<p>The sharing of security information among firms to improve their defense against hackers is usually encouraged by government departments and industry associations. However, there exists a negative impact of facilitating the learning of hackers to reduce attack costs. Besides, due to the existence of user inconvenience, a high defense level will bring a high inconvenience penalty to firms. Such impacts and penalties under different hacker attack regimes have not received attention in the literature. This paper constructs a game-theoretic model between two competitive firms and one hacker to examine the impacts of security information sharing and inconvenience penalty under different attack modes. We first find that even though the sharing of security information can improve defense level, security information should be shared moderately. The improved defense level can bring inconvenience on users and thus a penalty on firms, but this inconvenience penalty, we next show, may help alleviate the competition in security investment and benefit each firm under random attacks. Then, we reveal that the effects of security elements remain almost unchanged from random attacks to targeted attacks. We find that firms may suffer less and hackers may benefit less under targeted attacks even though they are widely deemed to be more harmful than random attacks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Should sharing security information be always encouraged between competitive firms?

  • Yi Ding,
  • Xing Gao,
  • Manting Qiu

摘要

The sharing of security information among firms to improve their defense against hackers is usually encouraged by government departments and industry associations. However, there exists a negative impact of facilitating the learning of hackers to reduce attack costs. Besides, due to the existence of user inconvenience, a high defense level will bring a high inconvenience penalty to firms. Such impacts and penalties under different hacker attack regimes have not received attention in the literature. This paper constructs a game-theoretic model between two competitive firms and one hacker to examine the impacts of security information sharing and inconvenience penalty under different attack modes. We first find that even though the sharing of security information can improve defense level, security information should be shared moderately. The improved defense level can bring inconvenience on users and thus a penalty on firms, but this inconvenience penalty, we next show, may help alleviate the competition in security investment and benefit each firm under random attacks. Then, we reveal that the effects of security elements remain almost unchanged from random attacks to targeted attacks. We find that firms may suffer less and hackers may benefit less under targeted attacks even though they are widely deemed to be more harmful than random attacks.