勒索
规范性
付款
赎金
支付卡
投资(军事)
业务
精算学
经济
心理干预
计算机安全
法学
财务
计算机科学
政治学
心理学
精神科
政治
作者
Kay‐Yut Chen,Jingguo Wang,Yan Lang
出处
期刊:Management Science
[Institute for Operations Research and the Management Sciences]
日期:2021-11-22
卷期号:68 (7): 5269-5286
被引量:12
标识
DOI:10.1287/mnsc.2021.4154
摘要
Digital extortion has emerged as a significant threat to organizations that rely on information technologies for their operations. Using human subject experimentation, we study the effectiveness of message appeals in encouraging defenders to adopt two mitigation strategies, investment in security and refusal to pay ransoms, to digital extortion threats. We explore two types of appeals, benefit and normative, for this purpose. We find that the decisions of the defenders (representing any organization that can be a potential victim) deviate from the predictions of game theory. However, given the strategic interactions between the defenders and the attacker as well as noisy decision-making behaviors, it is challenging to untangle the influence of the appeals on the defenders. We develop a structural model based on the quantal response equilibrium framework to measure how message appeals change the defenders’ utilities of investment and payment refusal. Although the interventions may be successful in increasing the utilities of investment and/or payment refusal, their impacts on investment rate and payment rate are mitigated by the attacker reducing ransoms. Thus, it is challenging for an intervention to significantly boost a community’s investment rate or to suppress the ransom payment rate. We characterize how security outcomes of a community (including expected ransom, attack rate, investment rate, and payment rate) vary with the defenders’ utilities of investment and pay refusal. This paper was accepted by Chris Forman, information systems.
科研通智能强力驱动
Strongly Powered by AbleSci AI