{"title":"Risk mitigation in resilient networks","authors":"P. Chołda, Piotr Guzik, Krzysztof Rusek","doi":"10.1109/RNDM.2014.7014927","DOIUrl":null,"url":null,"abstract":"This article proposes shifting the perspective for the design of resilient networks from cost-focused to one suited for business purposes. Risk engineering is used as a basis to enable us to monetarily express not only the cost of recovery, but also the impact of failures affecting connections (expressed with use of penalties imposed on an operator), and then to find the tradeoff between the cost of the assigned recovery methods and the improved level of resilience. During risk assessment, monetary quantification of penalties is applied with compensation policies, and business relevant risk measures are used. Then, risk response selection is based on various risk mitigation strategies (involving profit maximization, total benefit coverage, cost balance, and risk minimization) proposed in the security risk management. Looking for the cost-risk trade-off related to the assumed mitigation strategy is a complex optimization problem that cannot be modeled with deterministic linear programming. Therefore, to be able to choose recovery options, we develop a genetic algorithm. The results show diversity of recovery procedures selected for various selected mitigation strategies.","PeriodicalId":299072,"journal":{"name":"2014 6th International Workshop on Reliable Networks Design and Modeling (RNDM)","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 6th International Workshop on Reliable Networks Design and Modeling (RNDM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/RNDM.2014.7014927","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
This article proposes shifting the perspective for the design of resilient networks from cost-focused to one suited for business purposes. Risk engineering is used as a basis to enable us to monetarily express not only the cost of recovery, but also the impact of failures affecting connections (expressed with use of penalties imposed on an operator), and then to find the tradeoff between the cost of the assigned recovery methods and the improved level of resilience. During risk assessment, monetary quantification of penalties is applied with compensation policies, and business relevant risk measures are used. Then, risk response selection is based on various risk mitigation strategies (involving profit maximization, total benefit coverage, cost balance, and risk minimization) proposed in the security risk management. Looking for the cost-risk trade-off related to the assumed mitigation strategy is a complex optimization problem that cannot be modeled with deterministic linear programming. Therefore, to be able to choose recovery options, we develop a genetic algorithm. The results show diversity of recovery procedures selected for various selected mitigation strategies.