Protecting shared information in networks: A network security game with strategic attacks. (1st December 2019)
- Record Type:
- Journal Article
- Title:
- Protecting shared information in networks: A network security game with strategic attacks. (1st December 2019)
- Main Title:
- Protecting shared information in networks: A network security game with strategic attacks
- Authors:
- de Witte, Bram
Frasca, Paolo
Overvest, Bastiaan
Timmer, Judith - Other Names:
- Chen Jiming guestEditor.
Gupta Vijay guestEditor.
Quevedo Daniel E. guestEditor.
Tesi Pietro guestEditor. - Abstract:
- Summary: A digital security breach, by which confidential information is leaked, does not only affect the agent whose system is infiltrated but is also detrimental to other agents socially connected to the infiltrated system. Although it has been argued that these externalities create incentives to underinvest in security, this presumption is challenged by the possibility of strategic adversaries that attack the least protected agents. In this paper we study a new model of security games in which agents share tokens of sensitive information in a network of contacts. The agents have the opportunity to invest in security to protect against an attack that can be either strategically or randomly targeted. We show that, in the presence of random attack, underinvestments always prevail at the Nash equilibrium in comparison with the social optimum. Instead, when the attack is strategic, either underinvestments or overinvestments are possible, depending on the network topology and on the characteristics of the process of the spreading of information. Actually, agents invest more in security than socially optimal when dependencies among agents are low (which can happen because the information network is sparsely connected or because the probability that information tokens are shared is small). These overinvestments pass on to underinvestments when information sharing is more likely (and therefore, when the risk brought by the attack is higher). In order to keep our analysisSummary: A digital security breach, by which confidential information is leaked, does not only affect the agent whose system is infiltrated but is also detrimental to other agents socially connected to the infiltrated system. Although it has been argued that these externalities create incentives to underinvest in security, this presumption is challenged by the possibility of strategic adversaries that attack the least protected agents. In this paper we study a new model of security games in which agents share tokens of sensitive information in a network of contacts. The agents have the opportunity to invest in security to protect against an attack that can be either strategically or randomly targeted. We show that, in the presence of random attack, underinvestments always prevail at the Nash equilibrium in comparison with the social optimum. Instead, when the attack is strategic, either underinvestments or overinvestments are possible, depending on the network topology and on the characteristics of the process of the spreading of information. Actually, agents invest more in security than socially optimal when dependencies among agents are low (which can happen because the information network is sparsely connected or because the probability that information tokens are shared is small). These overinvestments pass on to underinvestments when information sharing is more likely (and therefore, when the risk brought by the attack is higher). In order to keep our analysis tractable, some of our results on strategic attacks make an assumption of homogeneity in the network, namely, that the network is vertex‐transitive. We complement these results with an analysis on star graphs (which are nonhomogeneous), which confirms that the essential lines of our findings can remain valid on general networks. … (more)
- Is Part Of:
- International journal of robust and nonlinear control. Volume 30:Number 11(2020)
- Journal:
- International journal of robust and nonlinear control
- Issue:
- Volume 30:Number 11(2020)
- Issue Display:
- Volume 30, Issue 11 (2020)
- Year:
- 2020
- Volume:
- 30
- Issue:
- 11
- Issue Sort Value:
- 2020-0030-0011-0000
- Page Start:
- 4255
- Page End:
- 4277
- Publication Date:
- 2019-12-01
- Subjects:
- large networks -- network externalities -- privacy game -- security game
Automatic control -- Periodicals
Control theory -- Periodicals
Nonlinear systems -- Periodicals
629.836 - Journal URLs:
- http://onlinelibrary.wiley.com/ ↗
- DOI:
- 10.1002/rnc.4794 ↗
- Languages:
- English
- ISSNs:
- 1049-8923
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.538900
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 13322.xml