{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T16:23:03Z","timestamp":1764174183016,"version":"3.40.3"},"publisher-location":"Cham","reference-count":29,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319241739"},{"type":"electronic","value":"9783319241746"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-24174-6_25","type":"book-chapter","created":{"date-parts":[[2015,10,9]],"date-time":"2015-10-09T11:36:32Z","timestamp":1444390592000},"page":"483-502","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Should Cyber-Insurance Providers Invest in Software Security?"],"prefix":"10.1007","author":[{"given":"Aron","family":"Laszka","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,1,13]]},"reference":[{"key":"25_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1007\/3-540-58618-0_67","volume-title":"Computer Security - ESORICS 94","author":"RJ Anderson","year":"1994","unstructured":"Anderson, R.J.: Liability and computer security: nine principles. In: Gollmann, D. (ed.) ESORICS 1994. LNCS, vol. 875, pp. 231\u2013245. Springer, Heidelberg (1994)"},{"issue":"5","key":"25_CR2","doi-asserted-by":"publisher","first-page":"934","DOI":"10.1287\/mnsc.1100.1304","volume":"57","author":"T August","year":"2011","unstructured":"August, T., Tunca, T.: Who should be responsible for software security? A comparative analysis of liability policies in network environments. Manag. Sci. 57(5), 934\u2013959 (2011)","journal-title":"Manag. Sci."},{"issue":"1","key":"25_CR3","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MSP.2009.24","volume":"7","author":"K Birman","year":"2009","unstructured":"Birman, K., Schneider, F.: The monoculture risk put into context. IEEE Secur. Priv. 7(1), 14\u201317 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"25_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"298","DOI":"10.1007\/11766155_21","volume-title":"Emerging Trends in Information and Communication Security","author":"R B\u00f6hme","year":"2006","unstructured":"B\u00f6hme, R.: A comparison of market approaches to software vulnerability disclosure. In: M\u00fcller, G. (ed.) ETRICS 2006. LNCS, vol. 3995, pp. 298\u2013311. Springer, Heidelberg (2006)"},{"issue":"5","key":"25_CR5","first-page":"290","volume":"52","author":"R B\u00f6hme","year":"2010","unstructured":"B\u00f6hme, R.: Towards insurable network architectures. IT - Inf. Technol. 52(5), 290\u2013293 (2010)","journal-title":"IT - Inf. Technol."},{"key":"25_CR6","unstructured":"B\u00f6hme, R., Kataria, G.: Models and measures for correlation in cyber-insurance. In: Proceedings of the 5th Workshop on the Economics of Information Security (WEIS) (2006)"},{"key":"25_CR7","unstructured":"B\u00f6hme, R., Schwartz, G.: Modeling cyber-insurance: Towards a unifying framework. In: Proceedings of the 9th Workshop on the Economics of Information Security (WEIS) (2010)"},{"key":"25_CR8","unstructured":"Brodkin, J.: Google and Samsung soar into list of top 10 Linux contributors (2013). http:\/\/arstechnica.com\/information-technology\/2013\/09\/google-and-samsung-soar-into-list-of-top-10-linux-contributors\/"},{"issue":"2","key":"25_CR9","doi-asserted-by":"publisher","first-page":"397","DOI":"10.2307\/23044049","volume":"35","author":"P Chen","year":"2011","unstructured":"Chen, P., Kataria, G., Krishnan, R.: Correlated failures, diversification, and information security risk management. MIS Q. 35(2), 397\u2013422 (2011)","journal-title":"MIS Q."},{"key":"25_CR10","doi-asserted-by":"crossref","unstructured":"Egelman, S., Herley, C., van Oorschot, P.: Markets for zero-day exploits: ethics and implications. In: Proceedings of the 2013 New Security Paradigms Workshop (NSPW), Banff, Canada, pp. 41\u201346 (2013)","DOI":"10.1145\/2535813.2535818"},{"key":"25_CR11","unstructured":"Finifter, M., Akhawe, D., Wagner, D.: An empirical study of vulnerability rewards programs. In: Proceedings of the 22nd USENIX Security Symposium, Washington, DC, August 2013"},{"key":"25_CR12","unstructured":"Geer, D., Pfleeger, C., Schneier, B., Quarterman, J., Metzger, P., Bace, R., Gutmann, P.: Cyberinsecurity: The cost of monopoly. How the dominance of Microsoft\u2019s products poses a risk to society (2003)"},{"key":"25_CR13","doi-asserted-by":"crossref","unstructured":"Grossklags, J., Christin, N., Chuang, J.: Secure or insure?: a game-theoretic analysis of information security games. In: Proceedings of the 17th International World Wide Web Conference, pp. 209\u2013218 (2008)","DOI":"10.1145\/1367497.1367526"},{"issue":"4","key":"25_CR14","doi-asserted-by":"publisher","first-page":"297","DOI":"10.1007\/BF00435537","volume":"7","author":"W Hanson","year":"1996","unstructured":"Hanson, W., Putler, D.: Hits and misses: Herd behavior and online product popularity. Mark. Lett. 7(4), 297\u2013305 (1996)","journal-title":"Mark. Lett."},{"key":"25_CR15","unstructured":"Hoffer, D.: A survey of economically targeted investments: opportunities for public pension funds (2004). http:\/\/www.vermonttreasurer.gov\/sites\/treasurer\/files\/pdf\/misc\/econTargetInvestReport20040216.pdf"},{"issue":"5","key":"25_CR16","doi-asserted-by":"publisher","first-page":"413","DOI":"10.1002\/mar.20119","volume":"23","author":"J Huang","year":"2006","unstructured":"Huang, J., Chen, Y.: Herding in online product choice. Psychol. Mark. 23(5), 413\u2013428 (2006)","journal-title":"Psychol. Mark."},{"key":"25_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-642-25280-8_11","volume-title":"Decision and Game Theory for Security","author":"B Johnson","year":"2011","unstructured":"Johnson, B., B\u00f6hme, R., Grossklags, J.: Security games with market insurance. In: Baras, J.S., Katz, J., Altman, E. (eds.) GameSec 2011. LNCS, vol. 7037, pp. 117\u2013130. Springer, Heidelberg (2011)"},{"key":"25_CR18","doi-asserted-by":"crossref","unstructured":"Johnson, B., Laszka, A., Grossklags, J.: The complexity of estimating systematic risk in networks. In: Proceedings of the 27th IEEE Computer Security Foundations Symposium (CSF), pp. 325\u2013336 (2014)","DOI":"10.1109\/CSF.2014.30"},{"key":"25_CR19","doi-asserted-by":"crossref","unstructured":"Johnson, B., Laszka, A., Grossklags, J.: How many down? toward understanding systematic risk in networks. In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security (ASIACCS), pp. 495\u2013500 (2014)","DOI":"10.1145\/2590296.2590308"},{"issue":"2","key":"25_CR20","first-page":"23:1","volume":"47","author":"A Laszka","year":"2014","unstructured":"Laszka, A., Felegyhazi, M., Buttyan, L.: A survey of interdependent information security games. ACM Comput. Surv. 47(2), 23:1\u201323:38 (2014)","journal-title":"ACM Comput. Surv."},{"key":"25_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1007\/978-3-662-45472-5_27","volume-title":"Financial Cryptography and Data Security","author":"A Laszka","year":"2014","unstructured":"Laszka, A., Johnson, B., Grossklags, J., Felegyhazi, M.: Estimating systematic risk in real-world networks. In: Christin, N., Safavi-Naini, R. (eds.) FC 2014. LNCS, vol. 8437, pp. 412\u2013430. Springer, Heidelberg (2014)"},{"key":"25_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-642-40203-6_16","volume-title":"Computer Security \u2013 ESORICS 2013","author":"A Laszka","year":"2013","unstructured":"Laszka, A., Johnson, B., Sch\u00f6ttle, P., Grossklags, J., B\u00f6hme, R.: Managing the weakest link. In: Crampton, J., Jajodia, S., Mayes, K. (eds.) ESORICS 2013. LNCS, vol. 8134, pp. 273\u2013290. Springer, Heidelberg (2013)"},{"key":"25_CR23","doi-asserted-by":"crossref","unstructured":"Lelarge, M., Bolot, J.: Economic incentives to increase security in the internet: the case for insurance. In: Proceedings of the 33rd IEEE International Conference on Computer Communications (INFOCOM), pp. 1494\u20131502 (2009)","DOI":"10.1109\/INFCOM.2009.5062066"},{"key":"25_CR24","unstructured":"Ozment, A.: Bug auctions: vulnerability markets reconsidered. In: Proceedings of the 3rd Workshop on the Economics of Information Security (WEIS), Minneapolis, MN, May 2004"},{"key":"25_CR25","unstructured":"Ozment, A.: The likelihood of vulnerability rediscovery and the social utility of vulnerability hunting. In: Proceedings of the 4th Workshop on the Economics of Information Security (WEIS), Cambridge, MA, June 2005"},{"issue":"1","key":"25_CR26","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1109\/MSP.2005.17","volume":"3","author":"E Rescorla","year":"2005","unstructured":"Rescorla, E.: Is finding security holes a good idea? IEEE Secur. Priv. 3(1), 14\u201319 (2005)","journal-title":"IEEE Secur. Priv."},{"key":"25_CR27","unstructured":"Schneier, B.: Schneier on security: liability changes everything (2003). https:\/\/www.schneier.com\/essays\/archives\/2003\/11\/liability_changes_ev.html"},{"key":"25_CR28","first-page":"1","volume-title":"Economics of Information Security","author":"H Varian","year":"2004","unstructured":"Varian, H.: System reliability and free riding. In: Camp, J., Lewis, S. (eds.) Economics of Information Security, pp. 1\u201315. Kluwer Academic Publishers, Dordrecht (2004)"},{"key":"25_CR29","doi-asserted-by":"crossref","unstructured":"Zhao, M., Grossklags, J., Chen, K.: An exploratory study of white hat behaviors in a web vulnerability disclosure program. In: Proceedings of the 2014 ACM Workshop on Security Information Workers (SIW), pp. 51\u201358 (2014)","DOI":"10.1145\/2663887.2663906"}],"container-title":["Lecture Notes in Computer Science","Computer Security -- ESORICS 2015"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-24174-6_25","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,17]],"date-time":"2023-11-17T08:03:57Z","timestamp":1700208237000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-24174-6_25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319241739","9783319241746"],"references-count":29,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-24174-6_25","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]},"assertion":[{"value":"13 January 2016","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}