In the modern digital landscape, protecting information infrastructure against malicious intrusions is a critical economic and operational challenge for any commercial or public enterprise. Standard risk management models often assume that security breaches occur independently over time. However, empirical observations show that real-world cyberattacks typically exhibit strong clustering effects, where a single vulnerability exploit can trigger a cascading wave of subsequent attacks. To capture this volatile and self-exciting threat landscape, this thesis models the frequency of security breaches using a Hawkes point process. Within this environment, a firm manages a continuous defensive asset representing its overall security posture. This security level naturally depreciates over time due to system obsolescence and evolving attacker capabilities, but it can be actively reinforced through continuous financial and operational investments. The firm's objective is to determine an optimal investment strategy that minimizes its total expected costs, balancing the direct capital expenditure of security investments against the financial damages inflicted by successful attacks. This stochastic optimal control problem is initially analyzed using classical dynamic programming techniques over a finite time horizon. As a foundational contribution, this thesis provides original, rigorous proofs for both the global Dynamic Programming Principle (DPP) and the corresponding Hamilton-Jacobi-Bellman (HJB) partial integro-differential equation (PIDE). Then we give a probabilistic representation of the value function by using a suitable SDE of backward type. While the classical HJB framework offers an intuitive analytical benchmark, traditional verification arguments demand that the value function satisfies highly restrictive global smoothness conditions ($\mathcal{C}^{1,1,1}$) across the entire state space, which are exceptionally difficult to guarantee in a pure-jump setting. To weaken these stringent hypotheses, we introduce a probabilistic approach to solve the optimization problem through a representation based on Backward Stochastic Differential Equations (BSDEs) driven by the compensated martingale of the Hawkes process. Under the weaker condition that the spatial derivative of the value function is uniformly bounded, we prove the existence and uniqueness of a square-integrable solution pair for the backward system. Finally, we establish a rigorous verification theorem demonstrating that the initial component of this jump-driven BSDE solution coincides perfectly with the optimal value function of the control problem, providing a new theoretical foundation for evaluating cybersecurity investment strategies.
Nel moderno panorama digitale, la protezione delle infrastrutture contro gli attacchi informatici rappresenta una sfida economica e operativa fondamentale per qualsiasi realtà aziendale o istituzionale. I modelli classici di gestione del rischio spesso assumono che le violazioni della sicurezza si verifichino in modo indipendente nel tempo. Tuttavia, l'evidenza empirica mostra che gli attacchi informatici reali tendono a manifestarsi in agglomerati o ondate concentrate, un fenomeno in cui il successo di una singola intrusione innesca una serie di violazioni successive. Per catturare la natura intrinsecamente volatile e auto-eccitante di questo scenario, in questo lavoro la frequenza dei tentativi di violazione viene modellata tramite un processo di punto di Hawkes. All'interno di questo contesto, un'impresa gestisce un livello di protezione continuo che descrive la solidità della propria difesa a tali attacchi. Tale livello subisce un naturale deprezzamento nel tempo a causa dell'obsolescenza dei sistemi e dell'evoluzione delle strategie degli attaccanti, ma può essere attivamente rafforzato tramite investimenti finanziari continui. L'obiettivo dell'impresa consiste nel determinare una strategia di investimento ottimale in grado di minimizzare i costi totali attesi, bilanciando l'esborso di capitale necessario alla difesa con i danni economici derivanti dagli attacchi andati a buon fine. Questo problema di controllo ottimo stocastico viene inizialmente analizzato su un orizzonte temporale finito attraverso le tecniche classiche della programmazione dinamica. Come contributo fondamentale, questa tesi fornisce dimostrazioni originali e rigorose sia per il Principio della Programmazione Dinamica, sia per la derivazione formale della corrispondente equazione integro-differenziale parziale di Hamilton-Jacobi-Bellman. Successivamente, viene fornita una rappresentazione probabilistica della funzione valore mediante un'opportuna equazione differenziale stocastica di tipo retrogrado. Sebbene l'approccio classico basato sull'equazione di Hamilton-Jacobi-Bellman offra un punto di riferimento analitico intuitivo, i tradizionali argomenti di verifica richiedono che la funzione valore soddisfi restrittive ipotesi di regolarità e differenziabilità globale sull'intero spazio degli stati, condizioni difficili da garantire a priori in presenza di salti puri. Per superare e indebolire tali vincoli strutturali rispetto al lavoro classico originale, viene introdotto un approccio probabilistico per la risoluzione del problema di ottimizzazione attraverso una rappresentazione matematica basata sulle Equazioni Differenziali Stocastiche Retrograde (BSDE) guidate dalla martingala compensata del processo di Hawkes. Sotto la condizione che la derivata parziale della funzione valore rispetto all'asset difensivo sia uniformemente limitata, viene dimostrata l'esistenza e l'unicità di una coppia di soluzioni a quadrato integrabile per l'equazione. Infine, viene enunciato e dimostrato un teorema di verifica rigoroso, il quale attesta che la componente iniziale della soluzione di questa equazione stocastica retrograda coincide esattamente con la funzione valore del problema di controllo, fornendo una solida base teorica per la pianificazione delle strategie di investimento nella sicurezza informatica.
Backward stochastic differential equations for cybersecurity optimal control problems with Hawkes processes
TOLOMELLI, LORENZO
2025/2026
Abstract
In the modern digital landscape, protecting information infrastructure against malicious intrusions is a critical economic and operational challenge for any commercial or public enterprise. Standard risk management models often assume that security breaches occur independently over time. However, empirical observations show that real-world cyberattacks typically exhibit strong clustering effects, where a single vulnerability exploit can trigger a cascading wave of subsequent attacks. To capture this volatile and self-exciting threat landscape, this thesis models the frequency of security breaches using a Hawkes point process. Within this environment, a firm manages a continuous defensive asset representing its overall security posture. This security level naturally depreciates over time due to system obsolescence and evolving attacker capabilities, but it can be actively reinforced through continuous financial and operational investments. The firm's objective is to determine an optimal investment strategy that minimizes its total expected costs, balancing the direct capital expenditure of security investments against the financial damages inflicted by successful attacks. This stochastic optimal control problem is initially analyzed using classical dynamic programming techniques over a finite time horizon. As a foundational contribution, this thesis provides original, rigorous proofs for both the global Dynamic Programming Principle (DPP) and the corresponding Hamilton-Jacobi-Bellman (HJB) partial integro-differential equation (PIDE). Then we give a probabilistic representation of the value function by using a suitable SDE of backward type. While the classical HJB framework offers an intuitive analytical benchmark, traditional verification arguments demand that the value function satisfies highly restrictive global smoothness conditions ($\mathcal{C}^{1,1,1}$) across the entire state space, which are exceptionally difficult to guarantee in a pure-jump setting. To weaken these stringent hypotheses, we introduce a probabilistic approach to solve the optimization problem through a representation based on Backward Stochastic Differential Equations (BSDEs) driven by the compensated martingale of the Hawkes process. Under the weaker condition that the spatial derivative of the value function is uniformly bounded, we prove the existence and uniqueness of a square-integrable solution pair for the backward system. Finally, we establish a rigorous verification theorem demonstrating that the initial component of this jump-driven BSDE solution coincides perfectly with the optimal value function of the control problem, providing a new theoretical foundation for evaluating cybersecurity investment strategies.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_07_Tolomelli_Executive Summary.pdf
accessibile in internet per tutti a partire dal 01/07/2027
Descrizione: executive summary
Dimensione
397.11 kB
Formato
Adobe PDF
|
397.11 kB | Adobe PDF | Visualizza/Apri |
|
2026_07_Tolomelli_Tesi.pdf
accessibile in internet per tutti a partire dal 01/07/2027
Descrizione: testo della tesi
Dimensione
565.32 kB
Formato
Adobe PDF
|
565.32 kB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/260960