Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment
October 27, 2022 Β· Declared Dead Β· π IEEE Transactions on Dependable and Secure Computing
"No code URL or promise found in abstract"
Evidence collected by the PWNC Scanner
Authors
Kevin Hu, Retsef Levi, Raphael Yahalom, El Ghali Zerhouni
arXiv ID
2210.15785
Category
q-fin.RM
Cross-listed
cs.CR
Citations
1
Venue
IEEE Transactions on Dependable and Secure Computing
Last Checked
3 months ago
Abstract
This paper provides the first large-scale data-driven analysis to evaluate the predictive power of different attributes for assessing risk of cyberattack data breaches. Furthermore, motivated by rapid increase in third party enabled cyberattacks, the paper provides the first quantitative empirical evidence that digital supply-chain attributes are significant predictors of enterprise cyber risk. The paper leverages outside-in cyber risk scores that aim to capture the quality of the enterprise internal cybersecurity management, but augment these with supply chain features that are inspired by observed third party cyberattack scenarios, as well as concepts from network science research. The main quantitative result of the paper is to show that supply chain network features add significant detection power to predicting enterprise cyber risk, relative to merely using enterprise-only attributes. Particularly, compared to a base model that relies only on internal enterprise features, the supply chain network features improve the out-of-sample AUC by 2.3\%. Given that each cyber data breach is a low probability high impact risk event, these improvements in the prediction power have significant value. Additionally, the model highlights several cybersecurity risk drivers related to third party cyberattack and breach mechanisms and provides important insights as to what interventions might be effective to mitigate these risks.
Community Contributions
Found the code? Know the venue? Think something is wrong? Let us know!
π Similar Papers
In the same crypt β q-fin.RM
R.I.P.
π»
Ghosted
R.I.P.
π»
Ghosted
Sequential Deep Learning for Credit Risk Monitoring with Tabular Financial Data
R.I.P.
π»
Ghosted
Explainable AI for Interpretable Credit Scoring
R.I.P.
π»
Ghosted
Preference Elicitation and Robust Optimization with Multi-Attribute Quasi-Concave Choice Functions
R.I.P.
π»
Ghosted
Leveraging Convolutional Neural Network-Transformer Synergy for Predictive Modeling in Risk-Based Applications
R.I.P.
π»
Ghosted
Advanced Risk Prediction and Stability Assessment of Banks Using Time Series Transformer Models
Died the same way β π» Ghosted
R.I.P.
π»
Ghosted
Federated Learning: Strategies for Improving Communication Efficiency
R.I.P.
π»
Ghosted
In-Datacenter Performance Analysis of a Tensor Processing Unit
R.I.P.
π»
Ghosted
Deep Convolutional Neural Networks for Computer-Aided Detection: CNN Architectures, Dataset Characteristics and Transfer Learning
R.I.P.
π»
Ghosted