Behavioral Cybersecurity: Investigating the influence of Patching Vulnerabilities in Markov Security Games via Cognitive Modeling
Zahid Maqbool, V. S. Chandrasekhar Pammi, Varun Dutt · International Journal on Cyber Situational Awareness · 2019
Current research in cyber-security is not focused on human decision-making.The primary objective of this study is to address this gap and investigate how cognitive processes proposed by Instance-based Learning Theory (IBLT) like reliance on recency and frequency, attention to opponent's actions, and cognitive noise are influenced by the effectiveness of vulnerability patching.Data involving participants performing as hackers and analysts was collected in a lab-based experiment in two patching conditions: effective (N = 50) and less-effective (N = 50).In effective (less-effective) patching, computer systems were in a non-vulnerable state (i.e., immune to cyber-attacks) 90% (50%) of the time after patching.An IBL model accounted for human decisions and revealed low (high) reliance on recency and frequency, attention to opponent's actions, and cognitive noise for hacker (analyst) in effective patching.Whereas, it revealed opposite results for less-effective patching.We highlight the implications of our findings for cyber decisionmaking.