Skip to main navigation Skip to search Skip to main content

An extreme value approach to information technology security investment

  • SUNY Buffalo
  • Bryant University

Research output: Contribution to conferencePaperpeer-review

6 Scopus citations

Abstract

Information technology security investment is receiving increasing attention in recent years. Various methods have been proposed to determine the effective level of security investment. In this paper, we introduce an extreme value approach to address the issues of effective budgeting and investing in IT security. In our model, the security status of a system depends on two factors: system security level, which is measured by the level of security investment, and system attack level, which reflects the security risk with which the system is confronted. Security investment level is endogenous to the system, while attack level is exogenous. Extreme value analysis is used to characterize the stochastic behavior of high-level attacks based on the historical data and to make inferences on future attacks. Based on these inferences, we determine the effective security solutions and the level of security investment to modulate the likelihood of system failure. For illustration purposes, we use an extreme value approach to analyze a set of traffic data collected from a regional bank.

Original languageEnglish
Pages347-359
Number of pages13
StatePublished - 2005
Event26th International Conference on Information Systems, ICIS 2005 - Las Vegas, NV, United States
Duration: Dec 11 2005Dec 14 2005

Conference

Conference26th International Conference on Information Systems, ICIS 2005
Country/TerritoryUnited States
CityLas Vegas, NV
Period12/11/0512/14/05

Keywords

  • Denial of service (DoS)
  • Extreme value theory
  • Information assurance
  • Security investment
  • Two-factor model

Fingerprint

Dive into the research topics of 'An extreme value approach to information technology security investment'. Together they form a unique fingerprint.

Cite this