The extreme risk of personal data breaches and the erosion of privacy

被引:71
|
作者
Wheatley, Spencer [1 ]
Maillart, Thomas [2 ]
Sornette, Didier [1 ]
机构
[1] ETH, Dept Management Technol & Econ, CH-8092 Zurich, Switzerland
[2] Univ Calif Berkeley, Sch Informat, Berkeley, CA 94720 USA
来源
EUROPEAN PHYSICAL JOURNAL B | 2016年 / 89卷 / 01期
基金
瑞士国家科学基金会; 美国国家科学基金会;
关键词
MULTIPLICATIVE PROCESSES; SIZE DISTRIBUTION;
D O I
10.1140/epjb/e2015-60754-4
中图分类号
O469 [凝聚态物理学];
学科分类号
070205 ;
摘要
Personal data breaches from organisations, enabling mass identity fraud, constitute an extreme risk. This risk worsens daily as an ever-growing amount of personal data are stored by organisations and online, and the attack surface surrounding this data becomes larger and harder to secure. Further, breached information is distributed and accumulates in the hands of cyber criminals, thus driving a cumulative erosion of privacy. Statistical modeling of breach data from 2000 through 2015 provides insights into this risk: A current maximum breach size of about 200 million is detected, and is expected to grow by fifty percent over the next five years. The breach sizes are found to be well modeled by an extremely heavy tailed truncated Pareto distribution, with tail exponent parameter decreasing linearly from 0.57 in 2007 to 0.37 in 2015. With this current model, given a breach contains above fifty thousand items, there is a ten percent probability of exceeding ten million. A size effect is unearthed where both the frequency and severity of breaches scale with organisation size like s 0.6. Projections indicate that the total amount of breached information is expected to double from two to four billion items within the next five years, eclipsing the population of users of the Internet. This massive and uncontrolled dissemination of personal identities raises fundamental concerns about privacy.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [31] PERSONAL DATA PRIVACY IN THE DIGITAL AGE
    Bharwaney, Mohan
    Marwah, Azan
    HONG KONG LAW JOURNAL, 2013, 43 : 801 - 834
  • [32] The challenges of personal data markets and privacy
    Sarah Spiekermann
    Alessandro Acquisti
    Rainer Böhme
    Kai-Lung Hui
    Electronic Markets, 2015, 25 : 161 - 167
  • [33] Protection of Privacy and Personal Data in Albania
    Garunja, Evis
    CROATIAN AND COMPARATIVE PUBLIC ADMINISTRATION, 2023, 23 (01): : 91 - 116
  • [34] Data privacy in the age of personal genomics
    Dennis Grishin
    Kamal Obbad
    George M. Church
    Nature Biotechnology, 2019, 37 : 1115 - 1117
  • [35] THE ITALIAN BILL ON THE PRIVACY OF PERSONAL DATA
    LOSANO, MG
    ELETTROTECNICA, 1983, 70 (10): : 943 - 946
  • [36] Valuing Personal Data with Privacy Consideration
    Li, Xiao-Bai
    Liu, Xiaoping
    Motiwalla, Luvai
    DECISION SCIENCES, 2021, 52 (02) : 393 - 426
  • [37] Privacy inalienability and personal data chips
    Schwartz, PM
    PRIVACY AND TECHNOLOGIES OF IDENTITY: A CROSS-DISCIPLINARY CONVERSATION, 2006, : 93 - 113
  • [38] Towards Privacy in Personal Data Management
    Efraimidis, P. S.
    Drosatos, G.
    Nalbadis, F.
    Tasidou, A.
    PCI 2008: 12TH PAN-HELLENIC CONFERENCE ON INFORMATICS, PROCEEDINGS, 2008, : 3 - 7
  • [39] Data privacy in the age of personal genomics
    Grishin, Dennis
    Obbad, Kamal
    Church, George M.
    NATURE BIOTECHNOLOGY, 2019, 37 (10) : 1115 - 1117
  • [40] The challenges of personal data markets and privacy
    Spiekermann, Sarah
    Acquisti, Alessandro
    Boehme, Rainer
    Hui, Kai-Lung
    ELECTRONIC MARKETS, 2015, 25 (02) : 161 - 167