Security and insurance management in networks with heterogeneous agents

Jens Grossklags, Nicolas Christin, John Chuang

Research output: Chapter in Book/Report/Conference proceedingConference contribution

28 Scopus citations


Computer users express a strong desire to prevent attacks and to reduce the losses from computer and information security breaches. However, security compromises are common and widespread and highly damaging. Next to attackers' increased sophistication, a root cause for the harm inflicted is that users often fail to optimally protect their resources or to recover gracefully from a security breach. We argue that users often underestimate the strong mutual dependence between their security strategies and the economic environment (e.g., threat model) in which these choices are made and evaluated. This misunderstanding weakens the effectiveness of users' security investments, and is compounded by heterogeneity within the user population, in some cases further reducing incentives for cooperation and coordination. We study how economic agents invest into security in five different economic environments, that are characteristic of different threat models. We consider generalized models of traditional public goods games (e.g., total effort and weakest link) and two recently proposed games (e.g., weakest target game). Agents may split their contributions between a public good (protection) and a private good (self-insurance). Our analysis centers on how agents respond to incentives when important parameters of the game (i.e., loss probability, loss magnitude, and cost of technology) are heterogeneous in the agent population. We also highlight key differences to the case of homogeneous decision makers. For example, security investments may become substantially more sensitive to the size of the network. We extend our results to discuss important modes of intervention.

Original languageEnglish (US)
Title of host publicationEC'08 - Proceedings of the 2008 ACM Conference on Electronic Commerce
Number of pages10
StatePublished - 2008
Event2008 ACM Conference on Electronic Commerce, EC'08 - Chicago, IL, United States
Duration: Jul 8 2008Jul 12 2008

Publication series

NameProceedings of the ACM Conference on Electronic Commerce


Other2008 ACM Conference on Electronic Commerce, EC'08
Country/TerritoryUnited States
CityChicago, IL

All Science Journal Classification (ASJC) codes

  • Software
  • Computer Science Applications
  • Computer Networks and Communications


Dive into the research topics of 'Security and insurance management in networks with heterogeneous agents'. Together they form a unique fingerprint.

Cite this