Modeling Fraud Prevention of Online Services Using Incident Response Trees and Value at Risk
Title | Modeling Fraud Prevention of Online Services Using Incident Response Trees and Value at Risk |
Publication Type | Conference Paper |
Year of Publication | 2015 |
Authors | Gorton, D. |
Conference Name | 2015 10th International Conference on Availability, Reliability and Security |
Date Published | Aug. 2015 |
Publisher | IEEE |
ISBN Number | 978-1-4673-6590-1 |
Keywords | Computer crime, conditional fraud value, cyber criminal, estimation theory, Europe, financial data processing, fraud, fraud prevention modelling, incident response tree, Internet, IRT, Online banking, online financial service, probability, probability estimation, pubcrawl170109, risk analysis, trees (mathematics), Trojan horses |
Abstract | Authorities like the Federal Financial Institutions Examination Council in the US and the European Central Bank in Europe have stepped up their expected minimum security requirements for financial institutions, including the requirements for risk analysis. In a previous article, we introduced a visual tool and a systematic way to estimate the probability of a successful incident response process, which we called an incident response tree (IRT). In this article, we present several scenarios using the IRT which could be used in a risk analysis of online financial services concerning fraud prevention. By minimizing the problem of underreporting, we are able to calculate the conditional probabilities of prevention, detection, and response in the incident response process of a financial institution. We also introduce a quantitative model for estimating expected loss from fraud, and conditional fraud value at risk, which enables a direct comparison of risk among online banking channels in a multi-channel environment. |
URL | https://ieeexplore.ieee.org/document/7299908 |
DOI | 10.1109/ARES.2015.17 |
Citation Key | gorton_modeling_2015 |
- internet
- Trojan horses
- trees (mathematics)
- risk analysis
- pubcrawl170109
- probability estimation
- probability
- online financial service
- Online banking
- IRT
- Computer crime
- incident response tree
- fraud prevention modelling
- fraud
- financial data processing
- Europe
- estimation theory
- cyber criminal
- conditional fraud value