Related Experiment Video
Updated: Nov 6, 2025

Signal Attenuation as a Rat Model of Obsessive Compulsive Disorder
Published on: January 9, 2015
The Work-Averse Cyberattacker Model: Theory and Evidence from Two Million Attack Signatures
Luca Allodi1, Fabio Massacci2,3, Julian Williams4
1Technical University of Eindhoven, Groene Loper 5, Eindhoven, The Netherlands.
Abstract:
The assumption that a cyberattacker will potentially exploit all present vulnerabilities drives most modern cyber risk management practices and the corresponding security investments. We propose a new attacker model, based on dynamic optimization, where we demonstrate that large, initial, fixed costs of exploit development induce attackers to delay implementation and deployment of exploits of vulnerabilities. The theoretical model predicts that mass attackers will preferably (i) exploit only one vulnerability per software version, (ii) largely include only vulnerabilities requiring low attack complexity, and (iii) be slow at trying to weaponize new vulnerabilities . These predictions are empirically validated on a large data set of observed massed attacks launched against a large collection of information systems. Findings in this article allow cyber risk managers to better concentrate their efforts for vulnerability management, and set a new theoretical and empirical basis for further research defining attacker (offensive) processes.
Related Concept Videos
Bullying
Theory of Attribution II: Kelley's Covariation Theory
Typical Model Studies
Work Done on a System by External Force
In the presence of a non-conservative opposing force, like friction, some part of the work done...
Theory of Attribution I: Correspondent Inference Theory
Social Loafing

