1st International Workshop on Managing Insider Security Threats | |
Insider Behavior: An Analysis of Decision under Risk | |
Fariborz Farahmand ; Eugene H. Spafford | |
Others : http://CEUR-WS.org/Vol-469/paper2.pdf PID : 11218 |
|
来源: CEUR | |
【 摘 要 】
There is considerable research being conducted on insider threats is directed to developing new technologies. At the same time, existing technology is not being fully utilized because of non-technological issues that pertain to economics and the human dimension. Issues related to how insiders actually behave are critical to ensuring that the best technologies are meeting their intended purpose. In our research, we have investigated accepted models of perceptions of risk and characteristics unique to insider threat, and we have introduced ordinal scales to these models to measure insider perceptions of risk. We have also in- vestigated decision theories, leading to a conclusion that Prospect Theory, developed by Tversky and Kahneman, may be used to describe the risk-taking behavior of insiders and can be accommodated in our model. We discuss the results of validating that model with thirty-five senior information security executives from a variety of organizations. We also discuss how the model may be used to identify characteristics of insiders' perceptions of risk and benefit, their risk-taking behavior and how to frame insider decisions.
【 预 览 】
Files | Size | Format | View |
---|---|---|---|
Insider Behavior: An Analysis of Decision under Risk | 138KB | download |