Risk assessment and optimal allocation of security measures under stealthy false data injection attacks
This paper firstly addresses the problem of risk assessment under false data injection attacks on uncertain control systems. We consider an adversary with complete system knowledge, injecting stealthy false data into an uncertain control system. We then use the Value-at-Risk to characterize the risk associated with the attack impact caused by the adversary. The worst-case attack impact is characterized by the recently proposed output-to-output gain. We observe that the risk assessment problem corresponds to an infinite non-convex robust optimization problem. To this end, we use dissipative system theory and the scenario approach to approximate the risk-assessment problem into a convex problem and also provide probabilistic certificates on approximation. Secondly, we consider the problem of security measure allocation. We consider an operator with a constraint on the security budget. Under this constraint, we propose an algorithm to optimally allocate the security measures using the calculated risk such that the resulting Value-at-risk is minimized. Finally, we illustrate the results through a numerical example. The numerical example also illustrates that the security allocation using the Value-at-risk, and the impact on the nominal system may have different outcomes: thereby depicting the benefit of using risk metrics.
Code (0)
등록된 구현이 없습니다.
Similar Papers 제목 키워드 기반
Risk sharing under heterogeneous beliefs without convexity
We consider the problem of finding Pareto-optimal allocations of risk among finitely many agents. The associated individual risk measures are law invariant, but with respect to agent-dependent and potentially heterogeneo…
Risk-based Security Measure Allocation Against Injection Attacks on Actuators
This article considers the problem of risk-optimal allocation of security measures when the actuators of an uncertain control system are under attack. We consider an adversary injecting false data into the actuator chann…
Pareto-Optimal Peer-to-Peer Risk Sharing with Robust Distortion Risk Measures
We study Pareto optimality in a decentralized peer-to-peer risk-sharing market where agents' preferences are represented by robust distortion risk measures that are not necessarily convex. We obtain a characterization of…
Fortify Your Defenses: Strategic Budget Allocation to Enhance Power Grid Cybersecurity
The abundance of cyber-physical components in modern day power grid with their diverse hardware and software vulnerabilities has made it difficult to protect them from advanced persistent threats (APTs). An attack graph …
Asset ManagementCyber Risk Assessment for Capital Management
This paper introduces a two-pillar cyber risk management framework to address the pervasive challenges in managing cyber risk. The first pillar, cyber risk assessment, combines insurance frequency-severity models with cy…
Decision MakingManagement