K-INFO
HU
EN
Login

Security and Privacy: an Economic Approach

Security and Privacy: an Economic Approach
A tantárgyleírás hatályossága
Hatályosság kezdete:
2026. March 21.
Hatályosság vége:
Subject name (Hungarian, English)
Security and Privacy: an Economic Approach
Security and Privacy: an Economic Approach
Subject code BMEVIHIAV34
Subject type
Training Level
Course types and hours (weekly/semester)
Course type lecture tutorial laboratory
hours (weekly) 2 0 0
type (linked/independent)
Assessment type félévközi érdemjegy
Credits 2
Subject coordinator
DR. Biczók Gergely
position: egyetemi docens
Responsible department
Hálózati Rendszerek és Szolgáltatások Tanszék
Faculty Villamosmérnöki és Informatikai Kar
Subject website
Primary curriculum type
Direct prerequisites – Strong prerequisite none
Direct prerequisites – Weak prerequisite none
Direct prerequisites – Parallel prerequisite none
Direct prerequisites – Milestone prerequisite none
Direct prerequisites – Exclusion none

Objectives

Programme
1. week
Introduction to system security, concepts, actors and security solutions. Detailed discussion of economics issues, motivation for the participants and misaligned incentives.

2. week
Tutorial on microeconomics concepts: game theory primer, normal- and extensive-form games, game solutions and equilibrium concepts, the Prisoner's Dilemma, externalities, the Tragedy of the Commons

3. week
Interdependent security, risks and dependency, total effort, weakest link and best shot models, security investment of selfish participants and equilibrium solutions

4. week
Misaligned incentives of the participants, ISPs involvement in mitigating security risks, detailed assessment of intervention power for various participants, user motivation and its failure, asymmetric information and lemon markets

5. week
Generic model of security investments: the Gordon-Loeb model and its follow-up work, iterated security investments and investment options

6. week
The problem of spam and related issues, motivation for spammers, economics solutions for software flaws

7. week
Measuring the underground economy, spammers, carders and exploits

8. week
Information sharing models, incentives and impact to reveal security breaches, information sharing for software vulnerabilities: vulnerability markets, cooperation against phishing

9. week
Economics of privacy and anonymity, privacy issues and threats, behavioral economics point of view, user privacy evaluation, price discrimination and usability, privacy policies

10. week
Economics of privacy in social networks, privacy of Facebook, privacy policies of social networks, anonymizing private data

11. week
Adoption of security technologies, case studies of SSH and PGP, digital rights management and trusted computing

12. week
Cyber-insurance for security and privacy risk management, issues and solutions, market models, asymmetric information and correlated incidents

13-14. week
Advanced topics and additional discussion

The goal of the course is to give a comprehensive overview of the economics of information security and privacy. This novel point of view is able to shed light on many security problems and promises the solutions to these problems. The economics point of view is particularly appropriate to analyze the incentives of users, service providers and other networking participants and to promises solutions to security issues that arise due to misaligned incentives. The course is taught in English.

Learning outcomes

Ez a tantárgy a KKK rendeletben meghatározott, következő kompetenciák fejlesztését szolgálja:

Knowledge

No learning outcomes recorded.

Skills

No learning outcomes recorded.

Attitudes

No learning outcomes recorded.

Autonomy and responsibility

No learning outcomes recorded.

Oktatási módszertan

Lectures

Tanulástámogató anyagok

Online források
Course material (lecture notes) is available in electronic format.; Ross Anderson, Rainer Böhme, Richard Clayton, and Tyler Moore, "Security, Economics, and the Internal Market," published by the European Network and Information Security Agency (ENISA)”, 2008; "Anderson, Ross J. Security Engineering: A; Guide to Building Dependable Distributed Systems. John Wiley & Sons,; 2010."

Recommended preliminary knowledge for completing the subject

Knowledge type competencies
(azon előzetes ismeretek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
computer networks, network security
Skill type competencies
(azon előzetes képességek és készségek összessége, amelyek megléte nem kötelező, de a tantárgy eredményes teljesítését nagyban elősegíti)
nincs
Recommended (non-compulsory) preliminary competencies
(azon ajánlott (nem kötelező) előzetesen megszerzendő kompetenciák összessége, amelyek jelentősen hozzájárulnak a tantárgy eredményes teljesítéséhez)
computer networks, network security
General rules
Requirements: a.     during the semester: Fulfilling the requirements 1 classroom test. The final grade is the grade obtained for the test. b.    during the exam period: - c.    preliminary exam: - Additional possibilities: Failed classroom tests can be retaken again on the supplement week.
Assessment methods
In-term assessments

No detailed assessments provided.

Weight of in-term assessments

No weights provided.

Exam-period assessments

No detailed assessments provided.

Weight of exam elements

No weights provided.

Grade calculation

No grade thresholds provided.

Attendance requirements

No attendance requirements provided.

Rules for retake and resubmission

Not provided.

Short description

Not provided.

Detailed description

Not provided.

Recommended courses
The course cannot be taken for students who already took VIHIAV15 Economics of Security and Privacy.
Workload to complete the subject

No workload breakdown provided.

Validity of subject requirements
Requirements valid from:
Requirements valid until:
Curriculum placement

No curriculum placements recorded for this subject version.