including the actual knowledge of the system under study), rather than the specialization or the years of experience, to influence more the assessment quality. Similarly, we find that the overall advantage given by professional expertise significantly depends on the composition of the individual security skills as well as on the available information.
Since Bitcoin's introduction in 2009, interest in cryptocurrencies has soared. One manifestation of this interest has been the explosion of newly created coins and tokens. In this paper, we analyze the dynamics of this burgeoning industry. We consider both cryptocurrency coins and tokens. The paper examines the dynamics of coin and token creation, competition and destruction in the cryptocurrency industry. In order to conduct the analysis, we develop a methodology to identify peaks in prices and trade volume, as well as when coins and tokens are abandoned and subsequently "resurrected". We also study trading activity. Our data spans more than 4 years: there are 1082 coins and 725 tokens in the data. While there are some similarities between coins and tokens regarding dynamics, there are some striking differences as well. Overall, we find that 44% of publicly-traded coins are abandoned, at least temporarily. 71% of abandoned coins are later resurrected, leaving 18% of coins to fail permanently. Tokens experience abandonment less frequently, with only 7% abandonment and 5% permanent token abandonment at the end of the data. Using linear regressions, we find that market variables such as the bitcoin price are not associated with the rate of introducing new coins, though they are positively associated with issuing new tokens. We find that for both coins and tokens, market variables are positively associated with resurrection. We then examine the effect that the bursting of the Bitcoin bubble in December 2017 had on the dynamics in the industry. Unlike the end of the 2013 bubble, some alternative cryptocurrencies continue to flourish after the bursting of this bubble.
The work presented in this paper is motivated by the need to estimate the security effort of maintaining Free and Open Source Software (FOSS) components within the software supply chain of a large international software vendor. We investigated publicly available factors (from number of active users to commits, from code size to usage of popular programming languages, etc.) to identify which ones impact three potential effort models: centralized (the company checks each component and propagates changes to the product groups), distributed (each product group is in charge of evaluating and fixing its consumed FOSS components), and hybrid (seldom used components are checked individually by each development team, the rest is centralized). We use Grounded Theory to extract the factors from a six months study at the vendor. We report the results on a sample of 166 FOSS components used by the vendor.
Introduction A decade has passed since the enactment of data breach notification laws (DBNLs) in numerous U.S. states. These laws mandate companies that have suffered a data breach to inform the customers whose data might have been exposed. The intent of DBNLs can perhaps be best summed up in the phrase: “sunlight is the best disinfectant”. Whether the goal of incentivizing better security practices has been realized is the subject of an ongoing debate (e.g., Romanosky et al. 2011, Bisogni 2016). What is clear, however, is that they have offered more visibility into the state of data breach events in the United States.
The assumption that a cyberattacker will potentially exploit all present vulnerabilities drives most modern cyber risk management practices and the corresponding security investments. We propose a new attacker model, based on dynamic optimization, where we demonstrate that large, initial, fixed costs of exploit development induce attackers to delay implementation and deployment of exploits of vulnerabilities. The theoretical model predicts that mass attackers will preferably (i) exploit only one vulnerability per software version, (ii) largely include only vulnerabilities requiring low attack complexity, and (iii) be slow at trying to weaponize new vulnerabilities . These predictions are empirically validated on a large data set of observed massed attacks launched against a large collection of information systems. Findings in this article allow cyber risk managers to better concentrate their efforts for vulnerability management, and set a new theoretical and empirical basis for further research defining attacker (offensive) processes.
We present the first measurement study of JoinMarket, a growing marketplace for more anonymous transfers in the Bitcoin ecosystem. Our study reveals that this market is funded with multiple thousand bitcoins and generated a turnover of almost 8 million USD over the course of eight months. Assessing the resilience of the market against a wellfunded attacker, we discover that in a typical scenario, a selective attack with 90 % success rate requires an investment of 32,000 USD (which is recoverable after the attack). We formulate stylized economic models of supply and demand to explain the existence of this novel market for anonymity and underpin some theoretical arguments with empirical data.
The study presented in this article investigated to what extent bank customers understand the terms and conditions (T&Cs) they have signed up to. If many customers are not able to understand T&Cs and the behaviours they are expected to comply with, they risk not being compensated when their accounts are breached. An expert analysis of 30 bank contracts across 25 countries found that most contract terms were too vague for customers to infer required behaviour. In some cases the rules vary for different products, meaning the advice can be contradictory at worst. While many banks allow customers to write Personal identification numbers (PINs) down (as long as they are disguised and not kept with the card), 20% of banks categorically forbid writing PINs down, and a handful stipulate that the customer have a unique PIN for each account. We tested our findings in a survey with 151 participants in Germany, the USA and UK. They mostly agree: only 35% fully understand the T&Cs, and 28% find important sections are unclear. There are strong regional variations: Germans found their T&Cs particularly hard to understand, and USA bank customers assumed some of their behaviours contravened the T&Cs, but were reassured when they actually read them.
While cybercrime has existed for many years and is still reported to be a growing problem, reliable estimates of the economic impacts are rare. We develop a survey instrument tailored to measure the costs of consumer-facing cybercrime systematically, by aggregating different cost factors into direct losses and expenses for protection measures. We use our instrument to collect representative primary data on the prevalence of seven different types of consumer-facing cybercrime in six European countries. Our results show that cybercrime rather causes losses of time than money and that the losses of victims are dwarfed by the expenses for preventive protection. We identify scams to be the worst type of cybercrime in terms of losses. While identity thefts associated with financial accounts cause high initial losses for the victims, most of them receive substantial compensation. We find that loss distributions are skewed to the left, bearing the risk of overestimating costs when looking at figures summarized by the arithmetic mean.
The payment industry has been characterized by a small number of players that operate the schemes for the facilitation of credit and debit card payments. Over the years, various initiatives have been taken in order to increase competition and hence cost efficiency within the industry. One of the latest efforts is the introduction of Payment Service Directive II (PSDII) within the European Union. PSDII requires banks to open up their services to Third Party Payment (TPP) networks. TPP networks make use of banks’ payment initiation services for e-commerce transactions, creating an alternative next to credit and debit card payments. However, just like in the card networks, payment fraud is not absent in TPP networks. Fraud manifests itself in non-payments: authorized payments that do not get settled. In this paper we first analyze the ecosystem dynamics of the TPP network by examining the role of each actor involved. By leveraging one year of transaction data from the TPP network, we estimate the prevalence of non-payments. Finally, we evaluate a preventive and reactive risk management strategy. The latter strategy comprises of a non-payment recovery process — sending the consumer a reminder of the due amount—and proves to be surprisingly effective. Additionally, we have evidence that combining both strategies into a continuous risk management process can yield even better results. As non-payment in the TPP network has similarities with chargebacks in the card network, we believe that our approach can also enhance risk management in the card network.
This paper studies investment in cybersecurity, where both the software vendor and the consumers can invest in security. In addition, the vendor can undertake attack-deterring and damage-control investments. I show that full liability, under which the vendor is liable for all damages, does not achieve eciency and, in particular, the vendor underinvests in attack deterrence and overinvests in damage control. Instead, the joint use of an optimal standard, which establishes a minimum compliance framework, and partial liability can restore eciency. This suggests that policies that encourage not only firms, but also consumers to invest in security might be desirable.
This paper aims to understand if, and to what extent, business details about an organization can help provide guidelines for better resource allocation across different preventive measures, in order to effectively protect, detect, and recover from, different forms of security incidents. Existing work on analyzing the distribution of risk across different incident categories, most notably Verizon’s latest Data Breach Investigations Report, provide recommendations based solely on business sector information. In this paper, we leverage a broader set of publicly available business details to provide a more fine-grained analysis. Specifically, we use incident reports collected in the VERIS Community Database (VCDB), as well as data from Alexa Web Information Service (AWIS), to train and test a sequence of classifiers/predictors. We show that compared to using business sector information alone, our method can achieve the same accuracy by allowing organizations to focus on a sparser set of incident types, thus achieving the same level of protection by spending less resources on security through more judicious prioritization.
Despite the high value that internet users place on privacy, they offer their personal information for low compensations. This behavior, known as the privacy paradox, has been explained by a stream of literature (culminating with a recent paper by Acquisti, John and Lowenstein) with different behavioral biases, and in particular with hyperbolic discounting. However, economic theory offers two possible reasons to discount payoffs — costs of waiting and hazard rates — which produce two possible reasons for choice reversal. This paper argues that the second can explain the privacy paradox within a rational-choice framework in a way that fits more intuitively with consumer claims and with contemporary policy debates on privacy. A discounting model based on uncertain hazard rates would also change the policy conclusions of the hyperbolic discounting model. In particular, it would be relevant for the right to be forgotten.
Legislators in many countries enact security breach notification regulation to address a lack of information security. The laws designate authorities to collect breach reports and advise firms. We devise a principal–agent model to analyze the economic effect of mandatory security breach reporting to authorities. The model assumes that firms (agents) have few incentives to unilaterally report breaches. To enforce the law, regulators (principals) can introduce security audits and sanction noncompliance. However, audits cannot differentiate between concealment and nescience of the agents. Even under optimistic assumptions regarding the effectiveness of mandatory security breach reporting to authorities in reducing individual losses, our model predicts that it may be difficult to adjust the sanction level such that breach notification laws generate social benefit.
Internet crime has become increasingly dependent on the underground economy: a loose federation of specialists selling capabilities, services, and resources explicitly tailored to the abuse ecosystem. Through these emerging markets, modern criminal entrepreneurs piece together dozens of a la carte components into entirely new criminal endeavors. From an abuse fighting perspective, criminal reliance on this black market introduces fragile dependencies that, if disrupted, undermine entire operations that as a composite appear intractable to protect against. However, without a clear framework for examining the costs and infrastructure behind Internet crime, it becomes impossible to evaluate the effectiveness of novel intervention strategies. In this paper, we survey a wealth of existing research in order to systematize the community’s understanding of the underground economy. In the process, we develop a taxonomy of profit centers and support centers for reasoning about the flow of capital (and thus dependencies) within the black market. Profit centers represent activities that transfer money from victims and institutions into the underground. These activities range from selling products to unwitting customers (in the case of spamvertised products) to outright theft from victims (in case of financial fraud). Support centers provide critical resources that other miscreants request to streamline abuse. These include exploit kits, compromised credentials, and even human services (e.g., manual CAPTCHA solvers) that have no credible non-criminal applications. We use this framework to contextualize the latest intervention strategies and their effectiveness. In the end, we champion a drastic departure from solely focusing on protecting users and systems (tantamount to a fire fight) and argue security practitioners must also strategically focus on disrupting frail underground relationships that underpin the entire for-profit abuse ecosystem—including actors, infrastructure, and access to capital.
Motivation: Participants on the front lines of abuse reporting have a variety of options to notify intermediaries and resource owners about abuse of their systems and services. These can include emails to personal messages to blacklists to machine-generated feeds. Recipients of these reports have to voluntarily act on this information. We know remarkably little about the factors that drive higher response rates to abuse reports. One such factor is the reputation of the sender. In this article, we present the first randomized controlled experiment into sender reputation. We used a private datafeed of Asprox-infected websites to issue notifications from three senders with different reputations: an individual, a university and an established anti-malware organization.Results: We find that our detailed abuse reports significantly increase cleanup rates. Surprisingly, we find no evidence that sender reputation improves cleanup. We do see that the evasiveness of the attacker in hiding compromise can substantially hamper cleanup efforts. Furthermore, we find that the minority of hosting providers who viewed our cleanup advice webpage were much more likely to remediate infections than those who did not, but that website owners who viewed the advice fared no better.
Information security professionals have to assess risk in order to make investment decisions on security measures. To investigate whether professionals make such decisions unbiased and rationally, we conducted an economic online experiment and survey measuring risk attitude of security professionals and contrasting their behaviour with the general population. Participants were asked to state their willingness-to-pay in order to avoid a series of losses-only lotteries and to make choices between such lotteries. We also devised a mechanism to elicit preferences between security and operability. Our findings suggest that security professionals are risk and ambiguity averse, consider small losses inevitable and take risks when losses are associated with large probabilities. We find that their preferences are measurably different from those of the general population in some of these aspects. We also find that job position influences security and operability preferences and that avoidance of salient (catastrophic) outcomes explains some of the professionals’ behaviour. Moreover, professionals are susceptible to framing effects to the same extent as the general population, and reveal distorted probability perception, factors that are usually overlooked in risk assessment methodologies.