200699:100026788(2006)0920043208,,,(,150001):,,.,,,;,.,,.:;;;:F832:ATheGameModelforReducingtheSecurityRiskofChineseCommercialBankQIAOLi2xin,YUANAi2ling,LIShu2xia,FENGYing2jun(SchoolofManagement,HarbinInstituteofTechnology,Harbin150001,China)Abstract:Inordertoinvestigatethegamebehindthehackersandcommercialbanks,thispaperanalyzesthecostsandprofitsabouttheattackandthedefenseofcommercialbanks&hackers,andstudiesthegamestatusofhackersandcommercialbanksbysignalgamemodel.Thispaperfiguresthatcommercialbanksshouldmaintainitsreputationatahigherleveltopreventhackersattack,andthusletthehackertobelievetheprofitwilllessthantheaveragedirectcostwhilemakinganattack.Regardingthecost,rationalcommercialbanksmayhopeitsmarginalprofitgainedbytheengagementinitsreputationpromotionequalstothebanksloseduetohackersattack.Thispaperfinallyconcludedthat,thesupervisorauthoritiesshouldtrytoincreasetheinspectionfrequencyaboutthestatusofcommercialbanksnetworksecurity,aswellasincreasethemediaexposinglevelaboutthelosingstatuscausedbynetworkinformationsecurityrisk,andthusforcethecommercialbankstoincreaseitsinvestmentonnetworksecurity.Keywords:commercialbank;networksecurity;gametheory;hacker:2005208221:(70131010);(2005AFXXJ41);(2005AFXXJ41):(1967-),,,:,E2mail:qiaolixin@sina.com;(1963-),,,,:;,,;(1940-),,,,:.1,.,:(2000,2001)[1,2](19992004)[38],(2002),TheSumitomoTrust&BankingCo.,Ltd.(2004)[9].,,(2003)[10],Watase,Jumpei(2004)[11],Tang,Qiang©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.(2003)RSASchnorr[12].,,.,,,.2.S,R.RS,:Si,R,SS,Sp(i).:S,Si()p(i),i[1,I],Ii=1p(i)=1.(1)SiSdj().,i,dji.i,djij={p(d1|i),p(d2|i),,p(dJ|i)},j=Jp(dj|i)=1.(2)RSdj,Ak.S,R;S,R.R:(Ak=0),(Ak=1).RSdj,j=p(Ak|dj),R,Rp(i)p=p(i|dj).,R,,p(i),.Rp=p(i|dj),,,.S,,,,S.,SSj,ij,,j,ij.,RS,Sj,ij,Sj..,SR,(SignalGame).(forwardinduction),RjSij,.SR,:4420069©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.(i),SRj=p(Ak|dj);,RS,Sp=p(i|dj),SRj-1;RS;RSRjSij,RjSij.3,.311R1)(i,i,j,j):i.i,.,,,.,.(i,i,j,j),i.i,:(i,i,j,j)=E(C|Ak)jp(dj)=E(C|Ak)jIi=1[i,jp(i)],(3):E(C|Ak);p(dj)dj,jdj,jp(dj),i,jidj,p(i)i.:.(p(e)),E(C)=E(C|e)p(e)..0.,,:C(i,i,j,j)=(i,i,j,j)=E[C|Ak]jp(dj)=E[C|Ak]jIi=1[i,jp(i)],(4):C(i,i,j,j)ji,j;E(C|Ak),jIi=1[i,jp(i)].2).,6000,25,7500..,.,i.i,j,.,:549©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.(i,i,j,j)=Ap(dj)jLD=AIi=1[i,jp(i)]jLD.(5),A,LD.i:R(i,i,j,j)=h(i,i,j,j)-C(i,i,j,j)=Ap(dj)jLD-E[C|Ak]jp(dj)=AIi=1[i,jp(i)]jLD-E[C|Ak]jIi=1[i,jp(i)]=(AjLD-E[C|Ak]j)Ii=1[i,jp(i)](6)312S1)SL(i,i,j,j),:L(i,i,j,j)=Ap(dj)cLD=AIi=1[i,jp(i)]jLD,(7),A,LD.2002918,,5:.,,dj,M(i,i,j).,,i;,.,C1.i,H(i).:CS(i,i,j,j)=L(i,i,j,j)+C1+H(i)+M(i,i,j)=AIi=1[i,jp(i)]jLD+C1+H(i)+M(i,i,j)(8):C1,;H(i);L(i,i,j).:,.2)dj.,dj,,,,,.,,,(i,i,j),Vr(i,i,j),Vr(i,i,j)0.6420069©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.(i,p),Fp1(i,p)(i),(1-p1(i))F.,:RS(i,i,j)=(1-p1(i))F+Vr(i,i,j).(9):W(i,i,j,j)=RS(i,i,j)-CS(i,i,j,j)=(1-p1(i,p))F+Vr(i,i,j)-C1-H(i)-Ap(dj)jLD-M(i,i,j)=(1-p1(i,p))F+Vr(i,i,j)-C1-H(i)-AIi=1[i,jp(i)]jLD-M(i,i,j).(10)313,jdj,j+1i:p=p(i|dj)=p(dj|i)p(i)p(dj)=p(dj|i)p(i)i=I[p(dj|i)p(i)]=i,jp(i)i=I[i,jp(i)].(11):maxj,i,i,jIi=1pR(j,i,i,j)=maxj,i,i,jIi=1i,jp(i)Ii=1[i,jp(i)](AjLD-E[C|Ak]j)Ii=1[i,jp(i)]=maxj,i,i,jIi=1[i,jp(i)(AjLD-E[C|Ak]j)]=maxj,i,i,j(AjLD-E[C|Ak]j)Ii=1[i,jp(i)](12):maxi,i,jW(j,i,i,j)=maxi,i,j(1-p1(i,p))F+Vr(i,i,j)-C1-H(i)-AIi=1[i,jp(i)]3jLD-M(i,i,j)(13)314,:,.:maxj,i,i,jIi=1pR(j,i,i,j)=maxj,i,i,j(AjLD-E[C|Ak]j)Ii=1[i,jp(i)]=maxj,dj(AjLD-E[C|Ak]j)p(dj)=0.(14)749©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.(14)0,:p(dj)(ALD-E[C|Ak])=0,(15)(AjLD-E[C|Ak]j)p(dj)0.(16)p(dj)[0,1],(16)(AjLD-E[C|Ak]j)0.jALDjE[C|Ak]=BdE[C|Ak].(17)(17)ALDjdj(),Bd;E[C|Ak].(17):,.j[011],(15),(ALD-E[C|Ak])=0]ALD=E[C|Ak].(18)(18)3j,ALD3j=E[C|Ak]3j,3j=ALD3jE[C|Ak]=BdE[C|Ak].(19)(19)(13):maxi,i,jW(i,i,j)=maxi,i,j(1-p1(i,p))F+Vr(i,i,j)-C1-H(i)-AIi=1[i,jp(i)]BdE[C|Ak]LD-M(i,i,j),(20)i,j:5Vr(i,i,j)5i,j-ABdE[C|Ak]LD-5M(i,i,j)5i,j=0,5Vr(i,i,j)5i,j-5M(i,i,j)5i,j=Bd.(21):3i,j.,:(3i,j,3j;p)=3i,j,BdE[C|Ak];i,jp(i)i=I[i,jp(i)].(22)4411(17)(19):i,j,=E[C|Ak],;E[C|Ak],;E[C|Ak],.(ii,j),8420069©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.[C|Ak],,.4123,:,3i,j0;,d3j1;,3i,j[0,1].1)(),3i,j[0,1],:5Vr(i,i,j)5i,j-5M(i,i,j)5i,j=Bd,(23):i,j5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd.2),3i,j1,:5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd,(24):i,j5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd.,,,3.3),3i,j0,:5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd,(25):i,j5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd.,(3),.,:1),,,,i,j,,E[C|Ak],.,3,3i,j;3,;3,.2),i,j5Vr(i,i,j)5i,j-5M(i,i,j)5i,jBd.Bd(),,,,,,,;,,.949©1994-2008ChinaAcademicJournalElectronicPublishingHouse.Allrightsreserved.[1]BaselCommitteeonBankingSupervision.RiskManagementPrinciplesforElectronicBanking[DBPOL].http:PP[2]BaselCommitteeonBankingSupervision.E