DOC PREVIEW
UW CSEP 590 - Lecture Notes

This preview shows page 1-2-3-4-5-6 out of 18 pages.

Save
View full document
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience
Premium Document
Do you want full access? Go Premium and unlock all 18 pages.
Access to all documents
Download any document
Ad free experience

Unformatted text preview:

Economics and computer securityOutlineAssignment of liabilityLeast cost avoiderDue care standardComputer securityExample: ATM machinesResult of ATM liability assignmentRole of insuranceWhy do corporations buy insurance?ExamplesInsurance: moral hazardAdverse selectionInfrastructure as public goodPrivate or public?CostsTotal effort v weakest linkWhy systems fail?Economics and computer securityHal R. VarianUC Berkeleyhttp://www.sims.berkeley.edu/~hal01/14/19 2Outline•Assignment of liability•Role of insurance•Efficiency and coordination costs•Implications of weakest link technology01/14/19 3Assignment of liability•Want to reduce expected cost of accidents–Parties can affect the probability of accidents happening–Want to set up incentives to get the right parties invest effort in reducing expected costs of accidents–Liability: who has to pay and how much if accident occurs. Sets incentives to reduce expected costs.•Basic principles–Least cost avoider: assign liability to the party that is best positioned to reduce expected costs–Due care standard: set a due care standard, no liability if you meet the due care standard, otherwise pay accident cost01/14/19 4Least cost avoider•ECost = Prob(e1+e2) A – c1 e1 – c2 e2–ECost = expected cost–Prob(e1+e2) = prob accident occurs–A = cost of accident/event–e1, e2 = effort to reduce prob of accident–c1, c2 = cost of effort•Observe: you want the party with the lowest effort cost to exert all the effort•This drives the other party’s effort to zero, but that’s OK in this case01/14/19 5Due care standard•EC = Prob(e1,e2) A – c1 e1 – c2 e2–Find efforts that minimize expected costs, (e1*,e2*) –Set due care standards equal to this effort level–No liability if you meet due care standard–Otherwise, pay fine equal to cost A if accident occurs–See Steven Shavell, Economic Analysis of Accident Law01/14/19 6Computer security•Sometimes the effort cost is so extreme (e.g., technical knowledge) that liability goes to one party•Other times due care standard is plausible–Due care standard determined by courts, but guided by industry practices–Could be very important role for security community–Better to be proactive than just let these standards evolve–Should there be a FASB-like board?01/14/19 7Example: ATM machines•Ross Anderson: “Why cryptosystems fail”•Suppose there is a dispute between you and your bank about your ATM usage–England: bank is right unless you can prove them wrong–US: you are right unless the bank can prove you wrong•Two different default assignments of liability01/14/19 8Result of ATM liability assignment•US: banks invest in risk reduction technology•England: banks typically do not invest in such technology•Credit card and phone card risk management•Role of competition: debit cards01/14/19 9Role of insurance•Two major risk management institutions–Stock market–Insurance market•Why do corporations buy insurance?–Value of shares depend on portfolio value–Shareholders can diversify risk themselves–Particularly good question in case of computer security01/14/19 10Why do corporations buy insurance?•Answer: risk management services•Insurance companies are well placed to–recommend actions–require compliance–disseminate best practices–insurance contract is incentive compatible!•Especially valuable services for rare events01/14/19 11Examples•Expert certification–Year 2000 problem•Could do more–CERT patches requirement for insurance–SATAN test•Prediction–insurance companies will move into computer security (supplemented by expert advisors)01/14/19 12Insurance: moral hazard•Want the insured to bear some risk–full insurance has bad incentives–deductible/co-pay is much better•Want to structure incentives to reduce risk–liability assignments – as discussed–deductible – moral hazard01/14/19 13Adverse selection•Those who need insurance most buy it•Pool that purchases insurance is not representative of entire population•Adverse selection can destroy market–argument for social insurance–e.g., infrastructure protection above and beyond that covered by private incentives01/14/19 14Infrastructure as public good•Private good v public good–excludability–rivalry•Public good aspect to security–national defense ; police services•How to pay for security?–individual or social choice?01/14/19 15Private or public?•Gated communities or private walls?01/14/19 16Costs•Production costs–economies of scale in protection?•Countervailing effects–decision costs: social v private decisions–coordination/complexity management costs–effectiveness of measures–clarity of who is responsible–genetic diversity01/14/19 17Total effort v weakest link•Public goods usually involve total effort•Security often has weakest-link character–makes public good more costly–private incentives•leadership is critical•coordination is critical01/14/19 18Why systems fail?•Ross Anderson paper “Why cryptosystems fail”–http://www.cl.cam.ac.uk/~rja14•What to do about human failure?–get incentives right (e.g., liability assignments)–outside monitors and auditors (insurance)–follow procedures (banking)–standards setting role of military (e.g.,


View Full Document

UW CSEP 590 - Lecture Notes

Documents in this Course
Sequitur

Sequitur

56 pages

Sequitur

Sequitur

56 pages

Protocols

Protocols

106 pages

Spyware

Spyware

31 pages

Sequitur

Sequitur

10 pages

Load more
Download Lecture Notes
Our administrator received your request to download this document. We will send you the file to your email shortly.
Loading Unlocking...
Login

Join to view Lecture Notes and access 3M+ class-specific study document.

or
We will never post anything without your permission.
Don't have an account?
Sign Up

Join to view Lecture Notes 2 2 and access 3M+ class-specific study document.

or

By creating an account you agree to our Privacy Policy and Terms Of Use

Already a member?