Skip to main content
QUICK REVIEW

[论文解读] Comparing Alternatives to Measure the Impact of DDoS Attack Announcements on Target Stock Prices

Abhishta Abhishta, Reinoud Joosten|arXiv (Cornell University)|May 30, 2018
Network Security and Intrusion Detection参考文献 12被引用 3
一句话总结

本文评估了三种方法以衡量DDoS攻击公告对受害公司股价的影响,将传统的正态性假设方法与两种使用经验分布的非参数方法进行比较。研究发现,假设累积异常收益服从正态分布会导致市场影响的显著高估或低估,建议在网络安全金融研究的事件研究中使用经验分布以获得更准确的结果。

ABSTRACT

The attack intensity of distributed denial of service (DDoS) attacks is increasing every year. Botnets based on internet of things (IOT) devices are now being used to conduct DDoS attacks. The estimation of direct and indirect economic damages caused by these attacks is a complex problem. One of the indirect damage of a DDoS attack can be on the market value of the victim firm. In this article we analyze the impact of 45 different DDoS attack announcements on victim's stock prices. We find that previous studies have a mixed conclusion on the impact of DDoS attack announcements on the victim's stock price. Hence, in this article we evaluate this impact using three different approaches and compare the results. In the first approach, we use the assume the cumulative abnormal returns to be normally distributed and test the hypothesis that a DDoS attack announcement has no impact on the victim's stock price. In the latter two methods, we do not assume a distribution and use the empirical distribution of cumulative abnormal returns to test the hypothesis. We find that the assumption of cumulative abnormal returns being normally distributed leads to overestimation/underestimation of the impact. Finally, we analyze the impact of DDoS attack announcement on victim's stock price in each of the 45 cases and present our results.

研究动机与目标

  • 评估传统事件研究方法在衡量DDoS攻击对股价影响时的可靠性,该方法假设累积异常收益服从正态分布。
  • 使用45起DDoS攻击公告的实证数据,比较三种不同方法——两种非参数方法和一种参数方法。
  • 确定关于收益分布的假设是否显著扭曲了对网络攻击公告市场影响的估计。
  • 基于更稳健的统计框架,重新评估并强化先前关于DDoS攻击市场价值效应的研究发现。

提出的方法

  • 采用三种方法的综合方法:方法1假设累积异常收益(CAR)服从正态分布,并使用Z统计量进行假设检验。
  • 方法2使用异常收益估计的加法模型,不依赖分布假设,依赖CAR的经验分布。
  • 方法3应用收益估计的乘法模型,并同样使用经验分布来检验显著性,避免正态性假设。
  • 通过列联表比较各方法的结果,识别在显著性分类(+ve、no、-ve影响)上的差异。
  • 使用事件研究方法,结合市场模型和Fama-French三因子模型进行异常收益估计。
  • 通过非参数检验,将观察到的CAR与原假设下无影响的经验抽样分布进行比较。

实验结果

研究问题

  • RQ1假设累积异常收益服从正态分布是否会导致对DDoS攻击公告市场影响的结论产生偏差?
  • RQ2使用经验分布的非参数方法与参数方法相比,在检测DDoS事件引起的显著股价反应方面表现如何?
  • RQ3假设正态分布的方法与不假设正态分布的方法之间,是否存在系统性的显著性分类差异?
  • RQ4在网络安全背景下,不同的收益估计模型(加法模型与乘法模型)在多大程度上影响事件研究分析的结果?

主要发现

  • 假设累积异常收益服从正态分布,在5.77%的案例中导致影响被高估,在7.55%的案例中导致影响被低估,表明存在显著偏差。
  • 非参数方法(方法2和方法3)在加法和乘法收益模型下结果一致,表明模型选择对结果影响极小。
  • 方法1(正态性假设)与方法3(经验分布)在225个分析时段中有22.2%的时段出现显著性分类冲突,凸显了错误推断的风险。
  • 研究证实,导致服务中断的DDoS攻击——如对ING、Nordea、Deutsche Telekom和Rackspace的攻击——在9天和11天事件窗口内导致显著负向异常收益。
  • 相比之下,对Visa、Mastercard和Facebook的攻击未表现出显著市场影响,与先前发现一致,但现通过更稳健的方法论框架得到验证。
  • 结果支持用基于经验分布的检验替代参数性正态性假设,以提高网络安全事件研究的准确性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。