An iterative learning and inference approach to managing dynamic cyber vulnerabilities of complex systems
Samrat Chatterjee and
Shital Thekdi
Reliability Engineering and System Safety, 2020, vol. 193, issue C
Abstract:
As modern infrastructure systems become increasingly reliant on cyber technologies and continue to be integrated with physical systems, managing risks from deliberate and non-deliberate sources is a significant research challenge. Unlike strictly physical systems, cyber-enabled physical systems are influenced by dynamic and evolving technologies, environments, and attack mechanisms. As a result, vulnerabilities are rapidly changing and difficult to detect and manage. While there is recent interest in the dynamic properties of performance through resilience analysis, limited research addresses the dynamic nature of cyber-system vulnerability. This paper presents an iterative data-driven learning approach to evaluate and manage vulnerabilities for such complex systems. These time-varying system health characteristics may not be directly observable, but can be inferred using observable indicators. The approach recognizes that multiple types of vulnerabilities need to be included in a holistic system health assessment. The methods are applied to the Common Vulnerability Scoring System (CVSS) database containing thousands of documented cybersecurity vulnerabilities over nearly two decades. We acknowledge the dynamic properties of cyber vulnerability, while also inferring system health using observable data and hidden operational states. The results will be of interest to managers of large-scale cyber-enabled physical systems who are seeking to prioritize system health investments.
Keywords: Cybersecurity; Cyber vulnerability; System resilience; Markov model; Probabilistic inference; Statistical learning (search for similar items in EconPapers)
Date: 2020
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (6)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S0951832018314558
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:reensy:v:193:y:2020:i:c:s0951832018314558
DOI: 10.1016/j.ress.2019.106664
Access Statistics for this article
Reliability Engineering and System Safety is currently edited by Carlos Guedes Soares
More articles in Reliability Engineering and System Safety from Elsevier
Bibliographic data for series maintained by Catherine Liu ().