Cybersecurity dynamics in software development environment. What system traps do exist?
dc.contributor.author | Zeijlemaker, Sander | |
dc.contributor.author | von Kutzschenbach, Michael | |
dc.date.accessioned | 2024-04-24T06:20:40Z | |
dc.date.available | 2024-04-24T06:20:40Z | |
dc.date.issued | 2020 | |
dc.description.abstract | Increasing dependency on information technology and an increasing number of cyber-attacks give rise to concerns about secure software development methods. Building system dynamics models we research and compare the structure underlying the behaviour relevant to security software developments for both agile and traditional software delivery methods. The difference between these models is related to the key characteristics of these methods, but not to the security aspects itself. Both dynamic models show similar structures to developing software and cybersecurity dynamics. Our study shows that network externalities may evoke the acceptance trap. The acceptance trap begins when insecure software is brought into production and is actively used, because if software is available, it can generate income, while further security development will cost more money. Insecure software means the software still contains vulnerabilities that can be exploited by cybercriminals in near future. In order to exploit these vulnerabilities cybercriminals will launch cyber attackers. In such situation there may be a contamination effect caused by successful attacks may evoke more cybercriminal activities. These ongoing cyber-attacks will have such an impact that more and more security improvements and incident responses are needed, which result in increasingly higher costs. As a result, less capacity will be available for future software development. The model structures suggest that more time and money spent on security testing and resolving vulnerabilities helps to avoid the acceptance trap. Similar conclusions have been formulated in the field of Internet of Things adaptation research. Further model quantification, validation, and policy evaluation should provide further insights and recommendations to resolve the acceptance trap. | |
dc.event | 38th international conference of the system dynamics society | |
dc.event.end | 2020-07-24 | |
dc.event.start | 2020-07-19 | |
dc.identifier.isbn | 978-1-7138-2021-5 | |
dc.identifier.uri | https://irf.fhnw.ch/handle/11654/43073 | |
dc.language.iso | en | |
dc.publisher | System dynamics society | |
dc.relation.ispartof | Proceedings of the 38th International Conference of the System Dynamics Society | |
dc.spatial | Online | |
dc.subject.ddc | 330 - Wirtschaft | |
dc.title | Cybersecurity dynamics in software development environment. What system traps do exist? | |
dc.type | 04B - Beitrag Konferenzschrift | |
dspace.entity.type | Publication | |
fhnw.InventedHere | Yes | |
fhnw.ReviewType | Anonymous ex ante peer review of a complete publication | |
fhnw.affiliation.hochschule | Hochschule für Wirtschaft FHNW | de_CH |
fhnw.affiliation.institut | Institut für Unternehmensführung | de_CH |
fhnw.openAccessCategory | Closed | |
fhnw.publicationState | Published | |
relation.isAuthorOfPublication | eb99e39c-5f93-42fe-a5be-1f59ae5188f8 | |
relation.isAuthorOfPublication.latestForDiscovery | eb99e39c-5f93-42fe-a5be-1f59ae5188f8 |
Dateien
Lizenzbündel
1 - 1 von 1
Kein Vorschaubild vorhanden
- Name:
- license.txt
- Größe:
- 1.36 KB
- Format:
- Item-specific license agreed upon to submission
- Beschreibung: