黑客
信息安全
业务
信息安全管理
计算机安全
信息共享
相互依存
产业组织
安全信息和事件管理
计算机科学
云安全计算
政治学
云计算
操作系统
万维网
法学
作者
Yong Wu,Mengyao Xu,Dong Cheng,Tao Dai
出处
期刊:Decision Analysis
[Institute for Operations Research and the Management Sciences]
日期:2022-03-23
卷期号:19 (2): 99-122
被引量:17
标识
DOI:10.1287/deca.2021.0442
摘要
Information resources have been shared to promote the business operations of firms. However, the connection of business information sharing interfaces between firms has increased the attack surface and created opportunities for the hacker. We examine the benefits and risks of business information sharing for firms who exert security efforts against a strategic hacker that launches attacks subjectively. We show that two kinds of security efforts, security investment and security knowledge sharing, act as strategic substitutes when the business-sharing degree is low and act as strategic complements otherwise. Besides, the strategic hacker is not always aggressive, who will give up launching attack activities when the business-sharing degree is relatively low. Moreover, as a specific characteristic in the security domain, the risk interdependency first enhances and then suppresses both firms’ security investments and the hacker’s attack effort, which causes a free-riding problem for two firms. Then, two coordination mechanisms, an investment-based mechanism and liability-based mechanism, are proposed to help firms coordinate their strategies to reach socially optimal security levels. Last, we extend the main model to three cases to make our model more general. This paper provides the first evidence to assess the security risks exacerbated by business information sharing while considering a strategic hacker. Some management insights to managers for making security decisions are provided.
科研通智能强力驱动
Strongly Powered by AbleSci AI