Wei Zhiyuan, Zhuang Jun
Department of Industrial and Systems Engineering, University at Buffalo, Buffalo, New York, USA.
Risk Anal. 2025 Jan;45(1):177-193. doi: 10.1111/risa.15070. Epub 2024 Jul 11.
Confronting the continuing risk of an attack, security systems have adopted target-hardening strategies through the allocation of security measures. Most previous work on defensive resource allocation considers the security system as a monolithic architecture. However, systems such as schools are typically characterized by multiple layers, where each layer is interconnected to help prevent single points of failure. In this paper, we study the defensive resource allocation problem in a multilayered system. We develop two new resource allocation models accounting for probabilistic and strategic risks, and provide analytical solutions and illustrative examples. We use real data for school shootings to illustrate the performance of the models, where the optimal investment strategies and sensitivity analysis are presented. We show that the defender would invest more in defending outer layers over inner layers in the face of probabilistic risks. While countering strategic risks, the defender would split resources in each layer to make the attacker feel indifferent between any individual layer. This paper provides new insights on resource allocation in layered systems to better enhance the overall security of the system.
面对持续的攻击风险,安全系统通过分配安全措施采用了目标强化策略。先前关于防御性资源分配的大多数工作都将安全系统视为一个整体架构。然而,诸如学校之类的系统通常具有多层特征,其中每层相互连接以帮助防止单点故障。在本文中,我们研究多层系统中的防御性资源分配问题。我们开发了两个考虑概率和战略风险的新资源分配模型,并提供了分析解决方案和示例。我们使用校园枪击案的真实数据来说明模型的性能,并给出了最优投资策略和敏感性分析。我们表明,面对概率风险时,防御者会在防御外层上比内层投入更多。在应对战略风险时,防御者会在每层中分配资源,以使攻击者对任何单个层都无差异。本文为分层系统中的资源分配提供了新的见解,以更好地增强系统的整体安全性。