Incentive Centered Design and Information Security

October 18th, 2009 Comments Off

By Rick Wash and Jeff MacKie-Mason

Humans are “smart components” in a system, but cannot be directly programmed to perform; rather, their autonomy must be respected as a design constraint and incentives provided to induce desired behavior. Sometimes these incentives are properly aligned, and the humans don’t represent a vulnerability. But often, a misalignment of incentives causes a weakness in the system that can be exploited by clever attackers. Incentive-centered design tools help us understand these problems, and provide design principles to alleviate them. We describe incentive-centered  design and some tools it provides. We provide a number of examples of security problems for which Incentive Centered Design might be helpful. We elaborate with a general screening model that offers strong design principles for a class of security problems.

Rick Wash and Jeff MacKie-Mason. “Incentive Centered Design and Information Security,” Presented at the First Workshop on Hot Topics in Security (HotSec). July 2006.

Download: PDF

Tagged: ,

Comments are closed.

What's this?

You are currently reading Incentive Centered Design and Information Security at Rick Wash.

meta