运筹与管理 ›› 2015, Vol. 24 ›› Issue (6): 136-142.DOI: 10.12005/orms.2015.0205

• 应用研究 • 上一篇    下一篇

考虑相互依赖性的信息系统安全投资及协调机制

顾建强, 梅姝娥, 仲伟俊   

  1. 东南大学 经济管理学院,江苏 南京 211189
  • 收稿日期:2013-12-12 出版日期:2015-12-25
  • 作者简介:顾建强(1979-),男,江苏泰州人,博士研究生,研究方向:信息系统安全投资策略及风险管理;梅姝娥(1968-),女,江苏南通人,博士生导师,教授,研究方向:信息安全经济学,决策理论;仲伟俊(1962-),男,江苏南通人,博士生导师,教授,研究方向:信息管理与信息系统。
  • 基金资助:
    国家自然科学基金资助项目(71071033)

Dynamic Coordination Mechanism of Information System Security Investment Based on Interdependent Security

GU Jian-qiang, MEI Shu-e, ZHONG Wei-jun   

  1. School of Economics and Management, Southeast University, Nanjing 211189, China
  • Received:2013-12-12 Online:2015-12-25

摘要: 考虑信息系统安全相互依赖情形下最优化信息系统连续时间安全投资水平是一个值得研究的问题。首先讨论了非合作博弈下信息系统安全投资的最优策略选择,在此基础上讨论了安全投资效率参数、黑客学习能力、传染风险对信息系统脆弱性及信息系统安全投资率的影响。其次,在推导出两企业在合作博弈情形下最优策略选择的基础上,对比两种情形下的博弈均衡结果,得出合作博弈下的投资水平高于非合作博弈下的投资水平。原因是两个企业的相互依赖关系隐含着企业投资的负外部性,从而导致企业投资不足。最后,构建一种双边支付激励机制消除企业投资不足问题,从而使企业达到合作博弈下的最优投资水平,提高两个企业的收益。

关键词: 信息系统安全投资, 合作协调, 微分博弈, 相互依赖的安全

Abstract: Optimizing continuous time information system security investment decisions of firms in the case of interdependent security is worthing studying. First, we employ the methodology of differential games to investigate two firms’ optimal investment strategies in the Nash non-cooperative game. In this general non-cooperative information system security investment game situation,the influence on the equilibrium vulnerability (security investment rate)is studied when three important elements(investment efficiency parameter,hackers’ learning effect, pidemic risk)are changed .Then the optimal action selection of two partners in the cooperative game situation is analyzed. After comparing these two game equilibrium results,it is found that symmetric firms maintain a higher rate of security investment under cooperative situation. The application of executing a bilateral compensation scheme is one of the measures to achieve the equilibrium which under coordination.

Key words: information system security investment, coordination, differential game, interdependent secuurity

中图分类号: