已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整的填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Correlated Failures, Diversification, and Information Security Risk Management

多元化(营销策略) 业务 风险管理 信息安全 信息安全管理 风险分析(工程) 知识管理 运营管理 计算机安全 安全信息和事件管理 计算机科学 财务 营销 经济 云安全计算 操作系统 云计算
作者
Chen,Kataria,Krishnan
出处
期刊:Management Information Systems Quarterly [MIS Quarterly]
卷期号:35 (2): 397-397 被引量:111
标识
DOI:10.2307/23044049
摘要

The increasing dependence on information networks for business operations has focused managerial attention on managing risks posed by failure of these networks. In this paper, we develop models to assess the risk of failure on the availability of an information network due to attacks that exploit software vulnerabilities. Software vulnerabilities arise from software installed on the nodes of the network. When the same software stack is installed on multiple nodes on the network, software vulnerabilities are shared among them. These shared vulnerabilities can result in correlated failure of multiple nodes resulting in longer repair times and greater loss of availability of the network. Considering positive network effects (e.g., compatibility) alone without taking the risks of correlated failure and the resulting downtime into account would lead to overinvestment in homogeneous software deployment. Exploiting characteristics unique to information networks, we present a queuing model that allows us to quantify downtime loss faced by a rm as a function of (1) investment in security technologies to avert attacks, (2) software diversification to limit the risk of correlated failure under attacks, and (3) investment in IT resources to repair failures due to attacks. The novelty of this method is that we endogenize the failure distribution and the node correlation distribution, and show how the diversification strategy and other security measures/investments may impact these two distributions, which in turn determine the security loss faced by the firm. We analyze and discuss the effectiveness of diversification strategy under different operating conditions and in the presence of changing vulnerabilities. We also take into account the benefits and costs of a diversification strategy. Our analysis provides conditions under which diversification strategy is advantageous.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
1秒前
科研饼发布了新的文献求助10
6秒前
乐乐应助yyt采纳,获得10
7秒前
JWonder完成签到,获得积分10
7秒前
斯寜应助否定之否定采纳,获得10
10秒前
hyd1640发布了新的文献求助200
11秒前
gao2689完成签到,获得积分10
13秒前
豆芽发布了新的文献求助10
14秒前
17秒前
19秒前
开心满天发布了新的文献求助10
20秒前
zhang完成签到 ,获得积分10
20秒前
豆芽完成签到,获得积分10
21秒前
隐形曼青应助郭叠采纳,获得10
21秒前
否定之否定完成签到,获得积分10
22秒前
23秒前
斯文败类应助梌夕采纳,获得10
26秒前
ding应助开心满天采纳,获得10
29秒前
wendydqw完成签到 ,获得积分10
31秒前
34秒前
OE完成签到,获得积分10
35秒前
Hello应助阜睿采纳,获得10
36秒前
贝贝贝贝贝贝舒适的休息下完成签到 ,获得积分10
36秒前
41秒前
41秒前
42秒前
42秒前
一颗小行星完成签到 ,获得积分10
42秒前
华仔应助成就紫真采纳,获得10
46秒前
yyt发布了新的文献求助10
47秒前
TheDay发布了新的文献求助10
47秒前
韭菜发布了新的文献求助10
47秒前
TheDay发布了新的文献求助10
51秒前
英姑应助韭菜采纳,获得10
53秒前
Jake完成签到,获得积分10
55秒前
无情听南完成签到,获得积分10
57秒前
珂尔维特完成签到,获得积分10
59秒前
TheDay发布了新的文献求助10
1分钟前
David完成签到 ,获得积分10
1分钟前
高分求助中
【此为提示信息,请勿应助】请按要求发布求助,避免被关 20000
Continuum Thermodynamics and Material Modelling 2000
Encyclopedia of Geology (2nd Edition) 2000
105th Edition CRC Handbook of Chemistry and Physics 1600
Maneuvering of a Damaged Navy Combatant 650
Периодизация спортивной тренировки. Общая теория и её практическое применение 310
Mixing the elements of mass customisation 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3778966
求助须知:如何正确求助?哪些是违规求助? 3324631
关于积分的说明 10218995
捐赠科研通 3039588
什么是DOI,文献DOI怎么找? 1668356
邀请新用户注册赠送积分活动 798646
科研通“疑难数据库(出版商)”最低求助积分说明 758440