Morshed: Guiding Behavioral Decision-Makers towards Better Security Investment in Interdependent Systems

11/12/2020
by   Mustafa Abdallah, et al.
0

We model the behavioral biases of human decision-making in securing interdependent systems and show that such behavioral decision-making leads to a suboptimal pattern of resource allocation compared to non-behavioral (rational) decision-making. We provide empirical evidence for the existence of such behavioral bias model through a controlled subject study with 145 participants. We then propose three learning techniques for enhancing decision-making in multi-round setups. We illustrate the benefits of our decision-making model through multiple interdependent real-world systems and quantify the level of gain compared to the case in which the defenders are behavioral. We also show the benefit of our learning techniques against different attack models. We identify the effects of different system parameters on the degree of suboptimality of security outcomes due to behavioral decision-making.

READ FULL TEXT
research
04/04/2020

BASCPS: How does behavioral decision making impact the security of cyber-physical systems?

We study the security of large-scale cyber-physical systems (CPS) consis...
research
01/30/2018

Over-representation of Extreme Events in Decision-Making: A Rational Metacognitive Account

The Availability bias, manifested in the over-representation of extreme ...
research
08/15/2022

Bias amplification in experimental social networks is reduced by resampling

Large-scale social networks are thought to contribute to polarization by...
research
05/16/2018

Dancing Pigs or Externalities? Measuring the Rationality of Security Decisions

Accurately modeling human decision-making in security is critical to thi...
research
04/12/2018

Local reservoir model for choice-based learning

Decision making based on behavioral and neural observations of living sy...
research
02/14/2023

Security Reputation Metrics

Security reputation metrics (aka. security metrics) quantify the securit...
research
11/15/2018

Many Phish in the C: A Coexisting-Choice-Criteria Model of Security Behavior

Normative decision theory proves inadequate for modeling human responses...

Please sign up or login with your details

Forgot password? Click here to reset