When information improves information security. (Short paper). (English)
Sion, Radu (ed.), Financial cryptography and data security. 14th international conference, FC 2010, Tenerife, Canary Islands, January 25‒28, 2010. Revised selected papers. Berlin: Springer (ISBN 978-3-642-14576-6/pbk). Lecture Notes in Computer Science 6052, 416-423 (2010).
Summary: This paper presents a formal, quantitative evaluation of the impact of bounded-rational security decision-making subject to limited information and externalities. We investigate a mixed economy of an individual rational expert and several naïve near-sighted agents. We further model three canonical types of negative externalities (weakest-link, best shot and total effort), and study the impact of two information regimes on the threat level agents are facing.