Visible to the public Modeling Fraud Prevention of Online Services Using Incident Response Trees and Value at Risk

TitleModeling Fraud Prevention of Online Services Using Incident Response Trees and Value at Risk
Publication TypeConference Paper
Year of Publication2015
AuthorsGorton, D.
Conference Name2015 10th International Conference on Availability, Reliability and Security
Date PublishedAug. 2015
PublisherIEEE
ISBN Number978-1-4673-6590-1
KeywordsComputer crime, conditional fraud value, cyber criminal, estimation theory, Europe, financial data processing, fraud, fraud prevention modelling, incident response tree, Internet, IRT, Online banking, online financial service, probability, probability estimation, pubcrawl170109, risk analysis, trees (mathematics), Trojan horses
Abstract

Authorities like the Federal Financial Institutions Examination Council in the US and the European Central Bank in Europe have stepped up their expected minimum security requirements for financial institutions, including the requirements for risk analysis. In a previous article, we introduced a visual tool and a systematic way to estimate the probability of a successful incident response process, which we called an incident response tree (IRT). In this article, we present several scenarios using the IRT which could be used in a risk analysis of online financial services concerning fraud prevention. By minimizing the problem of underreporting, we are able to calculate the conditional probabilities of prevention, detection, and response in the incident response process of a financial institution. We also introduce a quantitative model for estimating expected loss from fraud, and conditional fraud value at risk, which enables a direct comparison of risk among online banking channels in a multi-channel environment.

URLhttps://ieeexplore.ieee.org/document/7299908
DOI10.1109/ARES.2015.17
Citation Keygorton_modeling_2015