Redundancy Planning for Cost Efficient Resilience to Cyber Attacks

被引:4
|
作者
Soikkeli, Jukka [1 ]
Casale, Giuliano [1 ]
Munoz-Gonzalez, Luis [1 ]
Lupu, Emil C. [1 ]
机构
[1] Imperial Coll London, Dept Comp, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Costs; Redundancy; Resource management; Cyberattack; Servers; Resilience; Production; Cyber security; redundancy; diversity; performance; cyber resilience; FRAMEWORK; NETWORKS;
D O I
10.1109/TDSC.2022.3151462
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We investigate the extent to which redundancy (including with diversity) can help mitigate the impact of cyber attacks that aim to reduce system performance. Using analytical techniques, we estimate impacts, in terms of monetary costs, of penalties from breaching Service Level Agreements (SLAs), and find optimal resource allocations to minimize the overall costs arising from attacks. Our approach combines attack impact analysis, based on performance modeling using queueing networks, with an attack model based on attack graphs. We evaluate our approach using a case study of a website, and show how resource redundancy and diversity can improve the resilience of a system by reducing the likelihood of a fully disruptive attack. We find that the cost-effectiveness of redundancy depends on the SLA terms, the probability of attack detection, the time to recover, and the cost of maintenance. In our case study, redundancy with diversity achieved a saving of up to around 50 percent in expected attack costs relative to no redundancy. The overall benefit over time depends on how the saving during attacks compares to the added maintenance costs due to redundancy.
引用
收藏
页码:1154 / 1168
页数:15
相关论文
共 50 条
  • [31] Discussing resilience in the context of cyber physical systems
    Colabianchi, Silvia
    Costantino, Francesco
    Di Gravio, Giulio
    Nonino, Fabio
    Patriarca, Riccardo
    COMPUTERS & INDUSTRIAL ENGINEERING, 2021, 160
  • [32] Editorial: Cyber-Resilience in Supply Chains
    McPhee, Chris
    Khan, Omera
    TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 3 - 5
  • [33] Forecasting Issues of Wireless Communication Networks' Cyber Resilience for An Intelligent Transportation System: An Overview of Cyber Attacks
    Buinevich, Mikhail
    Vladyko, Andrei
    INFORMATION, 2019, 10 (01)
  • [34] Resilience of Cyber Systems with Over- and Underregulation
    Gisladottir, Viktoria
    Ganin, Alexander A.
    Keisler, Jeffrey M.
    Kepner, Jeremy
    Linkov, Igor
    RISK ANALYSIS, 2017, 37 (09) : 1644 - 1651
  • [35] Cyber Resilience versus Cybersecurity as Legal Aspiration
    Bygrave, Lee A.
    2022 14TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT: KEEP MOVING (CYCON), 2022, : 27 - 43
  • [36] The Need for Cyber-Resilience in Complex Systems
    Acur, Sezen
    Hendriks, Teun
    2024 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2024, : 480 - 485
  • [37] Systematic Approach to Cyber Resilience Operationalization in SMEs
    Carias, Juan Francisco
    Borges, Marcos R. S.
    Labaka, Leire
    Arrizabalaga, Saioa
    Hernantes, Josune
    IEEE ACCESS, 2020, 8 (08): : 174200 - 174221
  • [38] The Global Cyber Security Model: Counteracting Cyber Attacks through a Resilient Partnership Arrangement
    Trim, Peter R. J.
    Lee, Yang-Im
    BIG DATA AND COGNITIVE COMPUTING, 2021, 5 (03)
  • [39] Multibank Optimized Redundancy Analysis Using Efficient Fault Collection
    Kim, Hogyeong
    Lee, Hayoung
    Han, Donghyun
    Kang, Sungho
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (08) : 2739 - 2752
  • [40] Wide-Area Damping Control Resilience Towards Cyber-Attacks: A Dynamic Loop Approach
    Patel, Abhilash
    Roy, Spandan
    Baldi, Simone
    IEEE TRANSACTIONS ON SMART GRID, 2021, 12 (04) : 3438 - 3447