the art of explanation: behavioral models of infosec

37
THE ART OF EXPLANATION

Upload: kelly-shortridge

Post on 15-Apr-2017

391 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: The Art of Explanation: Behavioral models of infosec

THE ART OF EXPLANATION

Page 2: The Art of Explanation: Behavioral models of infosec
Page 3: The Art of Explanation: Behavioral models of infosec

What is behavioral economics?

Page 4: The Art of Explanation: Behavioral models of infosec

Cognitive biases

Page 5: The Art of Explanation: Behavioral models of infosec

Common complaints about infosec

Page 6: The Art of Explanation: Behavioral models of infosec

My goal

Page 7: The Art of Explanation: Behavioral models of infosec

What will I cover?

Page 8: The Art of Explanation: Behavioral models of infosec
Page 9: The Art of Explanation: Behavioral models of infosec

Prospect theory

Page 10: The Art of Explanation: Behavioral models of infosec

Core tenets of Prospect Theory

Page 11: The Art of Explanation: Behavioral models of infosec

Offense vs. Defense

Page 12: The Art of Explanation: Behavioral models of infosec

InfoSec reference points

Page 13: The Art of Explanation: Behavioral models of infosec

Implications of reference points

Page 14: The Art of Explanation: Behavioral models of infosec

Prospect theory in InfoSec

Page 15: The Art of Explanation: Behavioral models of infosec

What are the outcomes?

Page 16: The Art of Explanation: Behavioral models of infosec

Incentive problems

Page 17: The Art of Explanation: Behavioral models of infosec
Page 18: The Art of Explanation: Behavioral models of infosec

Time inconsistency

Page 19: The Art of Explanation: Behavioral models of infosec

Time inconsistency in InfoSec

Page 20: The Art of Explanation: Behavioral models of infosec

InfoSec as a public good?

Page 21: The Art of Explanation: Behavioral models of infosec

What could this mean?

Page 22: The Art of Explanation: Behavioral models of infosec

Dual-system Theory

Page 23: The Art of Explanation: Behavioral models of infosec

Dual-system theory

Page 24: The Art of Explanation: Behavioral models of infosec

Dual-system theory in InfoSec

Page 25: The Art of Explanation: Behavioral models of infosec

What about groups?

Page 26: The Art of Explanation: Behavioral models of infosec

Group vs. Individual Biases

Page 27: The Art of Explanation: Behavioral models of infosec

Potential risks of groups

Page 28: The Art of Explanation: Behavioral models of infosec

So, what do we do about it?

Page 29: The Art of Explanation: Behavioral models of infosec

Improving heuristics: industry-level

Page 30: The Art of Explanation: Behavioral models of infosec

Changing incentives: defender-level

Page 31: The Art of Explanation: Behavioral models of infosec

Leveraging attacker weaknesses

Page 32: The Art of Explanation: Behavioral models of infosec

How to promote System 2

Page 33: The Art of Explanation: Behavioral models of infosec

Other ideas

Page 34: The Art of Explanation: Behavioral models of infosec

Conclusion

Page 35: The Art of Explanation: Behavioral models of infosec

Final thoughts

Page 36: The Art of Explanation: Behavioral models of infosec

Further research

Page 37: The Art of Explanation: Behavioral models of infosec

Questions?