<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Methodology for quantitative assessment of critical infrastructure resilience</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Oleg Tretyakov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Batyr Khalmuradov</string-name>
          <email>batyrk@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maksym Pukha</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viktoriia Sydorenko</string-name>
          <email>viktoriia.sydorenko@npp.nau.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Larysa</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Chubko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Vitaliy Nechiporuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>Liubomyra Huzara Ave. 1, Kyiv, 03058</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>State Scientific and Research Institute of Cybersecurity Technologies and Information Protection</institution>
          ,
          <addr-line>Maksym Zalizniak Str., 3/6, Kyiv, 03142</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>State Service for Special Communications and Information Protection of Ukraine</institution>
          ,
          <addr-line>Solomianska St., 13, Kyiv, 03110</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>A methodological approach is proposed to quantify the level of resilience of critical infrastructure facilities, regardless of the critical infrastructure sector to which they belong and all types of project threats. The proposed approach makes it possible to conduct a resilience analysis for all elements of a critical infrastructure facility, conduct a comparable analysis of the vulnerability and resilience of sector facilities, assess the amount of additional investment required to reduce the vulnerability and increase the resilience of facility elements, develop sectoral programmes to improve the resilience of sector facilities, and determine the necessary territorial reserve resources and their volumes.</p>
      </abstract>
      <kwd-group>
        <kwd>resilience</kwd>
        <kwd>critical infrastructure</kwd>
        <kwd>quantitative assessment 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        Planning Guide published by the National Institute of Standards and Technology, buildings and
infrastructure play an important role in ensuring the health and vitality of a community's social and
economic fabric [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Achieving resilience can be challenging because of the highly complex
dependencies and interdependencies that exist in infrastructure systems, the geographic scope and
jurisdictional boundaries within which infrastructure systems operate, the distributed ownership of
infrastructure, the distributed responsibility for risk management, and the potential for failures to
cascade across systems [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>Infrastructure resilience depends on both the physical characteristics of the engineered
infrastructure systems and the capabilities of the organisations that influence the operation and
management of these systems (e.g. infrastructure owners and operators, regulators, suppliers and
contractors). Infrastructure resilience can be assessed at the asset, system or system of systems level.
Resilience is also influenced by organisational factors such as the existence of business continuity
and contingency plans, the level of staff training, the frequency of exercises to test plans, the
flexibility of staff working hours, and internal and external communication capabilities. All of this
requires a unified approach to quantify the resilience of critical infrastructure, especially when the
country recognises 24 sectors of critical infrastructure.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Analysis of recent research and publications</title>
      <p>Definitions of resilience vary considerably by author and discipline. Some of these differences are
related to the focus of the definition on a specific entity (e.g., enterprise resilience; system resilience;
community resilience). Other definitions of resilience emphasise different time periods (e.g.
resilience focusing on measures taken before and after a disaster). To understand infrastructure
resilience from a regional perspective, the definition of resilience is a logical and widely used option.</p>
      <p>The main elements of this definition - the ability to prepare for and adapt to changing conditions,
as well as to withstand and recover quickly from disruptions - can be described by four building
blocks: preparedness, mitigation measures, response capacity, and recovery mechanisms.</p>
      <p>
        Together, these four pillars can help practitioners break down the concept of resilience into
practical steps and ultimately measure progress in improving resilience over time. Table 1 describes
these pillars and provides examples for consideration [
        <xref ref-type="bibr" rid="ref10 ref9">9, 10</xref>
        ].
      </p>
      <p>This approach does help experts to break down the concept of resilience into practical steps and
to conduct a qualitative assessment of the resilience of critical infrastructure. However, it does not
allow for a comparative analysis of the resilience of critical infrastructure, especially if they belong
to different sectors of critical infrastructure.</p>
      <p>The purpose of the research is to develop a methodological approach to quantify the level of
resilience of critical infrastructure facilities, regardless of the critical infrastructure sector to which
they belong and all types of project threats.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Results of the research</title>
      <p>To overcome the difficulties in considering the components of resilience and concentrating them in
the context of infrastructure operations from a time perspective, it is possible to consider the
operation of a critical infrastructure facility as a function of the volume of service provision over
time under different conditions, especially under the influence of a hazard (natural, man-made,
terrorist, military), as shown in Figure 1.</p>
      <p>Until a hazardous event occurs, the critical infrastructure facility operates in a steady state and
provides services in the design scope. From the moment a hazardous event occurs: a natural disaster
(earthquake, landslide, flood, etc.), man-made accidents, unauthorised interference, cyberattack,
terrorist act, military attack, etc., the volume of services provided by the critical infrastructure facility
is sharply reduced or stopped altogether (t1). This is followed by a period of preparation for the
restoration of the facility's functioning (design work, concentration of the necessary material
resources, engagement of contractors, etc.), which precedes the restoration work, after which the
facility's capacity is restored with a gradual return to a sustainable mode of service provision in the
design volume.</p>
      <p>Description
Activities aimed at
anticipating relevant
threats/hazards and possible
consequences of their
occurrence, including
prevention and protection
measures; indicates the
adaptability of infrastructure
systems and the process of
integrating and incorporating
lessons learned
Activities aimed at countering
and/or absorbing the negative
effects of an event, reducing
the severity or consequences
of a threat; indicates the
reliability of the infrastructure.</p>
      <p>Measures and programmes
implemented or developed to
respond to and adapt to the
negative consequences of an
event; indicates the
resourcefulness of
infrastructure owners and
operators in managing crisis
situations
Activities and programmes to
help organisations return to an
acceptable level of working
conditions and recover from
an event; demonstrates the
ability to resume service
delivery quickly</p>
      <sec id="sec-3-1">
        <title>Mitigating the consequences Response Recovery</title>
        <p>Examples
• Maintenance of security forces
• Establishing/monitoring physical
access control
• Develop continuity plans,
contingency plans and cyber security plans
• Train staff on the plans
• Conduct regular drills to test the
plans
• Establish information sharing
mechanisms
• Modernisation of facilities to
mitigate the effects of various natural
hazards (e.g. flood control equipment, flood
barriers)
• Modernisation of equipment to
withstand foreseeable hazards
• Improving the
reliability/redundancy of infrastructure
support systems
• Establishment of an alternative
backup site that can continue operations
after an incident and facilitate recovery
• Understanding cross-sectoral
dependencies on key external resources
(e.g., electricity, fuel, water,
communications)
• Prepare additional supplies (e.g. fuel,
backup generators, backup
communications) in advance
• Maintaining on-site response
capabilities to key hazards (e.g. chemical
spills, fires, explosives, armed attacks,
medical emergencies)
• Building relationships with local first
responders and cross-sector partners
• Have the capacity to manage
contingencies on site, including trained
staff, a functional operations centre and an
understanding of cross-cutting issues
• Establish priority recovery
agreements with key service providers
• Estimating the time and activities
required to restore full organisational
operations after a disruption
• Strategies for rapid
replacement/repair of critical components
(e.g., certified vendors, maintaining
emergency stocks)</p>
        <sec id="sec-3-1-1">
          <title>Scope of services Vp</title>
        </sec>
        <sec id="sec-3-1-2">
          <title>A dangerous event</title>
          <p>t1
t2
and will characterise the vulnerability of the critical infrastructure facility.</p>
          <p>The resilience of a critical infrastructure facility (or its part, subdivision, etc.) can be defined as
the product of the time to full recovery and the costs associated with restoring the volume of services
to the baseline:
∆ ∙
where ∆ is time to fully restore the critical infrastructure facility (or its part, subdivision, etc.); ∑
– all recovery costs (financial, material, energy, human, transport, etc.).</p>
          <p>For convenience, the costs of restoring a critical infrastructure facility (or its part, subdivision,
etc.) can be taken not as an absolute value, but as a share of the facility's design cost.</p>
          <p>
            The initial stage after a hazardous event is a type of disaster manifestation in the theory of
disasters [
            <xref ref-type="bibr" rid="ref11">11</xref>
            ]. A "fold" type disaster ̶ is one of the simplest disasters. In this case, the
standard deformation (drop in the level of services) is given by the formula:
,
,
3
0
,
where is the scope of the service; is time.
          </p>
          <p>The numerical coefficient is introduced to simplify further calculations. The multivariety M of
such a catastrophe is defined by equation:</p>
          <p>The loss of service provision by a critical infrastructure facility as a result of a hazardous event
will be determined:
t
(4)
(1)
(2)
(3)
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•</p>
          <p>Determination of events in the scenario of the situation development (constituent elements
of the scenario that have a potential impact on the realisation of the threat).</p>
          <p>Determining the set of possible states of events that affect the threat level.</p>
          <p>Formation of threat development scenarios (identification of links consisting of pairs: "event
- transition to a given state") that lead to the realisation of the threat, presentation of a
structural and logical model of the development of a crisis situation that has a complex
structure according to different scenario options at a critical infrastructure facility.
Formation of a threat scenario organisation chart (a structural and logical model that includes
all threat scenarios).</p>
          <p>Estimation of probabilities of event states and their transitions.</p>
          <p>Assessing the likelihood of threat scenarios being realized.</p>
          <p>The use of such a simulation model for cascading effects makes it possible to obtain probabilistic
assessments of the development of events under certain scenarios and allows for the assessment of
threats to a critical infrastructure facility by the probability of events and transitions between them.</p>
          <p>Based on the obtained values of the probability of occurrence of hazardous events for all elements
of the critical infrastructure facility, we identify the most vulnerable ones and conduct a quantitative
assessment of their resilience. This makes it possible to assess the necessary resources (financial,
material, energy, human, transport, etc.) to increase resilience. Identify the necessary backup
elements to avoid cascading effects and undesirable consequences.</p>
          <p>This approach is appropriate for a critical infrastructure facility:</p>
          <p>If the quantitative assessment of the risk of hazardous events is carried out on the basis of a
simulation model to assess the threat of cascading effects for different scenarios in the area of the
critical infrastructure facility, which provides for the following procedures:</p>
          <p>Conduct a resilience analysis for all critical infrastructure facilities.</p>
          <p>Identify the most vulnerable and least resilient in the community.</p>
          <p>Develop a territorial programme to improve the resilience of critical infrastructure facilities.
Identify the necessary territorial reserve resources and their volume.</p>
          <p>Estimate the amount of additional investment required to reduce vulnerability and increase
the resilience of critical infrastructure in the community.
•
•
•
•
•</p>
          <p>Conduct a sustainability analysis for all elements of the facility.</p>
          <p>To determine the vulnerability and resilience of each in the event of any threats in
quantitative terms.</p>
          <p>Identify the most vulnerable and least resilient elements of the facility.</p>
          <p>Estimate the amount of additional investment required to reduce vulnerability and increase
the resilience of facility elements.</p>
          <p>Determine the necessary reserve resources and their volume.</p>
          <p>For a sectoral body in the field of critical infrastructure protection:</p>
          <p>Conduct comparable analyses of the vulnerability and resilience of sector facilities.
Identify the most vulnerable and least resilient.</p>
          <p>Develop a sectoral programme to improve the resilience of sector facilities.</p>
          <p>Identify investment priorities to improve the resilience of sector facilities.</p>
        </sec>
      </sec>
      <sec id="sec-3-2">
        <title>For territorial communities:</title>
        <p>The proposed approach can be used to develop Methodological Recommendations for assessing
the resilience of critical infrastructure facilities for the development of sectoral programmes to
improve their resilience.</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Conclusions</title>
      <p>Based on the theory of catastrophes, a unified methodological approach has been developed to
quantify the level of resilience of critical infrastructure facilities, regardless of the critical
infrastructure sector to which they belong.</p>
      <p>The proposed approach makes it possible to conduct a resilience analysis for all elements of a
critical infrastructure facility, conduct a comparative analysis of the vulnerability and resilience of
sector facilities, assess the amount of additional investment required to reduce the vulnerability and
increase the resilience of facility elements, develop sectoral programmes to improve the resilience of
sector facilities, and determine the necessary territorial reserve resources and their volumes.</p>
    </sec>
    <sec id="sec-5">
      <title>Declaration on Generative AI</title>
      <p>The author(s) have not employed any Generative AI tools.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] Law of Ukraine "On Critical Infrastructure" of 16.11.2021 No. 1882-IX as amended on 01.01</source>
          .
          <year>2024</year>
          (
          <article-title>1909-IX)</article-title>
          . URL: https://zakon.rada.gov.ua/laws/show/1882-20.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>C. S.</given-names>
            <surname>Renshler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. E.</given-names>
            <surname>Fraser</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. A.</given-names>
            <surname>Arendt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. P.</given-names>
            <surname>Cimellaro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. M.</given-names>
            <surname>Reinhorn</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bruno</surname>
          </string-name>
          ,
          <article-title>A framework for defining and measuring community-based resilience: the people-based resilience framework</article-title>
          ,
          <source>National Institute of Standards and Technology</source>
          ,
          <year>2010</year>
          . URL: https://hsdl.org/?view&amp;did=
          <fpage>790013</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Rose</surname>
          </string-name>
          , Economic resilience to disasters,
          <source>CARRI Research Report</source>
          <volume>8</volume>
          (
          <year>2009</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Zaliskyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Odarchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Petrova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Chaplits</surname>
          </string-name>
          ,
          <article-title>Method of traffic monitoring for DDoS attacks detection in e-health systems and networks</article-title>
          ,
          <source>CEUR Workshop Proceedings</source>
          <volume>2255</volume>
          (
          <year>2018</year>
          )
          <fpage>193</fpage>
          -
          <lpage>204</lpage>
          . URL: https://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>2255</volume>
          /paper18.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Al-Azzeh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. Al</given-names>
            <surname>Hadidi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. S.</given-names>
            <surname>Odarchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Shevchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          ,
          <article-title>Analysis of selfsimilar traffic models in computer networks</article-title>
          ,
          <source>International Review on Modelling and Simulations</source>
          <volume>10</volume>
          (
          <issue>5</issue>
          ) (
          <year>2017</year>
          )
          <fpage>328</fpage>
          -
          <lpage>336</lpage>
          . doi:
          <volume>10</volume>
          .15866/iremos.v10i5.
          <fpage>12009</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>APCBI</surname>
          </string-name>
          ,
          <article-title>"National Infrastructure Protection Plan (NIPP) 2013: Partnering for Critical Infrastructure Security and Resilience"</article-title>
          .
          <year>2013</year>
          . URL: https://cisa.gov/national-infrastructureprotection-plan.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <article-title>[7] NIST (National Institute of Standards and Technology</article-title>
          ),
          <source>Community Disaster Resilience Planning Guide for Buildings and Infrastructure Systems: Volume</source>
          <volume>1</volume>
          , May
          <year>2016</year>
          . URL: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.
          <volume>119</volume>
          0v1.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>N. S.</given-names>
            <surname>Kuzmenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>I. V.</given-names>
            <surname>Ostroumov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Marais</surname>
          </string-name>
          ,
          <article-title>An accuracy and availability estimation of aircraft positioning by navigational aids</article-title>
          ,
          <source>in: Proceedings of 5th International Conference on Methods and Systems of Navigation and Motion Control (MSNMC)</source>
          , IEEE, Kiev, Ukraine,
          <year>2018</year>
          , pp.
          <fpage>36</fpage>
          -
          <lpage>40</lpage>
          . doi:
          <volume>10</volume>
          .1109/MSNMC.
          <year>2018</year>
          .
          <volume>8576276</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>J. L.</given-names>
            ,
            <surname>Carlson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R. A.</given-names>
            <surname>Huffenden</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. W.</given-names>
            <surname>Bassett</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. A.</given-names>
            <surname>Behring</surname>
          </string-name>
          , M. D. Collins, III,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Folga</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Petit</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. A.</given-names>
            <surname>Phillips</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. R.</given-names>
            <surname>Werner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Whitfield</surname>
          </string-name>
          .
          <source>Resilience: Theory and Applications</source>
          , USA,
          <year>2012</year>
          . doi:
          <volume>10</volume>
          .2172/1044521.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>D.</given-names>
            <surname>Mi</surname>
          </string-name>
          et al.,
          <article-title>Demonstrating immersive media delivery on 5G broadcast and multicast testing networks</article-title>
          ,
          <source>IEEE Transactions on Broadcasting</source>
          <volume>66</volume>
          (
          <issue>2</issue>
          ) (
          <year>2020</year>
          )
          <fpage>555</fpage>
          -
          <lpage>570</lpage>
          . doi:
          <volume>10</volume>
          .1109/TBC.
          <year>2020</year>
          .
          <volume>2977546</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>J.</given-names>
            <surname>Thompson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Michael</surname>
          </string-name>
          , Instabilities and Catastrophes in Science and Engineering, New York, Wiley,
          <year>1982</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>