Redundancy Planning for Cost Efficient Resilience to Cyber Attacks

被引:4
|
作者
Soikkeli, Jukka [1 ]
Casale, Giuliano [1 ]
Munoz-Gonzalez, Luis [1 ]
Lupu, Emil C. [1 ]
机构
[1] Imperial Coll London, Dept Comp, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Costs; Redundancy; Resource management; Cyberattack; Servers; Resilience; Production; Cyber security; redundancy; diversity; performance; cyber resilience; FRAMEWORK; NETWORKS;
D O I
10.1109/TDSC.2022.3151462
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We investigate the extent to which redundancy (including with diversity) can help mitigate the impact of cyber attacks that aim to reduce system performance. Using analytical techniques, we estimate impacts, in terms of monetary costs, of penalties from breaching Service Level Agreements (SLAs), and find optimal resource allocations to minimize the overall costs arising from attacks. Our approach combines attack impact analysis, based on performance modeling using queueing networks, with an attack model based on attack graphs. We evaluate our approach using a case study of a website, and show how resource redundancy and diversity can improve the resilience of a system by reducing the likelihood of a fully disruptive attack. We find that the cost-effectiveness of redundancy depends on the SLA terms, the probability of attack detection, the time to recover, and the cost of maintenance. In our case study, redundancy with diversity achieved a saving of up to around 50 percent in expected attack costs relative to no redundancy. The overall benefit over time depends on how the saving during attacks compares to the added maintenance costs due to redundancy.
引用
收藏
页码:1154 / 1168
页数:15
相关论文
共 50 条
  • [21] Quantifying Cyber-Resilience Against Resource-Exhaustion Attacks
    Fink, Glenn A.
    Griswold, Richard L.
    Beech, Zachary W.
    2014 7TH INTERNATIONAL SYMPOSIUM ON RESILIENT CONTROL SYSTEMS (ISRCS), 2014,
  • [22] Cyber Network Resilience Against Self-Propagating Malware Attacks
    Chernikova, Alesia
    Gozzi, Nicolo
    Boboila, Simona
    Angadi, Priyanka
    Loughner, John
    Wilden, Matthew
    Perra, Nicola
    Eliassi-Rad, Tina
    Oprea, Alina
    COMPUTER SECURITY - ESORICS 2022, PT I, 2022, 13554 : 531 - 550
  • [23] Cost-Efficient Data Redundancy in the Cloud
    Waibel, Philipp
    Hochreiner, Christoph
    Schulte, Stefan
    2016 IEEE 9TH INTERNATIONAL CONFERENCE ON SERVICE-ORIENTED COMPUTING AND APPLICATIONS (SOCA), 2016, : 1 - 9
  • [24] Forecasting Issues of Wireless Communication Networks' Cyber Resilience for An Intelligent Transportation System: An Overview of Cyber Attacks
    Buinevich, Mikhail
    Vladyko, Andrei
    INFORMATION, 2019, 10 (01)
  • [25] A Prediction Algorithm to Enhance Grid Resilience Toward Cyber Attacks in WAMCS Applications
    Musleh, Ahmed S.
    Khalid, Haris M.
    Muyeen, S. M.
    Al-Durra, Ahmed
    IEEE SYSTEMS JOURNAL, 2019, 13 (01): : 710 - 719
  • [26] Experimental Evaluation of Smart Electric Meters' Resilience Under Cyber Security Attacks
    Kumar, Harsh
    Alvarez, Oscar. A.
    Kumar, Sanjeev
    IEEE ACCESS, 2023, 11 : 55349 - 55360
  • [27] Resilience of multi-object density fusion against cyber-attacks
    Gao, Lin
    Battistelli, Giorgio
    Chisci, Luigi
    2022 11TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND INFORMATION SCIENCES (ICCAIS), 2022, : 7 - 12
  • [28] Cyber resilience recovery model to combat zero-day malware attacks
    Tran, Hiep
    Campos-Nanez, Enrique
    Fomin, Pavel
    Wasek, James
    COMPUTERS & SECURITY, 2016, 61 : 19 - 31
  • [29] Resilience Against Sensor Deception Attacks on Cyber-Physical Control Systems
    Lafortune, Stephane
    Dotoli, Mariagrazia
    Gregoire, Amphitheatre A.
    2019 6TH INTERNATIONAL CONFERENCE ON CONTROL, DECISION AND INFORMATION TECHNOLOGIES (CODIT 2019), 2019,
  • [30] Model-Based Evaluation of the Resilience of Critical Infrastructures Under Cyber Attacks
    Netkachov, Oleksandr
    Popov, Peter
    Salako, Kizito
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2014), 2016, 8985 : 231 - 243