Insurance mechanisms in information security risk management

Borkhalenko V.A. OOO InfoProServis, Moscow, Russian Federation

Subject The article addresses risks of information security.
Objectives The aim of the study is to consider the treatment of information security risks associated with implementation of DDoS-attacks and the lack of efficient technical means to reduce these risks.
Methods I employ methods of linear programming, the theory of utility and actuarial mathematics to develop a mathematical model of a mutually profitable insurance contract.
Results I consider the basic disadvantages of organizational and technical measures against DDoS-attacks realization and describe the prevalence and profitability of using this type of attacks by attackers and dishonest competitors to violate the business continuity of the organization. The paper explains the need for using economic methods to ensure information security, and offers an insurance model that provides for shifting the risk associated with realization of DDoS-attacks.
Conclusions and Relevance The proposed cyberinsurance method of DDoS-attacks resistance is more efficient as compared to many common hardware available, and can be applied to reduce possible financial losses from information attacks.

Keywords: cyberinsurance, contract theory, DDoS, information security, risk


