Heavy-tailed distribution of cyber-risks

From MaRDI portal
Publication:614593

DOI10.1140/EPJB/E2010-00120-8zbMATH Open1202.68057arXiv0803.2256OpenAlexW2591887805MaRDI QIDQ614593FDOQ614593

D. Sornette, T. Maillart

Publication date: 4 January 2011

Published in: The European Physical Journal B. Condensed Matter and Complex Systems (Search for Journal in Brave)

Abstract: With the development of the Internet, new kinds of massive epidemics, distributed attacks, virtual conflicts and criminality have emerged. We present a study of some striking statistical properties of cyber-risks that quantify the distribution and time evolution of information risks on the Internet, to understand their mechanisms, and create opportunities to mitigate, control, predict and insure them at a global scale. First, we report an exceptionnaly stable power-law tail distribution of personal identity losses per event, mPr(mIDlossgeqV)sim1/Vb, with b=0.7pm0.1. This result is robust against a surprising strong non-stationary growth of ID losses culminating in July 2006 followed by a more stationary phase. Moreover, this distribution is identical for different types and sizes of targeted organizations. Since b<1, the cumulative number of all losses over all events up to time t increases faster-than-linear with time according to mathbfsimeqt1/b, suggesting that privacy, characterized by personal identities, is necessarily becoming more and more insecure. We also show the existence of a size effect, such that the largest possible ID losses per event grow faster-than-linearly as simS1.3 with the organization size S. The small value bsimeq0.7 of the power law distribution of ID losses is explained by the interplay between Zipf's law and the size effect. We also infer that compromised entities exhibit basically the same probability to incur a small or large loss.


Full work available at URL: https://arxiv.org/abs/0803.2256





Cites Work


Cited In (21)

Uses Software


Recommendations





This page was built for publication: Heavy-tailed distribution of cyber-risks

Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q614593)