Quantifying Security for Networked Control Systems: A Review
Sribalaji C. Anand, Anh Tung Nguyen, André M. H. Teixeira, Henrik Sandberg, Karl H. Johansson
TL;DR
This article surveys methods for quantifying security in Networked Control Systems by separating attack impact (physical degradation) from attack resources (feasibility), and extends the discussion to probabilistic risk under imperfect knowledge. It covers both finite- and infinite-horizon metrics, with SDP/LP formulations for tractable computation, and analyzes large-scale and power-grid applications using graph-based and grounded-Laplacian approaches. The paper also surveys mitigation strategies that jointly tune controllers, detectors, filters, and sensor/actuator placement to reduce attack impact and increase required resources, while outlining future research directions in scalable, nonlinear, and data-driven settings. Collectively, the work provides a comprehensive framework for secure-by-design NCSs and a roadmap for integrating security quantification into system design and risk management.
Abstract
Networked Control Systems (NCSs) are integral in critical infrastructures such as power grids, transportation networks, and production systems. Ensuring the resilient operation of these large-scale NCSs against cyber-attacks is crucial for societal well-being. Over the past two decades, extensive research has been focused on developing metrics to quantify the vulnerabilities of NCSs against attacks. Once the vulnerabilities are quantified, mitigation strategies can be employed to enhance system resilience. This article provides a comprehensive overview of methods developed for assessing NCS vulnerabilities and the corresponding mitigation strategies. Furthermore, we emphasize the importance of probabilistic risk metrics to model vulnerabilities under adversaries with imperfect process knowledge. The article concludes by outlining promising directions for future research.
