{"id":"https://openalex.org/W4307783291","doi":"https://doi.org/10.48550/arxiv.2210.15785","title":"Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment","display_name":"Supply Chain Characteristics as Predictors of Cyber Risk: A Machine-Learning Assessment","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4307783291","doi":"https://doi.org/10.48550/arxiv.2210.15785"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2210.15785","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2210.15785","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5017369402","display_name":"Kevin Hu","orcid":"https://orcid.org/0000-0001-7573-3880"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hu, Kevin","raw_affiliation_strings":["Massachusetts Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032712683","display_name":"Retsef Levi","orcid":"https://orcid.org/0000-0002-1994-4875"},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Levi, Retsef","raw_affiliation_strings":["Massachusetts Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091624653","display_name":"Raphael Yahalom","orcid":null},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yahalom, Raphael","raw_affiliation_strings":["Massachusetts Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology","institution_ids":["https://openalex.org/I63966007"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5057493110","display_name":"El Ghali Zerhouni","orcid":null},"institutions":[{"id":"https://openalex.org/I63966007","display_name":"Massachusetts Institute of Technology","ror":"https://ror.org/042nb2s44","country_code":"US","type":"education","lineage":["https://openalex.org/I63966007"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zerhouni, El Ghali","raw_affiliation_strings":["Massachusetts Institute of Technology"],"affiliations":[{"raw_affiliation_string":"Massachusetts Institute of Technology","institution_ids":["https://openalex.org/I63966007"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":60},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9853,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9853,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9681,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11864","display_name":"Supply Chain Resilience and Risk Management","score":0.9646,"subfield":{"id":"https://openalex.org/subfields/1408","display_name":"Strategy and Management"},"field":{"id":"https://openalex.org/fields/14","display_name":"Business, Management and Accounting"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/data-breach","display_name":"Data breach","score":0.64542925},{"id":"https://openalex.org/keywords/enterprise-data-management","display_name":"Enterprise data management","score":0.44608372},{"id":"https://openalex.org/keywords/enterprise-private-network","display_name":"Enterprise private network","score":0.4358849}],"concepts":[{"id":"https://openalex.org/C108713360","wikidata":"https://www.wikidata.org/wiki/Q1824206","display_name":"Supply chain","level":2,"score":0.71567345},{"id":"https://openalex.org/C165609540","wikidata":"https://www.wikidata.org/wiki/Q1172486","display_name":"Data breach","level":2,"score":0.64542925},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5608261},{"id":"https://openalex.org/C32896092","wikidata":"https://www.wikidata.org/wiki/Q189447","display_name":"Risk management","level":2,"score":0.52242225},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.5209445},{"id":"https://openalex.org/C11489865","wikidata":"https://www.wikidata.org/wiki/Q944806","display_name":"Operational risk","level":3,"score":0.49240196},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4765442},{"id":"https://openalex.org/C207209096","wikidata":"https://www.wikidata.org/wiki/Q848268","display_name":"Enterprise risk management","level":3,"score":0.47032154},{"id":"https://openalex.org/C136227091","wikidata":"https://www.wikidata.org/wiki/Q5380376","display_name":"Enterprise data management","level":3,"score":0.44608372},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.44334647},{"id":"https://openalex.org/C149859251","wikidata":"https://www.wikidata.org/wiki/Q483426","display_name":"Enterprise private network","level":2,"score":0.4358849},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3125124},{"id":"https://openalex.org/C27295321","wikidata":"https://www.wikidata.org/wiki/Q831795","display_name":"Enterprise information system","level":2,"score":0.2995004},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.24848947},{"id":"https://openalex.org/C10138342","wikidata":"https://www.wikidata.org/wiki/Q43015","display_name":"Finance","level":1,"score":0.131957},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C162853370","wikidata":"https://www.wikidata.org/wiki/Q39809","display_name":"Marketing","level":1,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2210.15785","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2210.15785","pdf_url":"http://arxiv.org/pdf/2210.15785","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2210.15785","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2210.15785","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4367296151","https://openalex.org/W380516208","https://openalex.org/W3123584172","https://openalex.org/W2607945619","https://openalex.org/W2377685380","https://openalex.org/W2376588887","https://openalex.org/W2353336844","https://openalex.org/W2352106690","https://openalex.org/W2293179011","https://openalex.org/W2086339938"],"abstract_inverted_index":{"This":[0],"paper":[1,34,53,101],"provides":[2,35,189],"the":[3,10,33,36,63,66,100,138,144,166,173],"first":[4,37],"large-scale":[5],"data-driven":[6],"analysis":[7],"to":[8,61,103,114,120,127,181,193,199],"evaluate":[9],"predictive":[11],"power":[12,113,168],"of":[13,19,48,65,99],"different":[14],"attributes":[15,44],"for":[16],"assessing":[17],"risk":[18,57,161,178],"cyberattack":[20,85,184],"data":[21,153],"breaches.":[22],"Furthermore,":[23],"motivated":[24],"by":[25,81,147],"rapid":[26],"increase":[27],"in":[28,165],"third":[29,83,182],"party":[30,84,183],"enabled":[31],"cyberattacks,":[32],"quantitative":[38,97],"empirical":[39],"evidence":[40],"that":[41,59,78,105,131,150],"digital":[42],"supply-chain":[43],"are":[45,79],"significant":[46,111,170],"predictors":[47],"enterprise":[49,67,116,136],"cyber":[50,56,117,152],"risk.":[51],"The":[52,95],"leverages":[54],"outside-in":[55],"scores":[58],"aim":[60],"capture":[62],"quality":[64],"internal":[68,135],"cybersecurity":[69,177],"management,":[70],"but":[71],"augment":[72],"these":[73,163,201],"with":[74],"supply":[75,106,139],"chain":[76,107,140],"features":[77,109,142],"inspired":[80],"observed":[82],"scenarios,":[86],"as":[87,89,192],"well":[88],"concepts":[90],"from":[91],"network":[92,108,141],"science":[93],"research.":[94],"main":[96],"result":[98],"is":[102,155],"show":[104],"add":[110],"detection":[112],"predicting":[115],"risk,":[118],"relative":[119],"merely":[121],"using":[122],"enterprise-only":[123],"attributes.":[124],"Particularly,":[125],"compared":[126],"a":[128,156],"base":[129],"model":[130,174],"relies":[132],"only":[133],"on":[134],"features,":[137],"improve":[143],"out-of-sample":[145],"AUC":[146],"2.3\\%.":[148],"Given":[149],"each":[151],"breach":[154,186],"low":[157],"probability":[158],"high":[159],"impact":[160],"event,":[162],"improvements":[164],"prediction":[167],"have":[169],"value.":[171],"Additionally,":[172],"highlights":[175],"several":[176],"drivers":[179],"related":[180],"and":[185,188],"mechanisms":[187],"important":[190],"insights":[191],"what":[194],"interventions":[195],"might":[196],"be":[197],"effective":[198],"mitigate":[200],"risks.":[202]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4307783291","counts_by_year":[],"updated_date":"2024-12-07T17:56:14.871852","created_date":"2022-11-05"}