{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/121396"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/121396","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Strategic network security for critical infrastructures","abstract":"Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","abstract_html":"Submission original under an indefinite embargo labeled &#x27;Open Access&#x27;. The submission was exported from vireo on 2023-12-04 without embargo terms","abstract_has_math":false,"creators":["Palani, Kartik"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Nicol, David M","Smith, Sean W","Borisov, Nikita","Srikant, Rayadurgam"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023-08","date_published":"2023-08","updated_at":"2026-07-22T22:24:57Z","subjects":["Optimization","Cybersecurity, Cyber-physical Systems","Algorithms","Computer Networks"],"languages":["en","eng"],"rights":["Copyright 2023 Kartik Palani"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/121396","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nicol, David M","Smith, Sean W","Borisov, Nikita","Srikant, Rayadurgam"]},{"key":"dc:creator","label":"Author","values":["Palani, Kartik"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2023-08","2023-05-10"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Optimization","Cybersecurity, Cyber-physical Systems","Algorithms","Computer Networks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2023 Kartik Palani"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/121396"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","The student, Kartik Palani, accepted the attached license on 2023-05-05 at 17:39.","The student, Kartik Palani, submitted this Dissertation for approval on 2023-05-05 at 17:44.","This Dissertation was approved for publication on 2023-05-10 at 09:50.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19365 on 2023-12-04 at 16:59:38","The safety and integrity of critical infrastructures are of utmost importance to a nation's economy and security. In order to guarantee operational availability and service metrics, these infrastructures rely on automation provided by an underlying network of computers. In recent years, these automation systems have been used by attackers to gain access to and disrupt the physical processes being controlled. This dissertation aims to provide quantifiable methods to assess the risk added to the system by this extended attack surface and to design automated mechanisms for mitigating the system risk by selecting and deploying the right countermeasures. Any countermeasure strategy must account for the operational constraints that the system has in place for service guarantees and must make trade-offs between system availability and cybersecurity. The risk mitigation work presented in this dissertation generates countermeasure strategies that account for the strict communication deadlines between networked controllers, the regulatory requirements demanded by national regulators, and the security budgets of the infrastructure operators. Regarding risk assessment, we propose quantifiable metrics that can be used with operator expertise. We describe metrics that can be computed with or without knowledge about the attacker. We also provide a tool for measuring the monetary impact of a successful attack campaign. Regarding risk mitigation, we describe algorithms to select and deploy countermeasures. Since firewalls are used as a primary network security mechanism, we provide a detailed analysis of mitigating the risk allowed by the network access policy. We also show how we can rank countermeasure strategies that prioritize security against certain adversary groups under assumptions about attacker capabilities. Finally, we also design a new countermeasure that tackles one of the most commonly used attacker tactics."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Strategic network security for critical infrastructures"]}]}],"canonical_facts":{"dc:contributor":["Nicol, David M","Smith, Sean W","Borisov, Nikita","Srikant, Rayadurgam"],"dc:creator":["Palani, Kartik"],"dc:date":["2023-08","2023-05-10"],"dc:description":["Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2023-12-04 without embargo terms","The student, Kartik Palani, accepted the attached license on 2023-05-05 at 17:39.","The student, Kartik Palani, submitted this Dissertation for approval on 2023-05-05 at 17:44.","This Dissertation was approved for publication on 2023-05-10 at 09:50.","DSpace SAF Submission Ingestion Package generated from Vireo submission #19365 on 2023-12-04 at 16:59:38","The safety and integrity of critical infrastructures are of utmost importance to a nation's economy and security. In order to guarantee operational availability and service metrics, these infrastructures rely on automation provided by an underlying network of computers. In recent years, these automation systems have been used by attackers to gain access to and disrupt the physical processes being controlled. This dissertation aims to provide quantifiable methods to assess the risk added to the system by this extended attack surface and to design automated mechanisms for mitigating the system risk by selecting and deploying the right countermeasures. Any countermeasure strategy must account for the operational constraints that the system has in place for service guarantees and must make trade-offs between system availability and cybersecurity. The risk mitigation work presented in this dissertation generates countermeasure strategies that account for the strict communication deadlines between networked controllers, the regulatory requirements demanded by national regulators, and the security budgets of the infrastructure operators. Regarding risk assessment, we propose quantifiable metrics that can be used with operator expertise. We describe metrics that can be computed with or without knowledge about the attacker. We also provide a tool for measuring the monetary impact of a successful attack campaign. Regarding risk mitigation, we describe algorithms to select and deploy countermeasures. Since firewalls are used as a primary network security mechanism, we provide a detailed analysis of mitigating the risk allowed by the network access policy. We also show how we can rank countermeasure strategies that prioritize security against certain adversary groups under assumptions about attacker capabilities. Finally, we also design a new countermeasure that tackles one of the most commonly used attacker tactics."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/121396"],"dc:language":["en","eng"],"dc:rights":["Copyright 2023 Kartik Palani"],"dc:subject":["Optimization","Cybersecurity, Cyber-physical Systems","Algorithms","Computer Networks"],"dc:title":["Strategic network security for critical infrastructures"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:57Z"}