Redundancy Planning for Cost Efficient Resilience to Cyber Attacks

被引:4
|
作者
Soikkeli, Jukka [1 ]
Casale, Giuliano [1 ]
Munoz-Gonzalez, Luis [1 ]
Lupu, Emil C. [1 ]
机构
[1] Imperial Coll London, Dept Comp, London SW7 2AZ, England
基金
英国工程与自然科学研究理事会;
关键词
Costs; Redundancy; Resource management; Cyberattack; Servers; Resilience; Production; Cyber security; redundancy; diversity; performance; cyber resilience; FRAMEWORK; NETWORKS;
D O I
10.1109/TDSC.2022.3151462
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We investigate the extent to which redundancy (including with diversity) can help mitigate the impact of cyber attacks that aim to reduce system performance. Using analytical techniques, we estimate impacts, in terms of monetary costs, of penalties from breaching Service Level Agreements (SLAs), and find optimal resource allocations to minimize the overall costs arising from attacks. Our approach combines attack impact analysis, based on performance modeling using queueing networks, with an attack model based on attack graphs. We evaluate our approach using a case study of a website, and show how resource redundancy and diversity can improve the resilience of a system by reducing the likelihood of a fully disruptive attack. We find that the cost-effectiveness of redundancy depends on the SLA terms, the probability of attack detection, the time to recover, and the cost of maintenance. In our case study, redundancy with diversity achieved a saving of up to around 50 percent in expected attack costs relative to no redundancy. The overall benefit over time depends on how the saving during attacks compares to the added maintenance costs due to redundancy.
引用
收藏
页码:1154 / 1168
页数:15
相关论文
共 50 条
  • [41] Resilience Against Bad Mouthing Attacks in Mobile Crowdsensing Systems via Cyber Deception
    Roy, Prithwiraj
    Bhattacharjee, Shameek
    Alsheakh, Hussein
    Das, Sajal K.
    2021 IEEE 22ND INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM 2021), 2021, : 169 - 178
  • [42] Resilience Framework for Power Electronic Systems Against Cyber-Physical Attacks: A Review
    Liu, Chang
    Ye, Jin
    Fang, Gaoliang
    Wang, Di
    Zhou, Linke
    Emadi, Ali
    IEEE OPEN JOURNAL OF POWER ELECTRONICS, 2025, 6 : 28 - 55
  • [43] Adaptation, redundancy or resilience
    van Helden, Paul
    EMBO REPORTS, 2011, 12 (09) : 872 - 872
  • [44] Neutralizing Cyber Attacks: Techniques of Neutralization and Willingness to Commit Cyber Attacks
    Adam M. Bossler
    American Journal of Criminal Justice, 2021, 46 : 911 - 934
  • [45] Neutralizing Cyber Attacks: Techniques of Neutralization and Willingness to Commit Cyber Attacks
    Bossler, Adam M.
    AMERICAN JOURNAL OF CRIMINAL JUSTICE, 2021, 46 (06) : 911 - 934
  • [46] Enhancing Sensor Fault Tolerance in Automotive Systems With Cost-Effective Cyber Redundancy
    Foshati, Amin
    Ejlali, Alireza
    IEEE TRANSACTIONS ON INTELLIGENT VEHICLES, 2024, 9 (04): : 4794 - 4803
  • [47] Speeding up Planning of Cyber Attacks Using AI Techniques: State of the art
    Grant, Tim
    PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018), 2018, : 235 - 244
  • [48] Viewpoint Cyber Efficiency and Cyber Resilience
    Linkov, Igor
    Ligo, Alexandre
    Stoddard, Kelsey
    Perez, Beatrice
    Strelzoff, Andrew
    Bellini, Emanuele
    Kott, Alexander
    COMMUNICATIONS OF THE ACM, 2023, 66 (04) : 33 - 37
  • [49] CYBER RESILIENCE: THE ESSENCE OF CYBER PEACE
    Toure, Hamadoun I.
    INTERNATIONAL SEMINAR ON NUCLEAR WAR AND PLANETARY EMERGENCIES: 45TH SESSION, 2013, : 35 - 40
  • [50] Foiling Cyber Attacks
    Guitton, Clement
    2017 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2017,