<p>Cyber resilience is now central to safety-critical cyber-physical systems (CPS), yet standards and assessments still treat it primarily as a security property. Interventions are implemented without knowing which aspects of resilience they affect, or whether one capability can compensate for another—leaving operators and regulators investing without knowing which operational outcome each intervention actually moves. This paper builds on the concept of a resilience trajectory: the measurable progression of system performance through degradation, detection, response and recovery. Using two industrial case studies and a physical safety-critical testbed, resilience attributes were selectively activated and observed under adversarial and non-adversarial disruption. The results show that resilience attributes do not contribute equally throughout a disruption: different domains performed different resilience functions, each exerting greatest influence at a particular phase while interacting throughout. Targeting the dominant domain for the affected phase produced the greatest improvement, suggesting that investment can be prioritised by identifying where resilience is lost and which domain constrains it. Critically, the domains were not interchangeable; weaknesses in one could not be fully compensated for by strengthening another. Building on these findings, a refined hierarchical taxonomy and cross-domain dependency model are introduced to trace how interventions influence outcomes and surface hidden consequence pathways, giving practitioners a clearer basis for prioritising resilience investment, and indicating where current assessment practice and standards could be strengthened.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Which resilience interventions move which outcomes in safety-critical CPS? Evidence from industrial case studies and controlled testbed experimentation

  • Kirsty Perrett,
  • Ian David Wilson

摘要

Cyber resilience is now central to safety-critical cyber-physical systems (CPS), yet standards and assessments still treat it primarily as a security property. Interventions are implemented without knowing which aspects of resilience they affect, or whether one capability can compensate for another—leaving operators and regulators investing without knowing which operational outcome each intervention actually moves. This paper builds on the concept of a resilience trajectory: the measurable progression of system performance through degradation, detection, response and recovery. Using two industrial case studies and a physical safety-critical testbed, resilience attributes were selectively activated and observed under adversarial and non-adversarial disruption. The results show that resilience attributes do not contribute equally throughout a disruption: different domains performed different resilience functions, each exerting greatest influence at a particular phase while interacting throughout. Targeting the dominant domain for the affected phase produced the greatest improvement, suggesting that investment can be prioritised by identifying where resilience is lost and which domain constrains it. Critically, the domains were not interchangeable; weaknesses in one could not be fully compensated for by strengthening another. Building on these findings, a refined hierarchical taxonomy and cross-domain dependency model are introduced to trace how interventions influence outcomes and surface hidden consequence pathways, giving practitioners a clearer basis for prioritising resilience investment, and indicating where current assessment practice and standards could be strengthened.