详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
Information security is an urgent problem for all kinds of organizations all over the world. Information security is not just a research field of technology, but a systematical engineering of technology, management and law. Information security investment problem is the research field of management. The distinct characteristic of information security investment is strategy interdependence, and strategy interdependence is just the basic characteristic of Game Theory. This doctoral dissertation has made scientific researches on information security problem based on game theory, and provides new methods to solve information security problem for organizations.
     This doctoral dissertation analyzes information security investment decision problem of the organizations by finite strategy game first, then analyzes the investment quantity of information security by infinite strategy game. Also, in view of bounded rationality and the need to predict the long-term stable trend, this doctoral dissertation studies information security investment under defenders game and attacker-defender game by evolutionary game theory. The main works are as follows:
     1. The finite strategy game analysis method of information security investment decision for organizations is proposed, and it provides the decision support for the correct information security investment. The information security investment decision game model is set up based on payoff matrix, and this game model contains all the value benefits of information security investment including the direct value benefits of preventing information security disaster and the indirect value benefits such as improving brand value and organization reputation. For information security investment decision game model between two organizations, the contrast of pure strategies and mixed strategies Nash Equilibrium shows the consistency of two analyses. In addition, when the information security investment cost is relatively high, the introduction of penalty parameter can achieve ideal Nash Equilibrium again. The example illustrates the information security investment game of two organizations. For the information security investment game model among organizations, the factors influencing cost threshold are discussed, and two propositions of information security investment are brought forward. The necessary conditions to achieve the equilibrium of investment are deduced, and the simulation analysis is made.
     2. The infinite strategy game analysis method of information security investment quantity for organizations is proposed, and it provides scientific reference for the proper investment quantity of information security. Insufficient investment of information security can not ensure enough security, and overabundant of investment induces the waste, so it is necessary to analyze the proper investment quantity of information security. The information security investment quantity game model is set up based on the strategy independence, and the relation parameter in the model reflects the game relation of the two organizations. According to the different value of the relation parameter, the equilibrium analysis is made based on reaction function method. In particular, for the attack-defence game, the correlation proposition of the defender's equilibrium cost and the relation parameter is set up, and verified by the simulation. The example illustrates the investment quantity game analysis.
     3. The evolutionary game analysis methods of information security investment under defenders game and attacker-defender game are proposed, solve the hard problem of bounded rationality of information security investment subject, and predict the long-term stable trend of information security investment. In view of the bounded rationality of information security investment subject in the real world and the need to predict the long-term stable trend of information security investment, the evolutionary game researches of information security investment under defenders game and attacker-defender game are made in order to strengthen the reality basis of information security investment game. In the evolutionary game analysis of information security investment under defenders game, based on the evolutionary game model of information security investment, Evolutionary Stable Strategy is analyzed by Replicator Dynamics. The REPAST simulation on the multi-agent platform verifies the Evolutionary Stable Strategy. For the evolutionary game of information security investment under attacker-defender game, the attacker-defender game model of information security is set up, and the Replicator Dynamics and Evolutionary Stable Strategy are analyzed. The law and long-term stable trend of attack and defence are studied based on the relation of Replicator Dynamics of the attacker colony and Replicator Dynamics of the defender colony. The research results explain the circle of attack and defence in information security, and put forward the strategy suggestions to settle information security problem.
     This doctoral dissertation has made scientific researches on information security problem for organizations from the new angle of game theory, explored the hard problem of information security investment, and achieved some innovative research results. This doctoral dissertation has important theoretical significance for this new research field, and also has important practical significance to reduce the blindness of the investment, and to direct information security investment scientifically.
    [5]Whitman,Michael E.Enemy at the gate:Threats to information security.Communications of the ACM,2003,46(8):91-95.
    [6]Ross Anderson.Why Information Security is Hard——An Economic Perspective.Proceedings of 17th Annual Computer Security Applications Conference,IEEE Computer Society,2001.
    [7]Fudenberg D,Tirole J.Game Theory.USA:MIT Press,1991.
    [8]Aumann R.On the centipede game.Games and Economic Behavior,1998,23(1):97-105.
    [9]Aumann R.Backward induction and common knowledge of rationality.Games and Economic Behavior,1995,8(1):6-19.
    [10]Aumann R,Michael Maschler.Game theoretic analysis of a bankruptcy problem from the Taimud.Journal of Economic Theory,1985,36(2):195-213.
    [11]Aumann R.Rationality and bounded rationality.Games and Economic Behavior,1997,21(1-2):2-14.
    [12]Schelling T.Intergenerational discounting.Energy Policy,1995,23(4-5):395-401.
    [13]Schelling T.Global environmental forces.Technological Forecasting and Social Change,1990,38(3):257-264.
    [16](美) 约翰·纳什著.张良桥,王晓刚译.纳什博弈论论文集.北京:首都经济贸易大学出版社.2000.
    [17]Harsanyi J.A newtheory of equilibrium selection for games with complete information.Games and Economic Behavior,1995,8(1):91-122.
    [18]Harsanyi J.A new theory of equilibrium selection for games with incomplete information.Games and Economic Behavior,1995,10(2):318-332.
    [19]Harsanyi J.Solutions for some bargaining games under the Harsanyi-Selten solution theory,part Ⅰ:Theoretical preliminaries.Mathematical Social Sciences,1982,3(2):179-191.
    [20] Harsanyi J. Solutions for some bargaining games under the Harsanyi-Selten solution theory, part II Analysis of specific bargaining games. Mathematical Social Sciences, 1982,3(3): 259-279.
    [21] Selten R, Wooders M. Cyclic games: an introduction and some examples. Games and Economic Behavior, 2001, 34(1): 138-152.
    [22] Selten R, Ockenfels A. An experimental solidarity game. Journal of Economic Behavior & Organization, 1998, 34(4): 517-539.
    [23] Selten R. Evolutionary stability in extensive two-person games. Mathematical Social Sciences, 1983, 5(3): 269-363.
    [24] Ockenfels A, Selten R. Impulse balance equilibrium and feedback in first price auctions. Games and Economic Behavior, 2005, 51(1): 155-170.
    [25] Wooders M, Cartwright E, Selten R. Behavioral conformity in games with many players. Games and Economic Behavior, 2006, 57(2): 347-360.
    [26] Mirrlees J. Optimal tax theory: a synthesis. Journal of Public Economics, 1976, 6(4): 327-358.
    [27] 谢识予. 经济博弈论. 上海:复旦大学出版社, 2004.
    [28] Hamilton S, Miller W, Ott A, Saydjari S. The Role of Game Theory in Information Warfare. In 4th Information survivability workshop (ISW-2001/2002), Vancouver, Canada, 2002.
    [29] Ryan J, Ryan D. Expected benefits of information security investment. Computers & Security. 2006, 25: 579-588.
    [30] Rodewald G. Aligning Information Security Investments with a Firm's Risk Tolerance. 2nd Annual Conference on Information Security Curriculum Development, Georgia, 2005: 139-141.
    [31] Rok B, Borka J. Standard Approach for Quantification of the ICT Security Investment for Cybercrime Prevention. Second International Conference on the Digital Society, Sainte Luce, 2008: 7-14.
    [32] Sonnenreich W. Return on Security Investment(ROSI): A Practical Quantitative Model. Journal of Research and Practice in Information Technology. 2006, 38(1): 55-66.
    [33] Locher C. Methodologies for Evaluating Information Security Investments-What Basel Two Can Change in the Financial Industry. 13th European Conference on Information Systems, Germany, 2005.
    [34] Wang Z, Song H. Towards and optimal information security investment strategy. IEEE International Conference on Networking, Sensing and Control, China, 2008: 756-761.
    [35] Baker W, Rees L, Tippett P. Metric-driven information security risk assessment and decision making. Communications of The ACM. 2007, 50(10): 101-106.
    [36] Piper J. Security Risk Management and Investment Decisions. http://www. fpri. org/pubs/200612. piper. securityriskmanagementinvestment. pdf, 2006.
    [37]Huang C,Hu Q,Behara R.An economic analysis of the optimal information security investment in the case of a risk-averse firm.International Journal of Production Economics.2008,114:793-804.
    [38]Mercuri R.Analyzing Security Costs.Communications of The ACM.2003,46(6):15-18.
    [39]Huang C,Hu Q,Behara R.Economics of Information Security Investment in the Case of Simultaneous Attacks.The Fifth Workshop on the Economics of Information Security,England,2006.
    [40]Mizzi A.Return on Information Security Investment.http://www.infosecwriters.com/text_resources/pdf/ROISI.pdf,2005.
    [41]Cremonini M,Nizovtsev D.Understanding and influencing attackers' Decisions:Implications for Security Investment Strategies.Fifth Workshop on the Economics of Information Security,England,2006.
    [42]Duffany J.Optimal resource allocation for securing an enterprise information infrastructure.The 4th international IFIP/ACM Latin American conference on Networking,Costa Rica,2007:35-42.
    [43]Kim Sangkyun,Lee H.Cost-Benefit Analysis of Security Investment:Methodology and Case Study.International Conference on Computational Science and its Applications,Singapore,2005:1239-1248.
    [44]Buck K,Hanf D.Applying ROI Analysis to Support SOA Information Security Investment Decisions.IEEE International Conference on Technologies for Homeland Security,Greater Boston,2008:359-366.
    [45]Gordon L,Loeb M.The Economics of Information Security Investment.ACM Transactions on Information and System Security,2002,5(4):438-457.
    [46]Bodin L,Gordon L,Loeb M.Evaluating Information Security Investments Using the Analytic Hierarchy Process.Communicatoins of The ACM.2005,48(2):79-83.
    [47]Gordon L,Loeb M.Budgeting Process for Information Security Expenditures.Communicatoins of The ACM.2006,49(1):121-125.
    [48]Hausken K.Returns to information security investment:The effect of alternative information security breach functions on optimal investment and sensitivity to vulnerability.Information Systems Frontiers,2006,8:338-349.
    [49]Willemson J.On the Gordon&Loeb Model for Information Security Investment.The Fifth Workshop on the Economics of Information Security,England:University of Cambridge,2006.
    [52] Farahmand F, Navathe S, Sharp G et al. Evaluating Damages Caused by Information Systems Security Incidents. 2nd Workshop on Economics and Information Security, Berkeley, 2003.
    [53] Adkins R. An Insurance Style Model for Determining the Appropriate Investment Level against Maximum Loss arising from an Information Security Breach. 3rd Workshop on Economics and Information Security, Berkeley, 2004.
    [54] Schechter S. Toward Econometric Models of the Security Risk from Remote Attacks. 3rd Workshop on Economics and Information Security, Berkeley, 2004.
    [55] Kannan K, Telang R. An Economic Analysis of Market for Software Vulnerabilities. 3rd Workshop on Economics and Information Security, Berkeley, 2004.
    [56] Gehring R. Softwawre Development, Intellectual Property Rights, and IT Security. 1st Workshop on Economics and Information Security, Berkeley, 2002.
    [57] Feigenbaum J, Freedman M, Sandre T et al. Economic Barriers to the Deployment of Existing Privacy Technologies. 1st Workshop on Economics and Information Security, Berkeley, 2002.
    [58] Acquisti A, Grossklags J. An Experimental Approach to Information Security Attitudes and Behavior. 2nd Workshop on Economics and Information Security, Berkeley, 2003.
    [59] Gal E, Ghose A. The Economic Consequences of Sharing Security Information. 2nd Workshop on Economics and Information Security, Berkeley, 2003.
    [60] Cavusoglu H, Cavusoglu H, Zhang J. Economics of Security Patch Management. Workshop on Economics and Information Security, Berkeley, 2006.
    [61] Gupta A, Zhdanov D. Growth and Sustainability of Managed Security Services Networks: An Economic Perspective. Workshop on Economics and Information Security, Berkeley, 2007.
    [62] Honeyman P. Interdependence of Reliability and Security. Workshop on Economics and Information Security, Berkeley, 2007.
    [63] Acohido B, Berinato S, Grow B. Communicating Security-The Role of Media: A Journalistic Perspective. Workshop on Economics and Information Security, Berkeley, 2008.
    [64] Desmedt Y. Using economics to model theats and security in distributed computing. 1st Workshop on Economics and Information Security, Berkeley, 2002.
    [65] Bergemann D, Feigenbaum J. Towards an Economic Analysis of Trusted Systems. 3rd Workshop on Economics and Information Security, Berkeley, 2004.
    [66] Rowe B. Will Outsourcing IT Security Lead to a Higher Social Level of Security? Workshop on Economics and Information Security, Berkeley, 2007.
    [67] Cachon G, Zipkin P. Competitive and Cooperative Inventory Policiesin a Two stage Supply Chain. Management Science, 1999, 45(7): 936-953.
    [68] Chen F, Federgruen A, Zheng Y. Near optimal Pricing Replenishment Strategies for a Retail distribution System. Operation research, 2001, 49(6): 839-853.
    [69]Sterman J.Modeling Managerial Behavior:Misperceptions of Feed back in a Dynamic Decision Making Experiment.Management Science,1989,35(3):321-339.
    [70]Chen F.Decentralized Supply Chains Subject to Information Delays.Management Science,1999,45(8):1076-1090.
    [71]Kimbrough S,WuD,Zhong F.Computers Play the Beer Game:Can Artificial agents Manage Supply Chains? Decision Support Systems,2002,33:323-333.
    [72]Cachon G,Lariviere M.Contracting to Assure Supply:How to Share Demand Forecasts in a Supply Chain.Management Science,2001,47(5):629-646.
    [73]Van J.Coordinating Investment,Production and Subcontracting.Management Science,1999,45(7):954-971.
    [74]Huang Z.Co-op Advertising Models in Manufacture retailer Supply Chains:A Game Theory Approach.European Journal of Operational Research,2001,135:527-544.
    [75]Brandenburger,Stuart A,Jr H.Value-Based Business Strategy.Journal of Economic Management Strategy,1996,5(1):52-54.
    [79]Thijssen J,Huisman K.Strategic Investment under Uncertainty and Information Spillovers:[dissertation].Tilburg:Tilburg University,2001.
    [80]Grenadier,Steven R.Option Exercise Games:An Application to the Equilibrium Investment Strategies of Firms.Review of Financial Studies,2002,15(3):691-721.
    [81]Pauli M,Keppo J.A Game model of Irreversible Investment Under Uncertainty.International Game Theory Review,2002,4(2):127-140.
    [82]Dean P,Pinto H.Competition Games in Duopoly Settings with Two Stochastic Factors.Working Paper,2003.
    [83]Smit H,Trigeorgis L.R&D Option Strategies.Working Paper,1997.
    [84]Kulatilaka,Nalin,Enrico C,Perotti.Strategic Growth Options.Management Science,1998,44(8):1021-1031.
    [88]Black F.The Dividend Puzzle.Journal of Portolio Management,1976,634-639.
    [89]Bhattacharyao S.Imperfact information Divident Policy and the bird in the Hand Fallacy.Bell Journal of Economic,1979,10(1):259-270.
    [90]Ross S.The Ditermination of Financial Structure:The incentive Signalling Approach.Bell Journal of Economica,1977,8(1):23-40.
    [91]Jesen,Meckling W.Theory of the Firm Managerial Agency Costs san Capital Structure.Journal of Financial Economics,1976,3(4):305-360.
    [92]Myers S,Majlfu.Corporate Financial and Investment Decisions When Firms Have information that investors do not Have.Journal of Financial Economics,1987,13(2):187-221.
    [93]Aoki,Masahiko.A model of the firm as a stockholder-employee cooperative game.American Economic Review,1980,70(4):600-610.
    [98]Singh H.Introduction to Game Theory and Its Application in Electric Power Markets.IEEE Computer Applications in Power,1999,12(4):18-20.
    [100]Wen E,David S.Oligopoly electricity market production under incomplete information.IEEE Power Engineering Review,2001,21(4):58-61.
    [101]Haili S,Chen-Ching L.Hash Equilibrium Bidding Strategies in a Bilateral Electricity Market.Transactions on Power Systems,2002,17(1):73-79
    [108]Cavusoglu H,Mishra B,Raghunathan S.A Model for Evaluating IT Security Investments.Communications of the ACM,2004,47(7):87-92.
    [109]Kunreuther H,Heal G.Interdependent Security.Journal of Risk and Uncertainty,2003,26(2-3):231-249.
    [110]Varian n.System Reliability and Free Riding.Working paper,Economics of Information Security,University of California,Berkeley,CA.2004.
    [111]Tanaka H,Matsuura K,Sudoh O.Yulnerabilityand information security investment:An empirical analysis of e-local government in Japan.Journal of Accounting and Public Policy,2005,24(1):37-59.
    [112]Grossklags J,Christin N,Chuang J.Secure or Insure? A Game-Theoretic Analysis of Information Security Games.Proceedings of the 17th International World Wide Web Conference,China,2008:209-218.
    [113]Jiang L,Anantharam V,Walrand J.Efficiency of Selfish Investment in Network Security.Proceedings of the 3rd international workshop on Economics of networked systems,USA,2008:31-36.
    [117]Nash J.Equilibrium points in N-person games.Proceedings of the National Academy of Science of the United States of America,1950,36:48-49.
    [118]Nash J.Non-cooperative games.Annals of Mathematics,1951,54:286-295.
    [119]Nash J.The bargaining problem.Econometrica,1950,18:155-162.
    [120]Nash J.Two person cooperative games.Econometrica,1953,18:155-162.
    [122]Shapley L.Contributions to the Theory of Games.Princeton:Princeton University Press,1953.
    [123]Selten R.Spieltheoretische Behandlung eines Oligopolmodells mit Nachfagetragheit.Xeitschrift fur die gesamte Staatswissenschaft,1965,12:301-324.
    [124]Selten R.Re-examinnation of the Perfectness Concept for Equilibrium Points in Extensive Games.International Journal of Game,1975,4:25-55.
    [125]Harsanyi J.Games with incomplete information played by Bayesian players.Management Science,1967,14:489.
    [126]Harsanyi.Game with randomly disturbed payoffs:a new rationale for mixed strategy equilibrium points.International Journal of Game Theory,1973,2:1-23.
    [130]Smith M.The theory of Games and the evolution of animal conflicts.Journal of Theoretical Biology,1973,47:209-221.
    [131]Kreps D,Wilson R.Reputation and imperfect information.Journal of Economic Theory,1982,27:179-253.
    [133]Putnam R.Diplomacy and domestic politics:the logic of two-level games.International Organization,1988,42(4):427-460.
    [134]Smith M.Evolution and the theory of game.England:Cambridge University Press,1982.
    [141]Neubauer T,Klemen M,Biffl S.Business Process-based Valuation of IT-Security.ACM SIGSOFT Software Engineering Notes,2005,30(4):1-5.
    [142]Osborne M,Rubinstein A.A Course In Game Theory.Beijing:China Social Sciences Press,2000.
    [143]Varian H.System reliability and free riding.Working paper,Economics of Information Security,Berkeley:University of California,2004.
    [144]Nash J.Non-Cooperative Games:[dissertation].NewJersey:Princeton University,1950.
    [145]Weibull J.Evolutionary Game Theory.Cambridge:MIT Press,1995.
    [146]Maynard S.The Theory of Games and the Evolution of Animal Conflict.Journal of Theory Biology,1973,47(1):209-221.
    [147]Maynard S,Price G.The Logic of Animal Conflicts.Nature,1973,246(5427):15-18.
    [148]Kosfeld M.Why Shops Close Again:An Evolutionary Perspective on the Deregulation of Shopping Hours.European Economic Review,2002,46(1):51-72.
    [149]Bester H,Guth W.Is Altruism Evolutionarily Stable.Journal of Economic Behavior &Organization,1998,34(2):193-209.
    [150]Skyrms,Brian.Deliberational Equilibria.Topoi,1986,5(1):59-67.
    [151]Friedman D,Fung K.International Trade and the Internal Organization of Firms:An Evolutionary Approach.Journal of International Economics,1996,41(1-2):113-137.
    [152]Friedman D.Evolutionary Games in Economics.Econometrica,1991,59(2):637-666.
    [154]Taylor P D,Jonker L B.Evolutionarily Stable Strategies and Game Dynamics.Mathematical Bioscience,1978,40:145-156.
    [155]Borgers T,Sarin R.Learning through Reinforcement and Replicator Dynamics.Journal of Economic Theory,1997,77(1):1-14.
    [159]Holland J.Emergence from chaos to order.California:Addison-Wesley Publishing Company,1998.
    [160]Holland J.Hidden order how adaptation builds complexity.California:Addison-Wesley Publishing Company,1995.
    [161]Standish R.On complexity and emergence,High Performance Computing Support Unit University of New South Wales[EB].http://parallel.hpc.unsw.edu.ar/rks.
    [171]Swarm Development Group.A Tutorial Introduction to Swarm[EB].http://www.swarm.org/csss-tutorial/frames.html.
    [173]Tobias R,Hofmann C.Evaluation of Free Java-libraries for Social-scientific Agent Based Simulation.Journal of Artificial Societies and Social Simulation,2004,7(1):1-33.
    [175]North M,Collier N,Vos J.Experiences Creating Three Implementations of the Repast Agent Modeling Toolkit.ACM Transactions on Modeling and Computer Simulation,2006,16(1):1-25.
    [177]StarLogo on the web.http://education.mit.edu/starlogo/[EB].
    [178]TNGLab Overview.http://www.econ.iastate.edu/tesfatsi/tnghome.htm[EB].

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700