Showing posts with label cyber crime. Show all posts
Showing posts with label cyber crime. Show all posts

Sunday, May 31, 2015

Net Insecurity, Cybersecurity, and New Future Internet Architectures

I was mesmerized by the terrific article in The Washington Post written by Craig Timberg entitled: Net Insecurity: A Flaw in the Design.

Not only did it feature David Clark of MIT, who spoke at the Cybersecurity Rosk Analysis for Enterprise Risk Security Workshop that my Isenberg School of Management and College of Engineering colleagues and I organized, with funding provided by the Advanced Cyber Security Center (ACSC)  and which took place at the Sloan School of MIT last September, but also Richard Stallman, who was a keynote speaker at the INFORMS Computing Society Conference this past January (and I had the pleasure of not only speaking with him but also sharing a taxi with him to the airport).

Below are photos of Clark and Stallman (with my great INFORMS colleagues Bob Fourer and Matt Saltzman)  that I took at these respective events.
In Timberg's Post article, Clark is quoted as saying in regards to the development of the Internet that: "It’s not that we didn’t think about security,” Clark recalled. “We knew that there were untrustworthy people out there, and we thought we could exclude them.”

The Post article ends with the following prescient sentences: In 2008, Clark crafted a new list of priorities for a National Science Foundation project on building a better Internet. The first item was, simply, “Security.” I  could not agree more.

Coincidentally, on June 1 and 2,  the Future Internet Architecture (FIA) Spring 2015 meeting is taking place at MIT at the Stata building. Although I am in Sweden and will be taking part in a Finance conference in Gothenburg, two of my doctoral students will be presenting there on our NSF ChoiceNet project work, since we are one of five teams selected (and sponsored) by the NSF as part of its very ambitious and visionary Future Internet Architecture programOur ChoiceNet project aims to construct an economy plane for the Internet, which will allow more choices and cybersecurity is, of course, a possible primary feature.

Specifically, on June 2, my doctoral student, Shivani Shukla, will be presenting the poster below, which is based on a paper of ours: "Game Theoretic Model for Cybersecurity with Nonlinear Budget Constraints."


My doctoral student, Sara Saberi, will be presenting a poster on our paper, "A Network Economic Game Theory Model of a Service-Oriented Internet with Price and Quality Competition in Both Content and Network Provision," that was published in the INFORMS journal Service Science. The paper was co-authored with the lead PI on our NSF project, Tilman Wolf of UMass Amherst.

My first paper on cybercrime, "A Multiproduct Network Economic Model of Cybercrime in Financial Services,"  was also published in Service Science.

Our paper, "A Game Theory Model of Cybersecurity Investments with Information Asymmetry," Anna Nagurney and Ladimer S. Nagurney,  is now in press in Netnomics.

Also, our paper,  "A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability,"  Anna Nagurney, Ladimer S. Nagurney, and Shivani Shukla, is in press in the book: Computation, Cryptography, and Network Security (2015), N.J. Daras and M.T. Rassias, Editors, Springer, New York. Since The Washington Post article expands on the challenges faced by encryption, especially in the early years of the Internet, this book should be very timely!

Given the importance of cybersecurity, I am delighted that the UMass Amherst  Provost Katherine S. Newman is helping to spearhead a new Cybersecurity Institute at UMass Amherst and, with the interest in the topic at the Isenberg School of Management, the School of Computer Science, the College of Engineering, and also other schools at UMass Amherst, this is a very exciting initiative!

Tuesday, April 7, 2015

Launch of Data Science Center at UMass

This is quite the exciting week with not only one of my doctoral students (Sara Saberi) defending her dissertation proposal on Thursday but also the launch of the new Data Science Center at UMass Amherst. The program looks terrific and I will be there before the proposal defense and shortly thereafter for the poster session, where we will be presenting our latest research on cyber crime and cybersecurity, done with another doctoral student of mine, Shivani Shukla, who also prepared the poster below.


The program is as follows:


Center for Data Science Launch Symposium


Thursday, April 9th 2015

Life Sciences Laboratories, 6th floor
240 Thatcher Road Amherst, MA, 01003
The event will bring together leaders in academia, industry and government.

Expected Agenda


9:00am
Light breakfast and social networking
10:00am
Welcome by Chancellor, Provost and other dignitaries
10:10am
Andrew McCallum, Professor & Director of Center for Data Science, UMass
Overview of day's agenda and the Center for Data Science
10:20am
Pat Larkin, Director, Innovation Institute at Mass Tech Collaborative
Data Science and the Massachusetts economy
10:30am
Jim Kurose, head of Computer & Information Science and Engineering, NSF
Keynote presentation
11:00am
Examples of our Research and Interaction with Industry
Industry and Academic spotlights
Information Economy
  • Steve Vinter, Site Director & Engineering Director, Google Cambridge
  • Andrew McCallum, Professor, UMass CS (information integration)
  • Misha Davidson, Director of Engineering, HP Vertica
  • Yanlei Diao, Associate Professor, UMass CS (big and fast data analytics)
Energy and Sustainability
  • Brian Beauregard, Electric Division Head, Holyoke Gas & Electric
  • Prashant Shenoy, Professor, UMass CS (distributed systems)
  • Scott Schwenk, North Atlantic LCC Coordinator, U.S. Fish & Wildlife Service
  • Dan Sheldon, Assistant Professor, UMass CS (computational ecology)
Business and Analysis
  • Gareth Ross, SVP Data, MassMutual
  • David Jensen, Professor, UMass CS (causality)
  • Andrew Merlino, Founder & CEO, Pixel Forensics
  • Erik Learned-Miller, Associate Professor, UMass CS (computer vision)
Health and Medicine
  • Deb Bulger, Executive Director of Strategic Programs, McKesson
  • Benjamin Marlin, Assistant Professor, UMass CS (machine learning)
  • Joel Vengco, CIO, BayState Health
  • Deepak Ganesan, Associate Professor, UMass CS (wearable sensors)
12:00pm
Lunch
and TV, radio and print press interviews
1:30pm
Industry and Government panel
statements and discussion
  • Brian Ulicny, Director of Data Science, Thomson Reuters
  • Rohit Prasad, Director of Research, Echo & Speech, Amazon
  • Eric Brown, Director of Watson TechnologiesIBM
  • Alex Cosmas, Chief Scientist, Booz Allen Hamilton
  • Raj Subbu, Analytics Leader, Pratt & Whitney
  • C.A. Webb, Executive Director, NE Venture Capital Association
  • Mark Corner, CTO, Fiksu
  • Jennifer Chayes, Distinguished Scientist and Managing Director, Microsoft Research New England and New York City
  • Steve Strassmann, CTO, Commonwealth of Massachusetts
2:30pm
Education panel
statements and discussion
Using Data Science to improve education & Data Science Education
  • Beverly Woolf, Professor and White House Presidential Innovation Fellow, UMass CS
  • Rick Adrion, Professor, Director or ECEP,  UMass CS
  • James Allan, Professor & future Chair, UMass CS 
  • Ben Marlin, Assistant Professor, UMass CS
  • Kathy McKeown, Director, Data Science Institute, Columbia Univ.
3:20pm
Provost Katherine Newman & Andrew McCallum.  Closing remarks
3:30pm
Poster session and open discussion
Browse posters describing Data Science research by faculty from across UMass, Mt. Holyoke, Smith, Amherst and Hampshire Colleges, as well as industry representatives.
4:30pm
End of formal event.  Open discussion continues.


Friday, March 13, 2015

Network Economics of Cybercrime and Cybersecurity

Lately I have been quite fascinated by the modeling challenges of both cybercrime and cybersecurity with my belief that the latter can only be well understood and captured if one has a good handle on the former.

I have for quite a few years been researching network vulnerabilities and Patrick Qiang and I even wrote a book on that topic: Fragile Networks: Identifying Vulnerabilities and Synergies in an Uncertain World. So moving into cyberspace vulnerabilities was a natural. In addition, when the opportunity presented itself for funding in this area through the Advanced Cyber Security Center then clearly the timing was also right. In a collaboration between the Isenberg School of Management and the College of Engineering at UMass Amherst, we received 2 grants. As part of the second grant, our team organized a terrific workshop at the Sloan School at MIT  (I may be biased but it really was terrific from both idea generation and networking perspectives).. The workshop was on  cybersecurity risk analysis for enterprises.   One of the benefits of such a workshop is not only the brainstorming that takes place but also that research ideas that gel.

The first paper in this area in a stream of papers that I have authored or co-authored was recently published in the INFORMS journal Service Science and it is entitled: A Multiproduct Network Economic Model of Cybercrime in Financial Services, Service Science 7(1): (2015) pp 70-81.

INFORMS was kind enough to issue a press release on it: A New Model of Cybercrime Factors in Perishanility of Stolen Data, thanks to our wonderful Communications Director, Barry List.  The model focuses on financial service firms and captures the decay in the value of cyberhacked products over time in terms of their prices.

The network economic framework that I constructed in the paper permits quantifiable evaluation of various policy interventions that are investigated:
  1. Determining the impact of strategies that make it harder to attack financial products’ source locations (computer servers)
  2. Evaluating ways that make it harder for cybercriminals to make transactions through the common technique of increasing transaction costs
  3. Exploring changes in the demand price to evaluate greater or lesser interest in criminal products at demand markets. 
The release has appeared on EurekAlert!, physorg.com, and also by UMass Amherst. I very much like the writeup by Paul Roberts on this paper that appeared in the Digital Guardian: Sale By Date: Research Finds that Stolen Data is Perishable.

As for our research on cybersecurity, there we also focus on the network issues and on the probability of an organization getting hacked and incurring associated damages, based on its investments in cybersecurity and also those of the others in their "network." We have developed a series of more general models with the latest one dealing with nonlinear budge constraints. In our work we care not only about good models but also effective computational procedures as well as insights for policy makers. We are utilizing game theory and variational inequality theory for the model formulations, qualitative analyses, and algorithmic implementations.

Wednesday, April 2, 2014

Cybersecurity and Financial Services and Prescriptive Analytics

Yesterday, I had the honor of speaking on Cybersecurity and Financial Services at the INFORMS Analytics Conference in Boston. The conference was very well-organized, the venue at the Westin Waterfront hotel was marvelous, and the speakers came from both industry (many of the top analytics firms as developers and/or users were there) and academia. Also, there were many students and even a good-sized cohot from our UMass Amherst INFORMS Student Chapter, which I highlighted in one of my posts.

I had multiple roles at this conference, which made the experience extra rewarding, and INFORMS staff presented me with the nice streamers below.

My talk was in the Prescriptive Analytics track, which was appropriate, and Dr. Marius Solomon of Northeastern University introduced me. I have known Marius for many years through the Transportation & Logistics Society of INFORMS. He shared with me that there were 104 submissions for presentations and out of these 30 were selected. I had carefully thought about the topics that I would like to speak on and chose Cybersecurity and Financial Services since I believe that cybersecurity is a topic that could greatly benefit from analytics and operations research methodologies and the wonderful geeks and brainiacs in our professional community for whom tough problems are both challenging and enticing!

It was great to have Dr. Irv Lustig of IBM  in the audience and some of you may know that Irv was also an Applied Math major at Brown University and I was his TA for an operations research  course taught there by my dissertation advisor Professor Stella Dafermos. Irv is well-known at INFORMS and very active in its Certified Analytics Professional program.   I posted a photo of Irv and me in my previous blogpost. 

Irv asked good questions, but, then again, he has had an outstanding education (his doctoral dissertation advisor at Stanford was Professor George Dantzig, one of the founders of Operations Research). And we continued the discussion after my presentation. Great to hear that IBM is also interested in Financial Networks!

In my presentation I spoke about a project that was funded by the Advanced Cyber Security Center (ACSC) and then segued into our NSF project.
My full presentation, in pdf format, can be downloaded from the Supernetworks Center website.

In the presentation I highlighted a network model that we developed to assess financial network vulnerability and importance of different financial network components, described a network economic model of cyber crime, and also discussed our latest NSF project on envisioning a Future Internet Architecture that we are calling ChoiceNet. Imagine if we could enhance the resilience of the network through redesign.

Thanks to INFORMS for organizing such a fabulous analytics conference!

Sunday, January 5, 2014

FireEye Acquires Mandiant and Why Cybersecurity Matters

My most recent post on this blog was on networks in mergers and acquisitions and shortly thereafter there was a very interesting acquisition announcement in the cybersecurity space: FireEye acquired Mandiant Corp. This is considered one of the biggest recent security deals as reported by The New York Times, which noted that The combination of the two companies — one that detects attacks in a novel way (FireEye), another that responds to attacks (Mandiant) — comes as corporate America has become wary of relying on the federal government to monitor the Internet and warn of incoming attacks. And according to The Wall Street Journal: Mandiant and FireEye market themselves to businesses, not consumers, and focus on blocking highly skilled hackers who can evade traditional antivirus software. But they have unique specialties. Mandiant has become famous for its investigators that act like a cyber-SWAT team for companies that have been hacked. They focus on figuring out how hackers got in and removing them from corporate systems.

Mandiant is named after its founder, Kevin Mandia, who also served as the company's CEO prior to its acquisition. According to the company's website: Mandia was profiled on the cover of Fortune magazine and recognized by Foreign Policy magazine as one of the 100 leading global thinkers of 2013. The New York Times a few months ago had major coverage of the expertise of Mandiant which was fascinating.

Mr. Mandia went to Lafayette College, in Easton, PA, which is also my husband's undergraduate alma mater. From  an article on Lafayette College's website, I learned that Kevin Mandia was a computer science graduate, and also holds a Master’s in forensic science from George Washington University. He is co-author of Incident Response: Investigating Computer Crime and articles for The International Journal of Cyber Crime.

I became interested in cybersecurity and cyber crime in my research on modeling the Internet and was involved in an Advanced Cyber Security  Center (ACSC) project, Prime the Pump, entitled: Cybersecurity Risk Analysis and Investment Optimization  with colleagues in Operations & Information Management and in Finance at the Isenberg School of Management, and in Electrical and Computer Engineering, at UMass Amherst, along with one of the university's chief information officers.

I presented some of our funded research at the INFORMS Annual Meeting in Minneapolis last October and posted some information prior to the conference. Our session, organized by Professor Alla Kammerdiner,  was entitled: Big Data Analytics for Cybersecurity, and it was videotaped. INFORMS recently posted the video of my presentation: Network Economics of Cyber Crime with Applications to Financial Service Organizations  on INFORMS' great youtube channel and it can be accessed directly below.


We hope to extend this and related work through the auspices of ACSC.

Also,  Alla's presentation was on Network Inference for Monitoring Cyber-physical Systems (CPS) and it can be viewed below.
Alla ran the Boston Marathon last April 15 and is an elite runner. She heard about the bombings after she completed the marathon route and while on the Green line traveling back to her hotel.

Friday, September 27, 2013

Network Economics of Cyber Crime

I have been working on network economics with interfaces to various applications for quite a while, with the first edition of my book on the topic being published twenty years ago!
About two years ago, we were approached to submit a proposal to the Advanced Cyber Security Center, which was soliciting proposals for its Prime the Pump Initiative and our project, Cybersecurity Risk Analysis and Investment Optimization, was funded.

Our project team is interdisciplinary, and consists of Professors Wayne Burleson of Electrical and Computer Engineering, Mila Getmansky Sherman of Finance, Senay Solak, and yours truly of the Operations & Information Management Department, of the Isenberg School of Management, and Chris Misra, of the OIT Department -- all of us at UMass Amherst.

The Project Synopsis:

The vision of this project was to develop:

  • rigorous models for cybersecurity risk,
  • models for costs and benefits of various cybersecurity technologies,
  • techniques for integrating  these models into higher level models that account for other risks and risk management expenditures.
I will be presenting an aspect of our research project at INFORMS Minneapolis in the presentation entitled: Network Economics of Cyber Crime with Applications to Financial Service Organizations.

 The presentation can be downloaded here.

The invitation to submit a paper to the invited session came from Dr. Alla Kammerdiner, whom I met at a marvelous conference in Yalta, Ukraine.

The session information is here.

Dr. Kammerdiner I wrote about earlier in this blog -- she had run the Boston Marathon that was the site for the terrorist attack last April 15.

Another presentation on our project, from a broader perspective, can be accessed here.