{"title":"Calibration of the Gordon-Loeb Models for the Probability of Security Breaches","authors":"M. Naldi, M. Flamini","doi":"10.1109/UKSim.2017.18","DOIUrl":null,"url":null,"abstract":"Security breaches provoke increasingly high economic losses, requiring higher investment in security. The models by Gordon and Loeb are the most prominent tool employed to assess the impact of security investments on the probability of security breaches, but the estimation of their parameters remains an elusive issue. In this paper the impact of the investment productivity parameters in both Gordon- Loeb models is investigated, and a method is proposed for their estimation. The method employs a least-squares procedure and requires the amount of investments in security over period and the corresponding observed loss due to security breaches.","PeriodicalId":309250,"journal":{"name":"2017 UKSim-AMSS 19th International Conference on Computer Modelling & Simulation (UKSim)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-04-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 UKSim-AMSS 19th International Conference on Computer Modelling & Simulation (UKSim)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/UKSim.2017.18","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7
Abstract
Security breaches provoke increasingly high economic losses, requiring higher investment in security. The models by Gordon and Loeb are the most prominent tool employed to assess the impact of security investments on the probability of security breaches, but the estimation of their parameters remains an elusive issue. In this paper the impact of the investment productivity parameters in both Gordon- Loeb models is investigated, and a method is proposed for their estimation. The method employs a least-squares procedure and requires the amount of investments in security over period and the corresponding observed loss due to security breaches.