SoK: Quantifying Cyber Risk
Daniel W. Woods, Rainer Böhme
摘要
This paper introduces a causal model inspired by structural equation modeling that explains cyber risk outcomes in terms of latent factors measured using reflexive indicators. First, we use the model to classify empirical cyber harm studies. We discover cyber harms are not exceptional in terms of typical or extreme losses. The increasing frequency of data breaches is contested and stock market reactions to cyber incidents are becoming less damaging over time. Focusing on harms alone breeds fatalism; the causal model is most useful in evaluating the effectiveness of security interventions. We show how simple statistical relationships lead to spurious results in which more security spending or applying updates are associated with greater rates of compromise. When accounting for threat and exposure, indicators of security are shown to be important factors in explaining the variance in rates of compromise, especially when the studies use multiple indicators of the security level.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper3
- Anatomy of a High-Profile Data Breach: Dissecting the Aftermath of a Crypto-Wallet CaseSvetlana Abramova, Rainer BöhmeUSENIX Security 2023
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
- Heimdall: Towards Risk-Aware Network Management OutsourcingYuejie Wang, Qiutong Men, Yongting Chen, Jiajin Liu 等NDSS 2025
相关 Paper
- "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected ThemPeter Mayer, Yixin Zou, Florian Schaub, Adam J. AvivUSENIX Security 2021 · 被引用 65 次
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise LevelRock Stevens, Daniel Votipka, Elissa M. Redmiles, Colin Ahern 等USENIX Security 2018 · 被引用 51 次
- Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach AttorneysDaniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel SchwarczUSENIX Security 2023
- Self-Efficacy and Security Behavior: Results from a Systematic Review of Research MethodsNele Borgert, Luisa Jansen, Imke Böse, Jennifer Friedauer 等CHI 2024 · 被引用 19 次
- "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber InsuranceRachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins 等S&P 2025
