Redundancy Planning for Cost Efficient Resilience to Cyber Attacks

被引:4
|
作者
Soikkeli, Jukka [1 ]
Casale, Giuliano [1 ]
Munoz-Gonzalez, Luis [1 ]
Lupu, Emil C. [1 ]
机构
[1] Imperial Coll London, Dept Comp, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Costs; Redundancy; Resource management; Cyberattack; Servers; Resilience; Production; Cyber security; redundancy; diversity; performance; cyber resilience; FRAMEWORK; NETWORKS;
D O I
10.1109/TDSC.2022.3151462
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We investigate the extent to which redundancy (including with diversity) can help mitigate the impact of cyber attacks that aim to reduce system performance. Using analytical techniques, we estimate impacts, in terms of monetary costs, of penalties from breaching Service Level Agreements (SLAs), and find optimal resource allocations to minimize the overall costs arising from attacks. Our approach combines attack impact analysis, based on performance modeling using queueing networks, with an attack model based on attack graphs. We evaluate our approach using a case study of a website, and show how resource redundancy and diversity can improve the resilience of a system by reducing the likelihood of a fully disruptive attack. We find that the cost-effectiveness of redundancy depends on the SLA terms, the probability of attack detection, the time to recover, and the cost of maintenance. In our case study, redundancy with diversity achieved a saving of up to around 50 percent in expected attack costs relative to no redundancy. The overall benefit over time depends on how the saving during attacks compares to the added maintenance costs due to redundancy.
引用
收藏
页码:1154 / 1168
页数:15
相关论文
共 50 条
  • [21] The effect of environmental turbulence on cyber security risk management and organizational resilience
    Durst, Susanne
    Hinteregger, Christoph
    Zieba, Malgorzata
    COMPUTERS & SECURITY, 2024, 137
  • [22] Ensuring Resilience Against Stealthy Attacks on Cyber-Physical Systems
    Griffioen, Paul
    Krogh, Bruce H.
    Sinopoli, Bruno
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2024, 69 (12) : 8234 - 8246
  • [23] A Bayesian Algorithm to Enhance the Resilience of WAMS Applications Against Cyber Attacks
    Khalid, Haris M.
    Peng, Jimmy C. -H.
    IEEE TRANSACTIONS ON SMART GRID, 2016, 7 (04) : 2026 - 2037
  • [24] Quantifying Cyber-Resilience Against Resource-Exhaustion Attacks
    Fink, Glenn A.
    Griswold, Richard L.
    Beech, Zachary W.
    2014 7TH INTERNATIONAL SYMPOSIUM ON RESILIENT CONTROL SYSTEMS (ISRCS), 2014,
  • [25] Enhancing Cyber Resilience Management: Exploring Attributes in the Context of Security and Resilience
    Munusamy, Thavaselvi
    Khodadadi, Touraj
    2023 IEEE 30TH ANNUAL SOFTWARE TECHNOLOGY CONFERENCE, STC, 2023, : 2 - 2
  • [26] Resilience Assessment of Cyber-Attacks on Distributed Secondary Control in Microgrid
    Paudel, Alisha
    Mandal, Paras
    Ravikumar, Gelli
    2024 56TH NORTH AMERICAN POWER SYMPOSIUM, NAPS 2024, 2024,
  • [27] Enhancing the Reliability of Services in NFV with the Cost-Efficient Redundancy Scheme
    Ding, Weiran
    Yu, Hongfang
    Luo, Shouxi
    2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [28] Building Cyber-Resilience into Supply Chains
    Davis, Adrian
    TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 19 - 27
  • [29] Redundancy as an important source of resilience in the Safety II concept
    Bastan, Ondrej
    Fiedler, Petr
    Benesl, Tomas
    Arm, Jakub
    IFAC PAPERSONLINE, 2019, 52 (27): : 382 - 387
  • [30] Redundancy, Diversity, and Modularity in Network Resilience: Applications for International Trade and Implications for Public Policy
    Kharrazi, Ali
    Yu, Yadong
    Jacob, Arun
    Vora, Nemi
    Fath, Brian D.
    CURRENT RESEARCH IN ENVIRONMENTAL SUSTAINABILITY, 2020, 2