<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="client.xsl" type="text/xsl"?>
<article article-type="other">
<front>
<journal-meta>
<journal-id/>
<issn/>
<banner>
<href>banner.jpg</href>
<size width="100%"/>
</banner>
</journal-meta>
<doi>0367-cd</doi>
<article-meta>
<title-group>
<article-title>A Game Theoretic Model for Understanding and Modelling Cybersecurity for Telecommunications Operators</article-title>
</title-group>

<author>Ian Oliver<sup>1</sup>, Sakshyam Panda<sup>2,a</sup> and Sotiris Moschoyiannis<sup>2,b</sup></author>

<aff><sup>1</sup>Nokia Bell Labs, Espoo, Finland</aff>

<email><a href="mailto:ian.oliver@nokia-bell-labs.com">ian.oliver@nokia-bell-labs.com</a></email>

<aff><sup>2</sup>University of Surrey, Guildford, UK</aff>

<email><a href="mailto:s.panda@surrey.ac.uk"><sup>a</sup>s.panda@surrey.ac.uk</a></email>

<email><a href="mailto:s.moschoyiannis@surrey.ac.uk"><sup>b</sup>s.moschoyiannis@surrey.ac.uk</a></email>

</article-meta></front>
<body>
<abstract>
<title>ABSTRACT</title>
<p>Cybersecurity is typically characterised as being between defenders and attackers. The economic analysis of such situations is made using either simple normal form games or Stackelberg game or dynamic games. We draw upon experiences in the telecommunications operator and standardisation domain in this study. While this model suffices for the understanding of the basic concepts, it does not and can not capture many of the subtle realities of the cybersecurity environment. Indeed it can result in a misunderstanding of the nature of threats when the defender is not under active attack.<br/>
We construct a model consisting of more roles and introduce the notion of an explicit security concept with a value to each of the participants or roles. Using this model we can explore the individual sub-games between participants and roles through <italic>dynamic games with imperfect information</italic>. In the former, we can understand the internal dynamics for any given security control, while in the latter we obtain a larger overall understanding of the players and their actions. Two results that are of particular interest in the studied domain are where the distinction between &#8216;foes&#8217; and &#8216;allies&#8217; is lost and where the absence of an attack cannot be understood as the absence of an attack.</p>
<p><italic>Keywords: </italic>Cybersecurity, Game Theory, Economics of cyber security, Attackers, Cyber insurance.</p>
</abstract>
<fpdf>
<href>pdflogo.jpg</href>
<hpdf>0367</hpdf>
</fpdf>
</body>
</article>