Showing posts with label financial services. Show all posts
Showing posts with label financial services. Show all posts

Friday, March 4, 2016

Looking Forward to Speaking at MITRE on Cybersecurity

On March 14, 2016, a day that is known as "Pi Day," I will be speaking at the MITRE Corporation in Bedford, Massachusetts.  The invitation came from Dr. Les Servi, who not only is an INFORMS Fellow, but he and I both received undergrad and graduate degrees in Applied Math at Brown University. I stayed on for my PhD there and Les went to Harvard for his.

The title of my talk, which I have been hard at work on, and enjoying preparing very much, is: "From Cybercrime in Financial Services to Cybersecurity Investments and Network Vulnerability."

I now have a stream of papers in cybersecurity, beginning with the paper: A Multiproduct Network Economic Model of Cybercrime in Financial Services, Anna Nagurney, Service Science 7(1): (2015) pp 70-81.  The paper: A Supply Chain Game Theory Framework for Cybersecurity Investments Under Network Vulnerability, Anna Nagurney, Ladimer S. Nagurney, and Shivani Shukla, in Computation, Cryptography, and Network Security, N.J. Daras and M.T. Rassias, Editors, Springer International Publishing Switzerland (2015) pp 381-398 is our first paper examining cyber network vulnerability in a supply chain context and extends our paper, A Game Theory Model of Cybersecurity Investments with Information Asymmetry, Anna Nagurney and Ladimer S. Nagurney, Netnomics 16(1-2): (2015) pp 127-148.
 
Since then, we have introduced nonlinear budget constraints on cyber security investments in the paper: A Supply Chain Network Game Theory Model of Cybersecurity Investments with Nonlinear Budget Constraints, Anna Nagurney, Patrizia Daniele, and Shivani Shukla, and,  with my collaborators in Italy, Professors Patrizia Daniele and Antonino Maugeri, we have co-authored the paper, Cybersecurity Investments with Nonlinear Budget Constraints: Analysis of the Marginal Expected Utilities, which is an invited paper for the volume: Operations Research, Engineering and Cyber Security: Trends in Applied Mathematics and Technology, T.M. Rassias and N.J. Daras, Editors, Springer International Publishing Switzerland.

Along with one of my doctoral students, Shivani Shukla, we have also recently revised and resubmitted a rather expansive paper: Multifirm Models of Cybersecurity Investment Competition vs. Cooperation and Network Vulnerability, in which we explore distinct concepts of Nash Equilibrium, Nash Bargaining, and System-Optimization for cybersecurity investments, and describe three case studies to the retail, financial services, and energy sectors, respectively.

In my MITRE presentation, I will focus on both the Service Science paper, and our most recent work, but will also highlight results for our supply chain game theory and cybersecurity investments models.

And, speaking of reciprocity, I am delighted that Dr. Les Servi will be speaking at the Isenberg School of Management on March 25 and the topic will also be cuybersecurity. The wonderful UMass Amherst INFORMS Student Chapter President and students prepared the nice poster announcement for his talk below.
This month will certainly be an exciting one!


Friday, March 13, 2015

Network Economics of Cybercrime and Cybersecurity

Lately I have been quite fascinated by the modeling challenges of both cybercrime and cybersecurity with my belief that the latter can only be well understood and captured if one has a good handle on the former.

I have for quite a few years been researching network vulnerabilities and Patrick Qiang and I even wrote a book on that topic: Fragile Networks: Identifying Vulnerabilities and Synergies in an Uncertain World. So moving into cyberspace vulnerabilities was a natural. In addition, when the opportunity presented itself for funding in this area through the Advanced Cyber Security Center then clearly the timing was also right. In a collaboration between the Isenberg School of Management and the College of Engineering at UMass Amherst, we received 2 grants. As part of the second grant, our team organized a terrific workshop at the Sloan School at MIT  (I may be biased but it really was terrific from both idea generation and networking perspectives).. The workshop was on  cybersecurity risk analysis for enterprises.   One of the benefits of such a workshop is not only the brainstorming that takes place but also that research ideas that gel.

The first paper in this area in a stream of papers that I have authored or co-authored was recently published in the INFORMS journal Service Science and it is entitled: A Multiproduct Network Economic Model of Cybercrime in Financial Services, Service Science 7(1): (2015) pp 70-81.

INFORMS was kind enough to issue a press release on it: A New Model of Cybercrime Factors in Perishanility of Stolen Data, thanks to our wonderful Communications Director, Barry List.  The model focuses on financial service firms and captures the decay in the value of cyberhacked products over time in terms of their prices.

The network economic framework that I constructed in the paper permits quantifiable evaluation of various policy interventions that are investigated:
  1. Determining the impact of strategies that make it harder to attack financial products’ source locations (computer servers)
  2. Evaluating ways that make it harder for cybercriminals to make transactions through the common technique of increasing transaction costs
  3. Exploring changes in the demand price to evaluate greater or lesser interest in criminal products at demand markets. 
The release has appeared on EurekAlert!, physorg.com, and also by UMass Amherst. I very much like the writeup by Paul Roberts on this paper that appeared in the Digital Guardian: Sale By Date: Research Finds that Stolen Data is Perishable.

As for our research on cybersecurity, there we also focus on the network issues and on the probability of an organization getting hacked and incurring associated damages, based on its investments in cybersecurity and also those of the others in their "network." We have developed a series of more general models with the latest one dealing with nonlinear budge constraints. In our work we care not only about good models but also effective computational procedures as well as insights for policy makers. We are utilizing game theory and variational inequality theory for the model formulations, qualitative analyses, and algorithmic implementations.

Sunday, January 25, 2015

A Great Week for Our Research on Networks

Last week was the first week of the new academic semester at UMass Amherst and it was a very exciting one.

I always very much enjoy meeting new students in the courses that I am teaching.

Plus, it was a great week for news on our research on Networks.

One of the best things about collaborations, besides the synergy and dynamism of researching tough problems together, is that, when one gets good news, such as a paper getting accepted, or hearing of its publication, and/or some great publicity about the work, you can share it and celebrate together - even if it is across the miles!

This week, Luis Marentes, who was a visiting doctoral student in the College of Engineering at UMass Amherst last year, and who is from Colombia, Professor Tilman Wolf (who was his host), and with whom I have a large NSF grant, and Professors Yezid Donoso and Harold Castro of the  Department of Systems and Computing Engineering, Universidad de los Andes in  Bogota, Colombia, and I had our paper, "Overcoming Economic Challenges of Internet Operators in Low Income Regions through a Delay Tolerant Architecture with Mechanic Backhauls," appear online in the journal NetnomicsIt was great to share in the happiness of all those involved in this publication, which is on the dynamic pricing of Delay Tolerant Networks, and proposes a new computer architecture. To-date, there has been minimal work on the pricing in this domain and the identification of the potential profitability of Internet Service Providers in poor, and, often, rural communities, where even mechanic (even in the form of mule transportation) may be used to transport Internet information.

Also, our paper, "Securing the Sustainability of Global Medical Nuclear Supply Chains Through Economic Cost Recovery, Risk Management, and Optimization," co-authored with Professor Ladimer S. Nagurney of the University of Hartford and my doctoral student, Dong "Michelle" Li, appeared this week in the special issue of the International Journal of Sustainable Transportation devoted to Sustainability in Transportation Networks.  The paper was accepted for publication close to 3 years ago so it was nice to see it officially in the journal volume!

The first paper above has 5 co-authors, the second one has 3, and the one below only one (but ensuing ones on cybersecurity will have co-authors).  Specifically, the paper, "A Multiproduct Network Economic Model of Cybercrime in Financial Services,  that I wrote after our very successful Advanced Cyber Security Workshop at the MIT Sloan School last Fall, received very nice reviews from an INFORMS journal, and it has been revised and resubmitted. In the Acknowledgments I also thank the audience who came to my presentation at the Boston INFORMS Analytics conference in Spring 2014, which was a fabulous conference!


Another highlight this past week was having our NSF project: Network Innovation Through Choice, which we are calling ChoiceNet, and for which Professor Wolf and I are PI and Co-PI (along with 5 other Co-PIs from the University of Kentucky, NCState, and the Renaissance Institute (RENCI) at UNC) being featured on the UMass Amherst Research website in Research Next.  And the article, Internext, UMass Amherst experts are driving the future of Internet infrastructure, will appear in the 2014 UMass Amherst Annual Report on Research which will be available, I am told, by the end of this month. 


This should be a very exciting week as well with many interview candidates coming both to the Isenberg School and to UMass and with a major snowstorm forecast for early this week!

Monday, September 29, 2014

Modeling the Network Economics of Cybercrime in Financial Services

For as long as I can remember, I have been fascinated by networks - their graphical structure and as a means of representing economic activity in terms of product flows, costs, and profits, along with the associated decision-making.

Typically, I work on network systems as varied as global supply chains,  complex financial networks, electric power generation and distribution networks, as even the Internet, for which we have a large-scale National Science Foundation grant: Network Innovation Through Choice, which is part of the Future Internet Architecture program. In fact, soon I will be getting ready for our almost weekly teleconference among our partners on this project, which we are calling ChoiceNet.

Over two years ago, we started working, through a Prime the Pump project, funded by the Advanced Cyber Security Center (ACSC), on cybersecurity and risk assessment. As my readers know, this project was followed by another project, the culmination of which took place only 10 days ago, with a workshop that several Isenberg School colleagues and a College of Engineering colleague at UMass Amherst co-organized with me. On Friday, September 19, 2014, we hosted a workshop at the Sloan School at MIT, entitled:  Cybersecurity Risk Analysis for Enterprise Security, which I blogged about, and which has received some nice press. I very much enjoyed the keynotes at the conference as well as the panels with terrific industry panelists.

In my presentation at the workshop on Network Science on Economics,  I motivated the major issues through the following graphics which illustrate very dramatically the impacts of cybercrime and, also, if I may say, fascinating research questions.
Source: The Economic Impact of Cybercrime and Cyber Espionage, Center for Strategic and International Studies, July 2013, sponsored by McAfee.

According to a recent survey  cyber crime is placing heavy strains on the global financial sector, with cyber crime now the second most commonly reported economic crime affecting financial services firms. Cyber crime accounted for 38% of all economic crimes in the financial sector, as compared to an average of 16% across all other industries.  Every minute, of every hour, of ever day, a major financial institution is under attack (Wilson writing  in The Telegraph, October 6, 2013).

Cyber attacks are intrusive and economically costly. In addition, they may adversely affect a company’s most valuable asset – its reputation.

There is both vertical and horizontal information asymmetry - as noted above, organizations may not even be aware that sensitive data has been stolen from them (and for many months, no less). Moreover, other firms in the same industry may not be aware of attacks of their competitors or even partners.  Finally, and, again and again, I am seeing real commonalities between supply chains, behavior, and cyber crime activities: how confident are you that the software that is to battle computer viruses, malware, denial of service attacks, etc., delivers what is being promised? Here we get into the quality of outsourced production!

As noted by Ablon, Libicki, and Golay  in their 2014 Rand Report, the black market for cybercrime products can be more profitable than the illegal drug trade. They also argued in their study that an economic approach to tackling cybercrime in warranted, which I completely agree with.

I had been researching the network economics of cybercrime for two years and had spoken both at the INFORMS Minneapolis conference last year and at the Boston Analytics Conference on the topic and, after our workshop, completed a paper: "A Multiproduct Network Economic Model of Cybercrime in Financial Services." In this paper, we propose a network economic model of cybercrime with a focus on financial services, since such organizations are one of the principal targets of such illicit activity. The model is a multiproduct one and constructed as a layered bipartite network with supply price, transaction cost, and demand price functions linking the networks. A novelty of the new model is the incorporation of average time associated with illicit product delivery at the demand markets with the demand price functions being decreasing functions of such times, as noted in reality. For example, it is recognized that there is a short time window during which the value of a financial product acquired through cybercrime is positive but it decreases during the time window. Following the major Target breach, credit cards obtained thus initially sold for $120 each on the black market, but, within weeks, as banks started to cancel the cards, the price dropped to $8 and, seven months after Target learned about the breach, the cards had essentially no value. In addition, different “brands” of credit cards can be viewed as different products since they command different prices on the black market. For example, credit cards with the highest credit limits, such as an American Express Platinum card, command the highest prices. A card number with a low limit might sell for $1 or $2, while a high limit can sell for $15 or considerably more, as noted above.

In the paper, the governing equilibrium conditions are formulated as a variational inequality problem with qualitative properties of the solution presented. An algorithm, with nice features for computations, is then applied to two sets of numerical examples in order to illustrate the model and computational procedure as well as the types of interventions that can be investigated from a policy perspective to make it more difficult for cybercriminals to obtain sensitive data.

Tuesday, August 26, 2014

Network Science for Cybersecurity

We recently heard the good news that our project, "Cybersecurity Risk Analysis for Enterprise Security," is being funded by the Advanced Cyber Security Center (ACSC). The project team consists of - from UMass Amherst: Professor Wayne Burleson of the College of Engineering, and Professors Mila Sherman and Senay Solak from the Isenberg School of Management, plus me, and from MIT - Professor Andrew Lo of the Sloan School, who needs no introduction.  This project is actually a second step, following in the footsteps of our first ACSC project, which was a Prime the Pump project, "Cybersecurity Risk Analysis and Investment Optimization," with Chris Misra of OIT of UMass also being on that project with us.

On Friday, September 19, 2014, we will be holding a workshop at the Sloan School at MIT on the theme of the new project and we are busy now with teleconferences and finalizing the organization of the day. We expect over 50 attendees and have already had a great response from various financial service firms, insurance companies, MITRE, RSA, and EMC, to start. We also expect participation from researchers of neighboring universities, and even pharmaceutical firms.

It should be a very exciting event.

The Co-PIs will be giving presentations and we are also scheduling panels for a lot of discussion.

I will be speaking on Network Science for Cybersecurity. This topic encapsulates nicely much of the research that my group at the Supernetworks Center has done on network vulnerability and resiliency. I also plan on including some of our latest results on cyber crime, which I had the pleasure of speaking on last year at the great INFORMS conference in Minneapolis and also, in a broader context,at the INFORMS Analytics conference in Boston last April, which was simply fabulous!
 The above presentation can be downloaded in its entirety here.

We are very grateful to the ACSC for their continuing support and vision!


Wednesday, April 2, 2014

Cybersecurity and Financial Services and Prescriptive Analytics

Yesterday, I had the honor of speaking on Cybersecurity and Financial Services at the INFORMS Analytics Conference in Boston. The conference was very well-organized, the venue at the Westin Waterfront hotel was marvelous, and the speakers came from both industry (many of the top analytics firms as developers and/or users were there) and academia. Also, there were many students and even a good-sized cohot from our UMass Amherst INFORMS Student Chapter, which I highlighted in one of my posts.

I had multiple roles at this conference, which made the experience extra rewarding, and INFORMS staff presented me with the nice streamers below.

My talk was in the Prescriptive Analytics track, which was appropriate, and Dr. Marius Solomon of Northeastern University introduced me. I have known Marius for many years through the Transportation & Logistics Society of INFORMS. He shared with me that there were 104 submissions for presentations and out of these 30 were selected. I had carefully thought about the topics that I would like to speak on and chose Cybersecurity and Financial Services since I believe that cybersecurity is a topic that could greatly benefit from analytics and operations research methodologies and the wonderful geeks and brainiacs in our professional community for whom tough problems are both challenging and enticing!

It was great to have Dr. Irv Lustig of IBM  in the audience and some of you may know that Irv was also an Applied Math major at Brown University and I was his TA for an operations research  course taught there by my dissertation advisor Professor Stella Dafermos. Irv is well-known at INFORMS and very active in its Certified Analytics Professional program.   I posted a photo of Irv and me in my previous blogpost. 

Irv asked good questions, but, then again, he has had an outstanding education (his doctoral dissertation advisor at Stanford was Professor George Dantzig, one of the founders of Operations Research). And we continued the discussion after my presentation. Great to hear that IBM is also interested in Financial Networks!

In my presentation I spoke about a project that was funded by the Advanced Cyber Security Center (ACSC) and then segued into our NSF project.
My full presentation, in pdf format, can be downloaded from the Supernetworks Center website.

In the presentation I highlighted a network model that we developed to assess financial network vulnerability and importance of different financial network components, described a network economic model of cyber crime, and also discussed our latest NSF project on envisioning a Future Internet Architecture that we are calling ChoiceNet. Imagine if we could enhance the resilience of the network through redesign.

Thanks to INFORMS for organizing such a fabulous analytics conference!

Tuesday, April 1, 2014

Highlights of INFORMS Boston Analytics Conference Through Photos

Today the sun has (finally) come out in Boston and it is the last day of the GREAT INFORMS Analytics Conference in Boston. I will be speaking later today on Cybersecurity and Financial Services, on research funded by the Advanced Cyber Security Center and the National Science Foundation.

I my previous post on this blog I included some photos of our UMass Amherst students who are attending this conference.

Below I have posted some photos from talks, networking events and also the Edelman Awards gala at which the CDC received the 2014 Edelman Award for its efforts in eradicating polio.

INFORMS Registration Area
 
Keynote Talk by Tom Davenport

Coffee with  Member
 Numerous Networking Opportunities

 Superb Supply Chain Talks
Serendipity of Seeing Colleagues and Students

The Edelman Gala with a Delicious Dessert
The analytics conference has been an intellectual and professional  feast!

Saturday, March 29, 2014

Packing and Revising My Optimal Route to the INFORMS Analytics Conference in Boston

I  am blogging the INFORMS Analytics Conference in Boston and below I am reposting my first submitted official post.

It is a beautiful sunny day in Massachusetts and we are very excited about the INFORMS Analytics Conference which kicks off tomorrow in Boston at the Westin Waterfront hotel!

My talk on cybersecurity and financial services, which I am presenting there on Tuesday is all set, and I have begun to pack. There is no need for printing a boarding pass and making a seat assignment, unlike for my trip of just over a week ago when I flew back from Amsterdam to Boston Logan. 

Since I work on network systems, from transportation and logistical ones to the Internet, I have  always been  interested in optimal  routing of flows.

I had settled on a route from Amherst, where I live, to Boston, which I am very familiar with, and then the email arrived from EZPass last evening, which stated:

MassDOT has planned 3 significant weekend lane restrictions on Interstate 90 (Massachusetts Turnpike) in Boston to remove the Prudential Tunnel ceiling over the roadway. The ceiling remains safe and secure, but has deteriorated beyond the point of repair and must be removed. The tunnel ceiling is owned and maintained by the Massachusetts Convention Center Authority (MCCA).

The restrictions will reduce traffic to one lane eastbound and one lane westbound inside the Prudential Center Tunnel on the following weekends:
March 28-30!!! (I added the exclamation points.)

Last Saturday,  my shuttle driver from Logan made a quick maneuver when he saw the stream of glowing car backlights in the same tunnel, which is just outside of Logan. This necessitated a diversion through Arlington and added about 40 minutes to the last leg of my journey back to Amherst, which had originated in Gothenburg, Sweden, 14 hours before!

But now I was forewarned, thanks to MassDOT!

So, since we are educated as operations researchers, my revised route to Boston is below:
analytics-reroute
This INFORMS conference should be very energizing with exciting interactions between academics and practitioners plus I am even bringing one of my doctoral students, who is the President of our UMass Amherst INFORMS Student Chapter. This will be an outstanding venue for introducing her to my favorite professional society and community!

Go INFORMS, Boston, and, always, Boston Strong!

Safe travels, everyone, and see you soon!

Friday, September 27, 2013

Network Economics of Cyber Crime

I have been working on network economics with interfaces to various applications for quite a while, with the first edition of my book on the topic being published twenty years ago!
About two years ago, we were approached to submit a proposal to the Advanced Cyber Security Center, which was soliciting proposals for its Prime the Pump Initiative and our project, Cybersecurity Risk Analysis and Investment Optimization, was funded.

Our project team is interdisciplinary, and consists of Professors Wayne Burleson of Electrical and Computer Engineering, Mila Getmansky Sherman of Finance, Senay Solak, and yours truly of the Operations & Information Management Department, of the Isenberg School of Management, and Chris Misra, of the OIT Department -- all of us at UMass Amherst.

The Project Synopsis:

The vision of this project was to develop:

  • rigorous models for cybersecurity risk,
  • models for costs and benefits of various cybersecurity technologies,
  • techniques for integrating  these models into higher level models that account for other risks and risk management expenditures.
I will be presenting an aspect of our research project at INFORMS Minneapolis in the presentation entitled: Network Economics of Cyber Crime with Applications to Financial Service Organizations.

 The presentation can be downloaded here.

The invitation to submit a paper to the invited session came from Dr. Alla Kammerdiner, whom I met at a marvelous conference in Yalta, Ukraine.

The session information is here.

Dr. Kammerdiner I wrote about earlier in this blog -- she had run the Boston Marathon that was the site for the terrorist attack last April 15.

Another presentation on our project, from a broader perspective, can be accessed here.



Wednesday, April 28, 2010

Multi-product Supply Chains, Network Integration, and Mergers and Acquisitions

Now that the economy appears to be recovering, more and more companies are looking at mergers and acquisitions as a means of further reducing costs, expanding markets, and creating possible synergy.

In a study, Multi-product Horizontal Supply Chain Network Integration: Models, Theory, and Computational Results, published in the International Journal of Operational Research, (2010), vol. 17, pp. 333-349, we developed a framework for the identification of potential synergy associated with network integration in the case of multi-product firms. The perspective was that of system-optimization and total cost reduction associated with the sharing of resources, such as facilities (from manufacturing plants to distribution centers) within a general supply chain network framework.

The study was conducted with two of my former doctoral students, who are now professors at Business Schools: Dr. Trisha Woolley, who is a Professor at Texas Wesleyan University, and Dr. Patrick Qiang, who is a Professor at the Penn State Great Valley Campus.

The network approach that we developed can be applied to assess the potential synergy a priori of different potential mergers and acquisitions, from airlines to consumer product companies and even financial services and oil companies. Since the perspective is that of system-optimization, the tools can also be applied to the assessment of teams as in the partnering of organizations in humanitarian logistics operations.

The paper is also available at the Virtual Center for Supernetworks website.