Cyber resilience metrics needed to meet increased threats

November 25, 2013

Cyber threats are rapidly emerging as one of the primary security concerns for the nation and global community as targeted cyber attacks can cause severe consequences to critical infrastructure and sectors of the economy. Recent calls for action, including President Obama's Executive Orders 13636 and Presidential Policy Directive 21, have brought the concept of "resilience" in the face of cyber attacks to the forefront of the nation's consciousness. In a recent special issue of Springer's journal Environment Systems & Decisions, Dr. Igor Linkov and colleagues describe a framework for understanding the concept of cyber resilience, and lay out a systematic method by which to generate resilience metrics for cyber systems.

Resilience is the capacity of a system to withstand and recover quickly from both known and unknown threats. The study describes that managing for resilience has been difficult because the concepts of resilience and risk have been conflated and have tended to focus on narrowly defined system components or on specific networks. However, the definition of cyber systems must be expanded to include rich and varied physical, information, cognitive and social networks – or "domains" – that form an integrated whole. Thus, the discussion of resilience should recognize the role of cross-domain communication before, during and after adverse events such as or natural events that may disrupt the functionality of cyber systems.

The study suggests combining the military concept of network-centric operations and the US National Academies' definition of resilience response stages to quantify and manage the resilience of a cyber system. Together, these factors form a matrix wherein a system's resilience may be quantified using tools of multi-criteria decision.

Regarding cyber resilience, the study describes, "Transition from risk-based approaches focusing on identifying individual vulnerability and fixing them one-at-a-time, to building a whole system for resilience, is required to deal with interconnected global risks and sophisticated adversaries. The resilience matrix approach is just the first step in the process which will lead us to formulating and quantifying resilience as a network property of the system."

Explore further: Researchers link youths' social interactions with grades, self-efficacy

More information: Linkov I. et al [add the other authors?] (2013). Resilience Metrics for Cyber Systems, Environment Systems & Decisions, DOI: 10.1007/s10669-013-9485-y

Related Stories

London-based banks simulate giant cyber-attack

November 12, 2013

Dozens of London-based banks joined other financial institutions in the capital on Tuesday for a giant exercise to test their defences against a cyber-attack, officials said.

Growing cyber threat to US infrastructure: spy chief

March 12, 2013

The United States faces a mounting danger from cyber attacks on its infrastructure while digital espionage threatens to undercut the military's technological edge, the intelligence chief said Tuesday.

Recommended for you

Your (social media) votes matter

January 24, 2017

When Tim Weninger conducted two large-scale experiments on Reddit - otherwise known as "the front page of the internet" - back in 2014, the goal was to better understand the ripple effects of malicious voting behavior and ...

Protective wear inspired by fish scales

January 24, 2017

They started with striped bass. Over a two-year period the researchers went through about 50 bass, puncturing or fracturing hundreds of fish scales under the microscope, to try to understand their properties and mechanics ...

'Droneboarding' takes off in Latvia

January 22, 2017

Skirted on all sides by snow-clad pine forests, Latvia's remote Lake Ninieris would be the perfect picture of winter tranquility—were it not for the huge drone buzzing like a swarm of angry bees as it zooms above the solid ...

Singapore 2G switchoff highlights digital divide

January 22, 2017

When Singapore pulls the plug on its 2G mobile phone network this year, thousands of people could be stuck without a signal—digital have-nots left behind by the relentless march of technology.

Making AI systems that see the world as humans do

January 19, 2017

A Northwestern University team developed a new computational model that performs at human levels on a standard intelligence test. This work is an important step toward making artificial intelligence systems that see and understand ...

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.