{"title":"Advancing Cyber Resilience Analysis with Performance-Based Metrics from Infrastructure Assessments","authors":"E. Vugrin, Jennifer Turgeon","doi":"10.4018/JSSE.2013010105","DOIUrl":null,"url":null,"abstract":"Cyber resilience is becoming increasingly recognized as a critical component of comprehensive cybersecurity practices. Current cyber resilience assessment approaches are primarily qualitative methods, making validation of their resilience analyses and enhancement recommendations difficult, if not impossible. The evolution of infrastructure resilience assessment methods has paralleled that of their cyber counterparts. However, the development of performance-based assessment methods has shown promise for overcoming the validation challenge for infrastructure systems. This article describes a hybrid infrastructure resilience assessment approach that combines both qualitative analysis techniques with performance-based metrics. The qualitative component enables identification of system features that limit resilience, and the quantitative metrics can be used to evaluate and confirm the effectiveness of proposed mitigation options. The authors propose adaptation of this methodology for cyber resilience analysis. A case study is presented to demonstrate how the approach could be applied to a hypothetical system. INTRODUCTION AND BACKGROUND Cybersecurity is generally acknowledged as a critical priority within the national, homeland, and business security communities. This sentiment has been echoed at the highest levels of the U.S. government, with President Obama (2009) stating that “cyber threat is one of the most serious economic and national security challenges we face as a nation.” Fortunately, the concept of cybersecurity is not new to the academic and research communities. Eric D. Vugrin Sandia National Laboratories, USA Jennifer Turgeon Sandia National Laboratories, USA","PeriodicalId":89158,"journal":{"name":"International journal of secure software engineering","volume":"7 1","pages":"75-96"},"PeriodicalIF":0.0000,"publicationDate":"2012-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of secure software engineering","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/JSSE.2013010105","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 17
Abstract
Cyber resilience is becoming increasingly recognized as a critical component of comprehensive cybersecurity practices. Current cyber resilience assessment approaches are primarily qualitative methods, making validation of their resilience analyses and enhancement recommendations difficult, if not impossible. The evolution of infrastructure resilience assessment methods has paralleled that of their cyber counterparts. However, the development of performance-based assessment methods has shown promise for overcoming the validation challenge for infrastructure systems. This article describes a hybrid infrastructure resilience assessment approach that combines both qualitative analysis techniques with performance-based metrics. The qualitative component enables identification of system features that limit resilience, and the quantitative metrics can be used to evaluate and confirm the effectiveness of proposed mitigation options. The authors propose adaptation of this methodology for cyber resilience analysis. A case study is presented to demonstrate how the approach could be applied to a hypothetical system. INTRODUCTION AND BACKGROUND Cybersecurity is generally acknowledged as a critical priority within the national, homeland, and business security communities. This sentiment has been echoed at the highest levels of the U.S. government, with President Obama (2009) stating that “cyber threat is one of the most serious economic and national security challenges we face as a nation.” Fortunately, the concept of cybersecurity is not new to the academic and research communities. Eric D. Vugrin Sandia National Laboratories, USA Jennifer Turgeon Sandia National Laboratories, USA
网络弹性越来越被认为是综合网络安全实践的关键组成部分。目前的网络弹性评估方法主要是定性方法,这使得其弹性分析和增强建议的验证即使不是不可能,也很困难。基础设施弹性评估方法的发展与网络环境弹性评估方法的发展是平行的。然而,基于性能的评估方法的发展已经显示出克服基础设施系统验证挑战的希望。本文描述了一种混合基础设施弹性评估方法,该方法结合了定性分析技术和基于性能的度量。定性部分能够识别限制复原力的系统特征,定量度量可用于评估和确认拟议的缓解方案的有效性。作者建议将这种方法用于网络弹性分析。提出了一个案例研究来演示如何将该方法应用于一个假设的系统。网络安全通常被认为是国家、国土和商业安全领域的关键优先事项。这种观点得到了美国政府最高层的呼应,奥巴马总统(2009年)表示,“网络威胁是我们作为一个国家面临的最严重的经济和国家安全挑战之一。”幸运的是,网络安全的概念对学术和研究界来说并不新鲜。Eric D. Vugrin美国桑迪亚国家实验室Jennifer Turgeon美国桑迪亚国家实验室