Empirical Investigation of Threats to Loyalty Programs by Using Models Inspired by the Gordon-Loeb Formulation of Security Investment — Oak Academic Publishing
Research ArticleOpen AccessGoogle Scholar indexed
Empirical Investigation of Threats to Loyalty Programs by Using Models Inspired by the Gordon-Loeb Formulation of Security Investment
Institute of Industrial Science, The University of Tokyo, Tokyo, Japan
,
Institute of Industrial Science, The University of Tokyo, Tokyo, Japan
1 Institute of Industrial Science, The University of Tokyo, Tokyo, Japan
2 Institute of Industrial Science, The University of Tokyo, Tokyo, Japan
Loyalty program (LP) is a popular marketing activity of enterprises. As a result of firms’ effort to increase customers’ loyalty, point exchange or redemption services are now available worldwide. These services attract not only customers but also attackers. In pioneering research, which first focused on this LP security problem, an empirical analysis based on Japanese data is shown to see the effects of LP-point liquidity on damages caused by security incidents. We revisit the empirical models in which the choice of variables is inspired by the Gordon-Loeb formulation of security investment: damage, investment, vulnerability, and threat. The liquidity of LP points corresponds to the threat in the formulation and plays an important role in the empirical study because it particularly captures the feature of LP networks. However, the actual proxy used in the former study is artificial. In this paper, we reconsider the liquidity definition based on a further observation of LP security incidents. By using newly defined proxies corresponding to the threat as well as other refined proxies, we test hypotheses to derive more implications that help LP operators to manage partnerships; the implications are consistent with recent changes in the LP network. Thus we can see the impacts of security investment models include a wider range of empirical studies.
Sharp, B. and Sharp, A. (1997) Loyalty Programs and Their Impact on Repeat-Purchase Loyalty Patterns. International Journal of Research in Marketing, 14, 473-486. http://dx.doi.org/10.1016/S0167-8116(97)00022-0
PricewaterhouseCoopers LLP (2013) Loyalty Analytics Exposed: What Every Program Manager Needs to Know. http://www.pwc.com/en_US/us/insurance/publications/assets/pwc-loyalty-analytics-exposed.pdf
Zhang, J. and Breugelmans, E. (2012) The Impact of an Item-Based Loyalty Program on Consumer Purchase Behavior. Journal of Marketing Research, 49, 50-65. http://dx.doi.org/10.1509/jmr.09.0211
Katsumata, S. and Wakabayashi, T. (2014) Loyalty Program Point Exchange Networks and Their Impact on Marketing Performance. Faculty of Economics, Nagasaki University Discussion Paper Series, 2014, 1-19.
Jenjarrussakul, B. and Matsuura, K. (2014) Analysis of Japanese Loyalty Programs Considering Liquidity, Security Efforts, and Actual Security Levels. The 13th Workshop on the Economics of Information Security, Pennsylvania, 23-24 June 2014.
Gordon, L.A. and Loeb, M.P. (2002) The Economics of Information Security Investment. ACM Transactions on Information and System Security, 5, 438-457. http://dx.doi.org/10.1145/581271.581274
Willemson, J. (2006) On the Gordon & Loeb Model for Information Security Investment. The 5th Workshop on the Economics of Information Security, Cambridge, 26-28 June 2006.
Matsuura, K. (2008) Productivity Space of Information Security in an Extension of the Gordon-Loeb’s Investment Model. The 7th Workshop on the Economics of Information Security, New Hampshire, 25-28 June 2008.
DarkReading.com (2015) British Airways the Latest Loyalty Program Breach Victim. http://www.darkreading.com/attacks-breaches/british-airways-the-latest-loyalty-program-breach-victim/d/d-id/1319683
Krebs on Security (2014) Thieves Cash out Rewards, Points Accounts. http://krebsonsecurity.com/2014/11/thieves-cash-out-rewards-points-accounts/
The Dallas Morning News (2015) Cyberthieves Steal Miles from American, United Customers. http://www.dallasnews.com/business/airline-industry/20150112-american-united-airlines-targets-of-attempt-to-steal-customers-miles.ece
My Bank Tracker (2015) Lesson from Starbucks: Creative Ways That Hackers Can Steal from You. http://www.mybanktracker.com/news/lesson-starbucks-creative-ways-hackers-steal
TrendMicro (2014) TrendLabs 2Q 2014 Security Roundup in Japan. (In Japanese) http://www.trendmicro.co.jp/cloud-content/jp/pdfs/security-intelligence/threat-report/pdf-2014q2-20140819. pdf?cm_sp=threat-_-sr-2014q2-_-lp-txt
G-PLAN INC (2012) Correspondence to the Unauthorized Accesses to G-Point. (In Japanese) http://www.gpoint.co.jp/company/service/gplan20120418.pdf
ITmedia Enterprise (2013) Unauthorized Access to T-Point, 299 Accounts Were Compromised. (In Japanese) http://www.itmedia.co.jp/enterprise/articles/1304/07/news005.html
Record China (2013) Chinese Students Were Arrested. They Exchanged 250 Accounts Rakuten Points into Electric Money. (In Japanese) http://www.recordchina.co.jp/a80323.html
NTT Communications Online Marketing Solutions (2014) The Report of Unauthorized Access to Potora. (In Japanese) http://www.nttcoms.com/page.jsp?id=2409
ITpro (2014) Unauthorized Access to JAL Mileage Website, JAL Requested 27 Million People to Change Their Passwords. (In Japanese) http://itpro.nikkeibp.co.jp/article/NEWS/20140203/534282/
Nikkei (2014) Enormous Unauthorized Access Attempted to JR East. (In Japanese) http://itpro.nikkeibp.co.jp/atcl/news/14/081800465/
Hatena Co., Ltd. (2014) Please Confirm Your Password and Registration Information in Order to Prevent Unauthorized Access. (In Japanese) http://hatena.g.hatena.ne.jp/hatena/20140224/1393211701
ITpro (2014) 1.12 Million Miles of ANA Mileage Club Were Stolen, Personal Information Such as Addresses Might Be Browsed. (In Japanese) http://itpro.nikkeibp.co.jp/article/NEWS/20140311/542563/
Poitan News (2014) Unauthorized Access to My JCB and Redeemed to T-Point. (In Japanese) http://www.poitan.jp/archives/3138
Sony Marketing (Japan) Inc. (2014) The Report of Unauthorized Access to Sony Point Service and a Request for Changing Passwords. (In Japanese) https://www.sony.jp/info/pw_management2.html
Security NEXT (2014) 0.22 Million Unauthorized Accesses to Niconico Video, 0.17 Million Yen Loss. (In Japanese) http://www.security-next.com/049575
Security NEXT (2014) Unauthorized Access to Hatena, Redemption to Amazon Gift Code Was Failed in Attempts. (In Japanese) http://www.security-next.com/049827
Security NEXT (2014) 11502 Unauthorized Accesses to a Questionnaire Website and Some Points Were Stolen. (In Japanese) http://www.security-next.com/049982
Scan Net Security (2014) A Questionnaire Website, Anpara, Was Attacked and Some Points Were Stolen. (In Japanese) http://scan.netsecurity.ne.jp/article/2014/07/08/34495.html
NTT Communications Corporation (2014) Unauthorized Access to Poin-Talk and Goo-Points. (In Japanese) http://www.ntt.com/release/monthNEWS/detail/20140730.html
ITpro (2014) Enormous Number of Accesses to Suica Point Club, Unauthorized Access to Some Acounts. (In Japanese) http://itpro.nikkeibp.co.jp/atcl/news/14/081800465/
D Style Web (2014) Information of Unauthorized Access and Unauthorized Point Redemption. (In Japanese) http://www.dstyleweb.com/20141028/
Security NEXT (2014) Unauthorized Access to a Research Service of Kyushu Electric Power, Which Was Detected When the Operator Found the Number of Exchanges Is 10 Times as Many as Usual. (In Japanese) http://www.security-next.com/054803
Mixi, Inc. (2015) The Report of Unauthorized Accesses to Morappo and Mixi Questionnaire Using the Passwords Which Were Leaked at the Third Party. (In Japanese) http://mixi.co.jp/press/2015/0109/15881/
AIP Corporation (2015) Unauthorized Access, Point Redemption and Personal Information Browsing. (In Japanese) http://www.aip-global.com/JP/corporate/releases/20150701.html
Lifemedia, Inc. (2015) The Report of Unauthorized Access to Lifemedia. (In Japanese) http://lifemedia.jp/utilization/info_d20150713.html
Orient Corporation (2015) Unauthorized Access to Customer Web Services. (In Japanese) http://www.orico.co.jp/information/20150727.html
PrizePrize (2015) The Report of Unauthorized Point Redemptions and Our Request for Changing Your Passwords. (In Japanese) http://www.moneyforall.net/rss/single.php?id=121
Washington Hotel (2015) The Report of Unauthorized Access to Lodging Net Point and Our Request for Changing Your Password. (In Japanese) http://www.washingtonhotel.co.jp/pdf/info20150805.pdf
Wakabayashi, T. (2008) Structure and Formation of the Exchange Market of Point Programs and Electronic Moneys. (In Japanese) Organizational Science, 42, 47-60.
Wakabayashi, T. and Katsumata, S. (2013) Which Factor Matters to the Formation of Strategic Alliance Network: Industry, Firm or Network? (In Japanese) Oganizational Science, 47, 69-79.
Yuhashi, H. and Gotou, H. (2010) The Reliability of the New Economic Platform: Mobile Value Exchange Alliance Network. 18th Biennial ITS Conference, Tokyo, 27-30 June 2010.
European Central Bank (2012) Virtual Currency Schemes. http://www.ecb.europa.eu/pub/pdf/other/virtualcurrencyschemes201210en.pdf
Moore, T. and Christin, N. (2013) Beware the Middleman: Empirical Analysis of Bitcoin-Exchange Risk. Financial Cryptography and Data Security, 7859, 25-33. http://dx.doi.org/10.1007/978-3-642-39884-1_3
Vasek, M., Thornton, M. and Moore, T. (2014) Empirical Analysis of Denial-of-Service Attacks in the Bitcoin Ecosystem. Financial Cryptography and Data Security, 8438, 57-71. http://dx.doi.org/10.1007/978-3-662-44774-1_5
Johnson, B., Laszka, A., Grossklags, J., Vasek, M. and Moore, T. (2014) Game-Theoretic Analysis of DDoS Attacks against Bitcoin Mining Pools. Financial Cryptography and Data Security, 8438, 72-86. http://dx.doi.org/10.1007/978-3-662-44774-1_6
Kroll, J.A., Davey, I.C. and Felten, E.W. (2013) The Economics of Bitcoin Mining, or Bitcoin in the Presence of Adversaries. The 12th Workshop on the Economics of Information Security, Washington DC, 11-12 June 2013.
Hu, J. and Zambetta, F. (2008) Security Issues in Massive Online Games. Security and Communication Networks, 1, 83-92. http://dx.doi.org/10.1002/sec.5
Ku, Y., Chen, Y., Wu, K. and Chiu, C. (2007) An Empirical Analysis of Online Gaming Crime Characteristics from 2002 to 2004. Intelligence and Security Informatics, 4430, 34-45. http://dx.doi.org/10.1007/978-3-540-71549-8_3
Bardzell, J., Jakobsson, M., Bardzell, S., Pace, T., Odom, W. and Houssian, A. (2007) Virtual Worlds and Fraud: Approaching Cybersecurity in Massively Multiplayer Online Games. Proceedings of DiGRA 2007 Conference, Tokyo, 24-28 September 2007, 451-742.
Kiondo, C., Kowalski, S. and Yngstrom, L. (2011) Exploring Security Risks in Virtual Economies. 1st International Conference on Social Eco-Informatics, Barcelona, 23-29 October 2011.
Irwin, A.S.M. and Slay, J. (2010) Detecting Money Laundering and Terrorism Financing Activity in Second Life and World of Warcraft. Proceedings of the 1st International Cyber Resilience Conference, Perth, 23-24 August 2010, 41-50.
Ministry of Economy, Trade and Industry (2013) Survey on Information Processing in 2012: Result Detail Part 3— Information Security. (In Japanese) http://www.meti.go.jp/statistics/zyo/zyouhou/result-2/h24jyojitsu.html
Ministry of Economy, Trade and Industry (2012) Survey on Information Processing in 2012: Questionnaire. (In Japanese) http://www.meti.go.jp/statistics/zyo/zyouhou/result-2/pdf/03_H24chousahyo.pdf