YaBeSH Engineering and Technology Library

    • Journals
    • PaperQuest
    • YSE Standards
    • YaBeSH
    • Login
    View Item 
    •   YE&T Library
    • ASCE
    • Journal of Infrastructure Systems
    • View Item
    •   YE&T Library
    • ASCE
    • Journal of Infrastructure Systems
    • View Item
    • All Fields
    • Source Title
    • Year
    • Publisher
    • Title
    • Subject
    • Author
    • DOI
    • ISBN
    Advanced Search
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Archive

    Empirical Risk Analysis Methodology for Adversarial Threats against Critical Infrastructure

    Source: Journal of Infrastructure Systems:;2024:;Volume ( 030 ):;issue: 001::page 04023036-1
    Author:
    David W. Wallace
    ,
    Lloyd Foster
    ,
    Kris Schartau
    ,
    David Lewin
    ,
    Conrad G. Keyes
    DOI: 10.1061/JITSE4.ISENG-2291
    Publisher: ASCE
    Abstract: The increase in foreign and domestic threats mandates a serious reevaluation of existing security methodologies, standards, and vulnerability assessments. A comprehensive defense strategy with quantitative and qualitative measurements is presented on how the water sector can optimize the application and placement of physical security countermeasures to improve resilience based on known parameters in a cost effective way. This study reviews the history and original intent of these methodologies that were adopted from the atomic and nuclear segments of the energy sector. These methodologies served as a starting point for the risk assessment documents that govern water sector security. The current American National Standards Institute (ANSI) risk models used by the water sector, based on design basis threat (DBT) and risk analysis and management for critical asset protection (RAMCAP), are rooted in the traditional risk formula of threat multiplied by vulnerability multiplied by consequence. This paper concludes that due to the inability to define who the adversary is, along with their objectives, motives, and capabilities, and the lack of statistically valid datasets or available intelligence of malevolent threats, the requirements listed in these methodologies are not achievable and will remain as unknowns in water/wastewater/stormwater systems. Therefore, the risk models used for mitigating adversarial threats have fundamental errors that should be replaced by an alternate risk model capable of measuring what can be known about facility resilience to malevolent attacks. By treating risk as a vector quantity consisting of known parameters, the probability of success of a given threat can be calculated using the mathematical analysis of defense strategy and countermeasures (MADSC) methodology. Once these parameters are established, the MADSC methodology can be used to determine the degree of difficulty in compromising existing countermeasures and provide guidance for physical security improvements and budgeting based on quantitative results.
    • Download: (1.752Mb)
    • Show Full MetaData Hide Full MetaData
    • Get RIS
    • Item Order
    • Go To Publisher
    • Statistics

      Empirical Risk Analysis Methodology for Adversarial Threats against Critical Infrastructure

    URI
    https://yetl.yabesh.ir/yetl1/handle/yetl/4297720
    Collections
    • Journal of Infrastructure Systems

    Show full item record

    contributor authorDavid W. Wallace
    contributor authorLloyd Foster
    contributor authorKris Schartau
    contributor authorDavid Lewin
    contributor authorConrad G. Keyes
    date accessioned2024-04-27T22:52:30Z
    date available2024-04-27T22:52:30Z
    date issued2024/03/01
    identifier other10.1061-JITSE4.ISENG-2291.pdf
    identifier urihttp://yetl.yabesh.ir/yetl1/handle/yetl/4297720
    description abstractThe increase in foreign and domestic threats mandates a serious reevaluation of existing security methodologies, standards, and vulnerability assessments. A comprehensive defense strategy with quantitative and qualitative measurements is presented on how the water sector can optimize the application and placement of physical security countermeasures to improve resilience based on known parameters in a cost effective way. This study reviews the history and original intent of these methodologies that were adopted from the atomic and nuclear segments of the energy sector. These methodologies served as a starting point for the risk assessment documents that govern water sector security. The current American National Standards Institute (ANSI) risk models used by the water sector, based on design basis threat (DBT) and risk analysis and management for critical asset protection (RAMCAP), are rooted in the traditional risk formula of threat multiplied by vulnerability multiplied by consequence. This paper concludes that due to the inability to define who the adversary is, along with their objectives, motives, and capabilities, and the lack of statistically valid datasets or available intelligence of malevolent threats, the requirements listed in these methodologies are not achievable and will remain as unknowns in water/wastewater/stormwater systems. Therefore, the risk models used for mitigating adversarial threats have fundamental errors that should be replaced by an alternate risk model capable of measuring what can be known about facility resilience to malevolent attacks. By treating risk as a vector quantity consisting of known parameters, the probability of success of a given threat can be calculated using the mathematical analysis of defense strategy and countermeasures (MADSC) methodology. Once these parameters are established, the MADSC methodology can be used to determine the degree of difficulty in compromising existing countermeasures and provide guidance for physical security improvements and budgeting based on quantitative results.
    publisherASCE
    titleEmpirical Risk Analysis Methodology for Adversarial Threats against Critical Infrastructure
    typeJournal Article
    journal volume30
    journal issue1
    journal titleJournal of Infrastructure Systems
    identifier doi10.1061/JITSE4.ISENG-2291
    journal fristpage04023036-1
    journal lastpage04023036-9
    page9
    treeJournal of Infrastructure Systems:;2024:;Volume ( 030 ):;issue: 001
    contenttypeFulltext
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian
     
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian