article Open access

Behavioral Cybersecurity: Investigating the influence of Patching Vulnerabilities in Markov Security Games via Cognitive Modeling

  • International Journal on Cyber Situational Awareness
Research footprint

At a glance

Citations
2
References
19
Comments
0
Paper overview

Abstract

Current research in cyber-security is not focused on human decision-making. The primary objective of this study is to address this gap and investigate how cognitive processes proposed by Instance-based Learning Theory (IBLT) like reliance on recency and frequency, attention to opponent's actions, and cognitive noise are influenced by the effectiveness of vulnerability patching. Data involving participants performing as hackers and analysts was collected in a lab-based experiment in two patching conditions: effective (N = 50) and less-effective (N = 50). In effective (less-effective) patching, computer systems were in a non-vulnerable state (i.e., immune to cyber-attacks) 90% (50%) of the time after patching. An IBL model accounted for human decisions and revealed low (high) reliance on recency and frequency, attention to opponent's actions, and cognitive noise for hacker (analyst) in effective patching. Whereas, it revealed opposite results for less-effective patching. We highlight the implications of our findings for cyber decisionmaking.

Record transparency

Publication details

DOI
10.22619/ijcsa.2019.100130
OpenAlex
W2998097558
Document type
article
Language
EN
Source
International Journal on Cyber Situational Awareness
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.