SearcharxivSearch

arXiv · 2311.15701

Cyber risk modeling using a two-phase Hawkes process with external excitation

Abstract

With the growing digital transformation of the worldwide economy, cyber risk has become a major issue. As 1 % of the world's GDP (around $1,000 billion) is allegedly lost to cybercrime every year, IT systems continue to get increasingly interconnected, making them vulnerable to accumulation phenomena that undermine the pooling mechanism of insurance. As highlighted in the literature, Hawkes processes appear to be suitable models to capture contagion phenomena and clustering features of cyber events. This paper extends the standard Hawkes modeling of cyber risk frequency by adding external shocks, modelled by the publication of cyber vulnerabilities that are deemed to increase the likelihood of attacks in the short term. The aim of the proposed model is to provide a better quantification of contagion effects since, while the standard Hawkes model allocates all the clustering phenomena to self-excitation, our model allows to capture the external common factors that may explain part of the systemic pattern. We propose a Hawkes model with two kernels, one for the endogenous factor (the contagion from other cyber events) and one for the exogenous component (cyber vulnerability publications). We use parametric exponential specifications for both the internal and exogenous intensity kernels, and we compare different methods to tackle the inference problem based on public datasets containing features of cyber attacks found in the Hackmageddon database and cyber vulnerabilities from the Known Exploited Vulnerability database and the National Vulnerability Dataset. By refining the external excitation database selection, the degree of endogeneity of the model is nearly halved. We illustrate our model with simulations and discuss the impact of taking into account the external factor driven by vulnerabilities. Once an attack has occurred, response measures are implemented to limit the effects of an attack. These measures include patching vulnerabilities and reducing the attack's contagion. We use an augmented version of the model by adding a second phase modeling a reduction in the contagion pattern from the remediation measures. Based on this model, we explore various scenarios and quantify the effect of mitigation measures of an insurance company that aims to mitigate the effects of a cyber pandemic in its insured portfolio.

Explore related subjects

Keep this discovery

BibTeXRIS

Alexandre Boumezoued, Yousra Cherkaoui, Caroline Hillairet. 2023-11-27. Cyber risk modeling using a two-phase Hawkes process with external excitation. https://arxiv.org/abs/2311.15701

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

A Scale Invariance Property of PCA

The PCA algorithm is sensitive to changes in measurement scale. Measuring one variable of a system in inches rather than centimeters, say, alters both its principal axes and principal eigenvalues. Although this scale dependence is generally complicated, we show here that it nevertheless obeys a strict invariance property: under a continuous scale adjustment, the initial state's $k$-th largest principal component (ordered by eigenvalue) continuously evolves into the final state's $k$-th largest principal component, for each $k$. In this sense, we can say that the modes of PCA are "order-stable" with respect to changes in measurement scale. A special case occurs when scaling along directions that are orthogonal to some modes. Here, apparent eigenvalue crossings can occur. However, we show that we can interpret these apparent crossings as cases where the modes instantaneously swap their orientation, in this way maintaining the required order stability.

math.ST

Small noise asymptotics for linear parabolic SPDEs in two space dimensions with unknown damping factors

We study parametric estimation for second order linear parabolic stochastic partial differential equations in two space dimensions with a small volatility parameter driven by a $Q$-Wiener process with an unknown damping parameter using high frequency spatio-temporal data. We first provide an estimator for the damping parameter of the $Q$-Wiener process utilizing realized quadratic variations based on spatial and temporal increments. We next propose minimum contrast estimators of the diffusive and advective parameters in the SPDE using a contrast function with the proposed estimator of the damping parameter. We then construct a quasi-maximum likelihood estimator of the reaction parameter in the SPDE using the approximate coordinate process derived from the estimators of the diffusive and advective parameters. We also provide simulation results of the proposed estimators.

math.ST

Spike Estimation from Heteroscedastic Noise via Random Splitting

In this paper, we consider a spiked Wigner type matrix with a heteroscedastic and unknown variance profile. It is well known that in the supercritical regime of the BBP transition, strong spikes can create outliers in the spectrum. Unfortunately, in the heteroscedastic case, in general it is not possible to estimate the spike strength from these observed outlier consistently, as the latter is a solution to a Dyson equation with unknown parameters from the variance profile. In this paper, inspired by the work on sparse matrix completion \citep{BordenaveCosteNadakuditi2023}, we introduce an asymmetrized model by randomly splitting the spiked matrix into two parts, which transforms the noisy Wigner type matrix into a non Hermitian random matrix, while preserving the Hermitian spikes at the cost of a dilution. We establish a BBP type transition for the asymmetrized model, from which we can estimate the strength of the spikes precisely, even without knowing the variance profile of the noise part. We then further apply our approach to study the correlation between two correlated spiked models, where the spike/signal parts of the two models are correlated, and the noise parts are independent but may both be heteroscedastic. By applying our asymmetrization approach to the two models separately and also jointly, we are able to obtain a precise estimate of the correlation between the signal parts of the two models.

math.ST