Preventing organizations from Cyber exploits needs timely intelligence about Cyber vulnerabilities and attacks, referred as threats. Cyber threat intelligence can be extracted from various sources including social media platforms where users publish the threat information in real time. Gathering Cyber threat intelligen…
Study finds stocks with higher cyber risk scores outperform others, indicating a market-wide cyber risk premium.
problem Identifying and quantifying firms' cyber risks and their impact on stock performance.
method Machine learning algorithm to analyze disclosures and a dedicated cyber corpus.
result High cyber risk stocks significantly outperform others, indicating a market-wide cyber risk premium.
TinyML models detect RF and cyber threats in spacecraft with low latency.
problem Detecting cyber-RF threats in autonomous spacecraft with low latency.
method Analysis of classical models (RF, LR, SVM, MLP) for latency-accuracy trade-offs.
result Logistic Regression achieves microsecond-level inference with minimal accuracy loss.
Recent changes to greenhouse gas emission policies are catalyzing the electric vehicle (EV) market making it readily accessible to consumers. While there are challenges that arise with dense deployment of EVs, one of the major future concerns is cyber security threat. In this paper, cyber security threats in the form o…
We present a new machine learning and text information extraction approach to detection of cyber threat events in Twitter that are novel (previously non-extant) and developing (marked by significance with respect to similarity with a previously detected event). While some existing approaches to event detection measure …
The paper uses a simulator and optimisation to defend against cyber threats.
problem Defending against cyber threats in simulated networks.
method Dynamic causal Bayesian optimisation (DCBO) integrated with a cyber security simulator.
result DCBO optimally reduces the cost of intrusions in simulated networks.
This paper surveys ML applications in SG for cyberattacks.
problem Cyberattacks in smart grid due to advanced technologies.
method Comprehensive review of existing research in cyberattacks detection and mitigation.
result Machine learning is effective in detecting and mitigating cyberattacks.
Paper models cloud outages for cyber insurance stress-testing.
problem Cyber insurance portfolios' vulnerability to simultaneous cloud outages.
method Modeling and calibrating cloud-outage scenarios, measuring diversification.
result Cloud-outage diversification can protect against accumulation risk.
Study examines cyber losses across sectors, finds high severity and frequency.
problem Understanding the nature of cyber losses and their variability across sectors.
method Analysis of a leading industry dataset of cyber events, focusing on frequency and severity.
result Cyber risks are heavy-tailed, with high probability of extreme losses.
Research shows filtering reduces predictability of cyber-attacks.
problem Predicting cyber-attacks from incomplete data.
method Combining external data with machine learning algorithms to learn indicators of cyber-attacks.
result The process of filtering reduces the predictability of cyber-attacks.
Cyber attacks are growing in frequency and severity. Over the past year alone we have witnessed massive data breaches that stole personal information of millions of people and wide-scale ransomware attacks that paralyzed critical infrastructure of several countries. Combating the rising cyber threat calls for a multi-p…
The use of machine learning and intelligent systems has become an established practice in the realm of malware detection and cyber threat prevention. In an environment characterized by widespread accessibility and big data, the feasibility of malware classification without the use of artificial intelligence-based techn…
Paper tackles cyber threats to PHM systems using adversarial examples.
problem Vulnerability of IoT sensors and DL algorithms to cyber attacks.
method Adopted adversarial example crafting techniques from computer vision to PHM domain.
result PHM models are vulnerable to adversarial attacks, leading to inaccurate remaining useful life estimation.
This paper optimizes cybersecurity resource allocation in networks with heterogeneous attacker and defender valuations.
problem Optimizing cybersecurity resource allocation in networks with heterogeneous attacker and defender valuations.
method Combining strategic behavior of players with contagion dynamics, a method is extended to determine optimal resource allocation based on simple network metrics weighted by risk profiles.
result The asymmetry between attacker and defender valuations drives optimal attack and defense strategies, shaping system resilience.
This paper maps the insurability of AI risks across various insurance products.
problem Emerging AI risks and their implications for insurance coverage.
method Coding 55 AI threat classes against 26 insurance products using public carrier materials and threat catalogs.
result Identification of a four-tier insurability frontier: affirmatively insured, silent-AI exposures, actively excluded, and unstructured perils.
The exponential increase in dependencies between the cyber and physical world leads to an enormous amount of data which must be efficiently processed and stored. Therefore, computing paradigms are evolving towards machine learning (ML)-based systems because of their ability to efficiently and accurately process the eno…
Intrusion detection systems (IDSs) generate valuable knowledge about network security, but an abundance of false alarms and a lack of methods to capture the interdependence among alerts hampers their utility for network defense. Here, we explore a graph-based approach for fusing alerts generated by multiple IDSs (e.g.,…
Paper studies autoencoder-based anomaly detectors' robustness to adversarial poisoning attacks.
problem Adversarial poisoning attacks on online-trained autoencoder-based anomaly detectors in ICSs.
method Proposes two algorithms for generating poison samples and evaluates them on synthetic and real-world ICS data.
result Autoencoder detectors are resilient to poisoning in the face of all relevant attacks in the SWaT dataset.
This work develops agents to learn generalizable policies for dynamic network environments.
problem Real-world network topologies change due to attackers, defenders, or system failures, leading to failures in adaptive ACD systems.
method Developing agents to learn generalizable policies across dynamic network environments.
result Agents can learn robust policies for dynamic network topologies and diverse attackers.
Paper analyzes cyber risk classifications for forecasting performance.
problem Lack of effective out-of-sample forecasting performance in current cyber risk classifications.
method Rolling window analysis using threshold weighted scoring functions.
result Dynamic and impact-based cyber risk classifiers outperform others in forecasting future cyber risk losses.
Motivated by the developments in cyber risk treatment in the finance industry, we propose a general framework of cyber bond, whose main purpose is to insure (compensate) losses of a cyber attack. Based on a database of publicly available cyber events, we determine cyber loss distribution parameters and use them to nume…
Develops a Bonus-Malus model for cyber risk insurance to incentivize cybersecurity.
problem Lack of effective insurance strategies to incentivize cybersecurity.
method Proposes a Bonus-Malus model and a mathematical model with a numerical algorithm.
result Demonstrates how a Bonus-Malus system resolves moral hazard and benefits the insurer.
Paper introduces a framework for managing cyber risk with insurance and cybersecurity models.
problem Pervasive challenges in managing cyber risk, especially for capital allocation.
method Combines insurance frequency-severity models with cybersecurity cascade models for comprehensive cyber risk assessment. Facilitates informed capital allocation through a two-pillar framework.
result Demonstrates the necessity of comprehensive cost-benefit analysis for budget-constrained companies.
The paper models and prices cyber insurance risks, distinguishing idiosyncratic, systematic, and systemic risks.
problem Modeling and pricing cyber insurance policies, especially for systemic risks.
method Distinguishes three types of cyber risks and proposes methods for their valuation.
result Complex methods are needed for systemic cyber risks, including risk-neutral valuation and monetary risk measures.
Smart grid is an alternative solution of the conventional power grid which harnesses the power of the information technology to save the energy and meet today's environment requirements. Due to the inherent vulnerabilities in the information technology, the smart grid is exposed to a wide variety of threats that could …
Introduces an artificial cyber lab to test and identify cyber resilience measures.
problem Systemic cyber risks and their control methods.
method Classical contagion models and artificial cyber lab simulations.
result Identified two classes of measures: security- and topology-based interventions.
Study on cyber insurance viability using statistical models.
problem Exploring insurability of cyber risk and its factors.
method Regression models (GAMLSS, ordinal regressions) and utility modelling.
result Provides insights into insurability of cyber risk.
Study finds high cyber risk stocks generate significant excess returns.
problem Understanding and quantifying cyber risk's impact on stock returns.
method Machine learning algorithm measuring cyber risk proximity to a corpus.
result High cyber risk stocks generate an excess return of 18.72% p.a.
The paper examines the feasibility of managing aggregate cyber-risk in IoT environments.
problem Determining sustainable conditions for providing aggregate cyber-risk coverage.
method Developed a rigorous general theory and validated it with real data.
result Conditions for sustainable aggregate cyber-risk management under heavy-tailed distributions.
The scale of Internet-connected systems has increased considerably, and these systems are being exposed to cyber attacks more than ever. The complexity and dynamics of cyber attacks require protecting mechanisms to be responsive, adaptive, and scalable. Machine learning, or more specifically deep reinforcement learning…
Enhances cyber risk assessment with entity-specific features.
problem Lack of high-quality public cyber incident data.
method Develops an InsurTech framework to enrich cyber incident data with entity-specific attributes and implements machine learning models.
result InsurTech features improve prediction robustness and provide customized risk profiles.
A novel model combines deep learning and extreme value theory for multivariate cyber risk prediction.
problem High dimensionality and heavy tails in multivariate cyber risk patterns.
method Combines deep learning for point predictions and extreme value theory for quantile predictions.
result The model provides satisfactory high quantile predictions and accurate point predictions.
Study quantifies model risk in cyber insurance, affecting premium pricing.
problem Model risk and risk sensitivity in cyber insurance pricing.
method Robust estimators for model parameters and dependence analysis.
result Robust estimation improves tail index and joint loss model accuracy.
This paper aims to optimize incident-specific cyber insurance design.
problem Complexity in determining optimal risk retention and transfer.
method Economic foundation for incident-specific cyber insurance with Pareto optimality.
result Illustrates feasibility of designing incident-specific indemnities for both parties.
In recent years numerous advanced malware, aka advanced persistent threats (APT) are allegedly developed by nation-states. The task of attributing an APT to a specific nation-state is extremely challenging for several reasons. Each nation-state has usually more than a single cyber unit that develops such advanced malwa…
This research develops a new model for cyber risk and insurance pricing.
problem Accurate calculation of aggregate losses in cyber insurance pricing.
method A path-based k-generation risk contagion model in a tree-shaped network structure.
result Explicit expressions for mean and variance of local loss on a single path.
This paper discusses adversarial attacks on cyber security systems using machine learning.
problem Adversarial attacks limit the use of machine learning in cyber security.
method Characterizes adversarial attack methods and their applications in cyber security.
result Highlights unique challenges and future research directions for adversarial attacks in cyber security.
We present cyber-security problems of high importance. We show that in order to solve these cyber-security problems, one must cope with certain machine learning challenges. We provide novel data sets representing the problems in order to enable the academic community to investigate the problems and suggest methods to c…
I present a unified discussion of several recently published results concerning the escalation, timing and severity of violent events in human conflicts and global terrorism, and set them in the wider context of real-world and cyber-based collective violence and illicit activity. I point out how the borders distinguish…
CyPhERS provides real-time event info for CPSs, avoiding downtime.
problem Real-time event identification in CPSs is challenging due to complex interdependencies and rare events.
method CyPhERS integrates cyber and physical components, generating event signatures for known and unknown events.
result Event signatures provide relevant and inferable information on both known and unknown event types.
Study shows data breaches cause significant financial losses for firms, especially in health sector.
problem Understanding the economic impact of cyber incidents on listed firms.
method Event study using abnormal returns over 2012-2022, adjusting for event-induced variance and residual cross-correlation.
result Data breaches cause significant financial losses for firms, especially in health sector.
New approach detects cyber-attacks in real-time.
problem Real-time detection of cyber-attacks for effective mitigation.
method Aggregates unsupervised anomaly detection algorithms and incorporates delayed feedback.
result Improves anomaly detection performance through theoretical guarantees.
Framework for managing cyber risks in networks.
problem Managing systemic cyber risks in digital networks.
method Three components: acceptable configurations, risk mitigation interventions, and cost function.
result Effective decision-making for network resilience.
Study detects and mitigates stealthy DDoS attacks in IoT networks.
problem Stealthy DDoS attacks in IoT networks.
method Anomaly-based IDS for timely detection and mitigation.
result Demonstrated capability of detecting and mitigating small attack size per source.
In this paper, we introduce Anomaly Contribution Explainer or ACE, a tool to explain security anomaly detection models in terms of the model features through a regression framework, and its variant, ACE-KL, which highlights the important anomaly contributors. ACE and ACE-KL provide insights in diagnosing which attribut…
Model quantifies cyber-attacks' impact on firms and insurers.
problem Impact of cyber-attacks on firms' revenues and insurers' portfolios.
method Stochastic SIR model coupled with granular firm growth model.
result Predicts insurer needs to compensate up to two days of revenue in a 100-day incident.
The paper shows supply chain features improve cyber risk prediction.
problem Predicting cyber risk from supply chain attributes.
method Machine learning, external supply chain features, AUC improvement.
result Supply chain network features improve AUC by 2.3%.
This work develops secure distributed algorithms for machine learning to protect against data poisoning and network attacks.
problem Vulnerability of distributed machine learning algorithms to cyber threats.
method Game-theoretic framework to capture conflicting goals of a learner and an attacker, iterative distributed algorithm.
result Distributed SVM is prone to fail in different types of attacks, with impact depending on network structure and attack capabilities.