The extreme risk of personal data breaches and the erosion of privacy

被引:71
|
作者
Wheatley, Spencer [1 ]
Maillart, Thomas [2 ]
Sornette, Didier [1 ]
机构
[1] ETH, Dept Management Technol & Econ, CH-8092 Zurich, Switzerland
[2] Univ Calif Berkeley, Sch Informat, Berkeley, CA 94720 USA
来源
EUROPEAN PHYSICAL JOURNAL B | 2016年 / 89卷 / 01期
基金
瑞士国家科学基金会; 美国国家科学基金会;
关键词
MULTIPLICATIVE PROCESSES; SIZE DISTRIBUTION;
D O I
10.1140/epjb/e2015-60754-4
中图分类号
O469 [凝聚态物理学];
学科分类号
070205 ;
摘要
Personal data breaches from organisations, enabling mass identity fraud, constitute an extreme risk. This risk worsens daily as an ever-growing amount of personal data are stored by organisations and online, and the attack surface surrounding this data becomes larger and harder to secure. Further, breached information is distributed and accumulates in the hands of cyber criminals, thus driving a cumulative erosion of privacy. Statistical modeling of breach data from 2000 through 2015 provides insights into this risk: A current maximum breach size of about 200 million is detected, and is expected to grow by fifty percent over the next five years. The breach sizes are found to be well modeled by an extremely heavy tailed truncated Pareto distribution, with tail exponent parameter decreasing linearly from 0.57 in 2007 to 0.37 in 2015. With this current model, given a breach contains above fifty thousand items, there is a ten percent probability of exceeding ten million. A size effect is unearthed where both the frequency and severity of breaches scale with organisation size like s 0.6. Projections indicate that the total amount of breached information is expected to double from two to four billion items within the next five years, eclipsing the population of users of the Internet. This massive and uncontrolled dissemination of personal identities raises fundamental concerns about privacy.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [1] The extreme risk of personal data breaches and the erosion of privacy
    Spencer Wheatley
    Thomas Maillart
    Didier Sornette
    The European Physical Journal B, 2016, 89
  • [2] Privacy Perceptions on Personal Data and Data Breaches in South Africa
    Nyoni, Phillip
    Velempini, Mthulisi
    Mavetera, Nehemiah
    AFRICAN JOURNAL OF INFORMATION SYSTEMS, 2024, 16 (03):
  • [3] NHS data breaches: a further erosion of trust
    Banner, Natalie
    BMJ-BRITISH MEDICAL JOURNAL, 2022, 377
  • [4] Protecting organisations from personal data breaches
    Phua, Clifton
    Computer Fraud and Security, 2009, 2009 (01): : 13 - 18
  • [5] Security breaches threaten personal and financial data
    Schultz, E
    COMPUTERS & SECURITY, 2004, 23 (04) : 269 - 270
  • [6] Securing OLAP data cubes against privacy breaches
    Wang, L
    Jajodia, S
    Wijesekera, D
    2004 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2004, : 161 - 175
  • [7] Can the Utility of Anonymized Data be Used for Privacy Breaches?
    Wong, Raymond Chi-Wing
    Fu, Ada Wai-Chee
    Wang, Ke
    Yu, Philip S.
    Pei, Jian
    ACM TRANSACTIONS ON KNOWLEDGE DISCOVERY FROM DATA, 2011, 5 (03)
  • [8] Vidal-Hall and Risk Management for Privacy Breaches
    Evans, Katrine
    IEEE SECURITY & PRIVACY, 2015, 13 (05) : 80 - 84
  • [9] Measuring Personal Privacy Breaches Using Third-Party Trackers
    Shuford, Erica
    Kavanaugh, Tara
    Ralph, Brian
    Ceesay, Ebrima
    Watters, Paul A.
    2018 17TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (IEEE TRUSTCOM) / 12TH IEEE INTERNATIONAL CONFERENCE ON BIG DATA SCIENCE AND ENGINEERING (IEEE BIGDATASE), 2018, : 1615 - 1618
  • [10] Hospital Risk of Data Breaches
    Bai, Ge
    Jiang, John
    Flasher, Renee
    JAMA INTERNAL MEDICINE, 2017, 177 (06) : 878 - 880