Cyber Risk Analysis for a Smart Grid: How Smart is Smart Enough? A Multiarmed Bandit Approach to Cyber Security Investment

被引:35
|
作者
Smith, Matthew David [1 ]
Pate-Comell, M. Elisabeth [1 ]
机构
[1] Stanford Univ, Dept Management Sci & Engn, Stanford, CA 94305 USA
关键词
Cyber-physical security; multiarmed bandit (MAB); smart grid; DEFENSE; FRAMEWORK; INTERNET; ATTACKS; MODELS;
D O I
10.1109/TEM.2018.2798408
中图分类号
F [经济];
学科分类号
02 ;
摘要
As electric sector stakeholders make the decision to upgrade traditional power grid architectures by incorporating smart grid technologies, the benefits of added connectivity must be weighed against the risk of increased exposure to cyber-attacks. Therefore, decision makers must ask: How smart is smart enough? This paper presents a probabilistic risk analysis framework to address this problem. The goal is to quantify the overall benefit and risk of adding connections to a network and hiring a number of cyber defense teams, with the objective to help decision makers formally assess tradeoffs and set priorities given limited resources. Central to this approach is a new Bayes-adaptive network security model based on a reformulation of the "multiarmed bandits" (MAB) problem. Here, instead of projects with uncertain probabilities of success as in the classic MAB problem, a network defender faces the possibility of attacks against network nodes at uncertain Poisson-distributed rates. This new technique, which by similarity we call "multinode bandits," takes a dynamic view of cyber security investment, exploring how network defenders can optimally allocate cyber defense teams among nodes. In effect, this approach entails employing proactively for defensive and information gathering purposes teams that traditionally respond to cyber breaches after they occur. We apply this model to the case study of an electric utility considering the degree to which they should integrate demand response into their smart grid network, jointly identifying both the optimal level of connectivity and the optimal strategy for the sequential allocation of cyber security resources.
引用
收藏
页码:434 / 447
页数:14
相关论文
共 50 条
  • [1] Cyber Risk Analysis for a Smart Grid: How Smart is Smart Enough? A Multi-Armed Bandit Approach
    Smith, Matthew
    Pate-Cornell, Elisabeth
    [J]. SYSTEMS APPROACH TO CYBER SECURITY, 2017, 15 : 37 - 56
  • [2] A Cyber Security for a Smart Grid
    Halder, T.
    [J]. 2014 6TH IEEE POWER INDIA INTERNATIONAL CONFERENCE (PIICON), 2014,
  • [3] An Analysis of Smart Grid Communication Infrastructure & Cyber Security in Smart Grid.
    Jahan, Sharmin
    Habiba, Rabeya
    [J]. 2015 INTERNATIONAL CONFERENCE ON ADVANCES IN ELECTRICAL ENGINEERING (ICAEE), 2015, : 190 - 193
  • [4] Cyber Security of Smart Grid Infrastructure
    Camachi, Balduino Estison Mugilila
    Ichim, Loretta
    Popescu, Dan
    [J]. 2018 IEEE 12TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI), 2018, : 303 - 308
  • [5] Smart grid cyber security for Europe
    Pearson, Ivan L. G.
    [J]. ENERGY POLICY, 2011, 39 (09) : 5211 - 5218
  • [6] An Overview of Cyber Security for Smart Grid
    Zhao, Zhiheng
    Chen, Guo
    [J]. 2018 IEEE 27TH INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2018, : 1127 - 1131
  • [7] Smart Grid Cyber Security Guidelines Released
    Hovland, Al
    Lyter, Frank G.
    Truchot, Charles
    [J]. POWER, 2010, 154 (10) : 16 - +
  • [8] Methodology of Cyber Security Assessment in the Smart Grid
    Woo, Pil Sung
    Kim, Balho H.
    [J]. JOURNAL OF ELECTRICAL ENGINEERING & TECHNOLOGY, 2017, 12 (02) : 495 - 501
  • [9] Cyber security in the Smart Grid: Survey and challenges
    Wang, Wenye
    Lu, Zhuo
    [J]. COMPUTER NETWORKS, 2013, 57 (05) : 1344 - 1371
  • [10] Cyber, Physical, and System Security for Smart Grid
    Ren, Kui
    Li, Zuyi
    Qiu, Robert Caiming
    [J]. IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (04) : 643 - 644