Review on Energy Resilience

profileharsh55
AMethodologicalOverviewofNetwork.pdf

A Methodological Overview of Network Vulnerability Analysis

ALAN T. MURRAY, TIMOTHY C. MATISZIW, AND TONY H. GRUBESIC

ABSTRACT Evaluating network infrastructures for potential vulnerabilities is an important

component of strategic planning, particularly in the context of managing and mitigating service

disruptions. Many methods have been proposed to facilitate such analysis, providing different

interpretations of infrastructure vulnerability. The primary approaches that have been employed for

network vulnerability analysis can be broadly classified as scenario-specific, strategy-specific,

simulation, and mathematical modeling methodologies. Research on network vulnerability assess-

ment has traditionally focused on one of these methodologies without consideration of the others.

This article highlights the important implications of methodology for both infrastructure planning

and policy development. To better understand the theoretical and practical trade-offs associated

with methodology selection, this article provides a review of these categories of analysis, exam-

ining benefits and shortcomings with regard to practical planning issues and policy interpretation.

Introduction

S ocietal functions are highly dependent on networked systems. Even the most basicday-to-day functions involve interaction with a variety of critical infrastructure systems. For example, millions of Americans utilize transportation infrastructure to get to work, school, or the local mall. Telecommunication infrastructure is used to maintain contact with family and friends, shop, or perform financial transactions. Energy infrastruc- ture is used to heat our homes, power local industries, and deliver fuel to our automobiles. While these basic activities are common, the magnitude of infrastructure use is less obvious. For instance, over 19 billion tons of freight valued at $13 trillion dollars was moved through the U.S. multimodal transportation system during 2002 (U.S. Department of

Alan T. Murray is a professor in the School of Geographical Sciences, Arizona State University. His

e-mail address is: [email protected]. Timothy C. Matisziw is an assistant professor in the Department

of Geography and Department of Civil and Environmental Engineering, University of Missouri. His

e-mail address is: [email protected]. Tony H. Grubesic is an assistant professor in the Depart-

ment of Geography, Indiana University. His e-mail address is: [email protected]. The authors

wish to acknowledge the critical comments of two referees. This research is based upon work supported

by the National Science Foundation under Grants No. 0720989 and 0718091. Any opinions, findings,

and conclusions or recommendations expressed in this material are those of the author(s) and do not

necessarily reflect the views of the National Science Foundation.

Growth and Change Vol. 39 No. 4 (December 2008), pp. 573–592

Submitted November 2007; revised April 2008; accepted June 2008. © 2008 Copyright the Authors Journal compilation © 2008 Wiley Periodicals, Inc.

Transportation 2006). Where telecommunication networks are concerned, U.S. backbone traffic exceeded 100 petabytes per month in 2002 (SVBJ 2002). Assuming an average e-mail is 25 kilobytes, this translates into 45,035,996,273 e-mails per month. Finally, the daily delivery capacity of the U.S. natural gas grid is 119 billion cubic feet, with yearly consumption estimated at 22.8 trillion cubic feet for 2002. Considering the degree to which industrialized societies are reliant on such critical infrastructure systems, their importance should not be underestimated. Moreover, because the operability of these systems can be vulnerable to disasters, accidents, and intentional harm, there is a need to understand how networked systems, and their functionality, might be impacted should disruption occur.

Equally important are the public policy considerations for critical infrastructure systems. For example, not only does public policy play a role in how networks are constructed (e.g., rights-of-way), operated (e.g., access fees), and maintained (e.g., pub- licly or privately financed), it also impacts how disruptions are managed when networked systems are compromised. For instance, the U.S. Department of Homeland Security’s (2004) National Response Plan outlines the pertinent details of disaster response and recovery within the U.S., highlighting organizational structure, agency roles, and respon- sibilities and priorities for incident management. This plan was largely ineffective in a number of ways leading up to and following Hurricane Katrina in 2005 (Davis 2006), as local, state, and federal disaster response was plagued by miscommunication, failures to coordinate mitigation efforts, and generally poor preparation at all levels of government.

Hidden within this mesh of inadequate policy coordination and implementation are issues concerning how policy frameworks and plans, such as the National Response Plan, are actually generated. While it might be overly optimistic to assume that all public policies are based on carefully constructed science, recent work suggests that even the most basic requirements of an empirical study, such as data quality (e.g., precision, accuracy, vague- ness, completeness, consistency, distribution, and documentation) have the potential to bias both the results and subsequent policy generation (Grubesic and Murray 2005). In addition to data concerns, analysts need to be aware that many empirical studies focusing on critical infrastructure planning and network vulnerability assessment have relatively narrow methodological breadth and often ignore interdependencies between interacting systems. In this context, the North American Electrical Blackout of 2003 is a prime example of a failure to anticipate critical scenarios, such as those involving the collapse of secondary (e.g., telecom, water, oil, gas, etc.), interconnected systems (Grubesic and Murray 2006; Perrow 1999).

The purpose of this article is to explore how different methods of network vulnerability analysis impact infrastructure planning and policy development. To better understand the theoretical and practical trade-offs associated with each methodological approach, a basic typology of network vulnerability approaches is proposed, namely: scenario specific, strategy specific, simulation, and mathematical modeling. This is followed by a thorough review of these categories of analysis, examining associated benefits and shortcomings with regard to practical planning issues and policy interpretation.

574 GROWTH AND CHANGE, DECEMBER 2008

Background and Multimethod Approaches to Analysis A common theme in the analysis and evaluation of network-based critical infrastructure

is interdiction, where network elements (nodes or arcs) are disabled, intentionally or otherwise, disrupting the flow of valuable goods or services through the network. Again, this could be the result of a targeted attack, accident, or natural disaster. As an example, consider the infrastructure network shown in Figure 1, depicting some of the major gas pipelines in the state of Ohio. Some questions that arise in this case are: How vulnerable is this critical infrastructure to interdiction? What are the potential impacts of a particular interdiction scenario? Is the existing network structure one that enhances or diminishes network survivability? Which nodes or arcs, if lost, would cause the most damage to the system? What type of methodological approach(es) is best for evaluating the potential vulnerabilities of this system?

Methodologies for identifying potentially important network interdiction scenarios are wide-ranging in their conceptual and technical frameworks. However, their specific focus can result in limited applicability in planning and policy development contexts. These

FIGURE 1. GAS PIPELINES IN OHIO.

NETWORK VULNERABILITY ANALYSIS 575

limitations often arise due to the geographic scope of analysis in which a scenario is evaluated. In some cases, disruption scenarios are analyzed independently. For example, one might assume that the loss of a major electrical substation is a scenario warranting further analysis. While this may be true, the loss of two seemingly minor substations might actually represent a larger threat to network operation. In reality, vulnerability is a multi- faceted concept, and problems can arise when a single measure is relied upon to describe systemic weaknesses (Haimes 2006). For instance, a focus on characteristics of individual facilities (e.g., size, number of adjacent facilities) might ignore a facility’s role in network connectivity. Alternatively, a focus on system connectivity might ignore how a network is actually used (e.g., flow of goods, available capacity). Further, assessment of measures used to characterize network performance often depend on the temporal and spatial scale at which analysis is conducted as well as the duration of the disruptive event.

Such a limited perspective on network vulnerability is indicative of a much larger public policy issue. Narrow methodological views are likely to generate myopic and contentious results and inconsistencies in public policies. Moreover, in an era where damage from natural or technological disasters routinely cost billions of dollars, impacting local, regional, national, and international economies (e.g., Hurricane Katrina), the ability to develop holistic public policies is dependent on quality data, diverse and robust method- ologies, and rigorous interpretation of the empirical results.

Elements of general systems theory (GST), specifically multimethod analytical frame- works, offer theoretical insight into these issues. With roots in biology, the goal of GST is to determine the optimum degree of scientific generality across different levels of abstraction and different disciplines (Bertalanffy 1950; Boulding 1956). More specifi- cally, GST can accommodate a holistic approach to critical infrastructure planning prob- lems, which are routinely complex and richly interconnected—allowing local, regional, and federal planning organizations as well as policy makers the ability to adapt to con- stant shifts in their environment (Jackson 2006). This is necessary since narrowly defined problems and their subsequent analyses often concentrate on parts of the problem (or system), missing crucial interactions and failing to account for consequences of pre- scribed (or unexpected) actions in other parts of the system. Consider, for instance, the August 2003 electrical blackout in North America. With the loss of a single electricity generation plant in Cleveland, Ohio, a cascading failure of interconnected electrical systems commenced, eventually generating a blackout encompassing eight U.S. states, two Canadian provinces, and nearly 50 million people (ELCON 2004). In addition to the loss of electricity, telecommunication hubs were unable to route data (Renesys Corpo- ration 2004), water pumps in high-rise apartment buildings failed throughout the North- eastern U.S., and thousands of commuters were stranded in the New York City subway system (North American Electric Reliability Corporation [NERC] 2004). In this instance, the collateral consequences of electrical failure were felt across a wide variety of infra- structure systems and throughout a relatively large geographic region (Grubesic and Murray 2006). The economic damages alone were estimated at $6.4 billion (Anderson and Geckil 2003).

576 GROWTH AND CHANGE, DECEMBER 2008

In a causal analysis of the 2003 Blackout, the NERC determined that a complex matrix of necessary environmental and engineering conditions existed on August 14, 2003, com- bined with a number of violations relating to operating policies and planning standards,1

that when combined, allowed the blackout to occur (NERC 2005). Clearly, in this case, hindsight allows planners to deconstruct exactly what happened and why this chain of events led to a total system collapse. However, the challenge for planners and policy makers is identifying important scenarios before they occur and developing strategic plans for reducing associated vulnerability to disruption.

Multimethodology. Mingers and Brocklesby (1997) contend that in order to make the most effective contribution in dealing with the complexities and richness of the real world, it is often desirable to go beyond using a single methodology for solving problems. In an attempt to decompose the analytical elements that form a multimethodological frame- work, Mingers and Brocklesby make distinctions among paradigm, methodology, and technique. For example, paradigms are a generalized set of philosophical assumptions that define the nature of how research may be conducted and the results interpreted. The “quantitative revolution” in geography is a good example of this. Methodology is a struc- tured set of operating principles that assist in the research process. Methodologies typically embody the philosophical assumptions of their paradigm. Techniques are specific research activities that fit within the methodology. Examples include integer programming, factor analysis, and the like. Mingers and Brocklesby also suggest that methodologies specify what types of activities should be undertaken whereas techniques provide avenues for executing the activities.

Again, the fundamental value in multimethodology is the ability to provide a spectrum of solutions to planning problems and their interventions by incorporating a diversity of methods and techniques (Jackson and Keys 1984). More importantly, interventions to a system, whether the development of new operational procedures and contingency plans, fortification of critical infrastructures, or the expansion of an infrastructure’s geographical footprint, often proceed incrementally, with each phase posing a different set of tasks or problems. Further, with each additional change to a critical infrastructure system, the matrix of vulnerabilities and threats also changes, potentially impacting secondary and/or interconnected systems. As a result, many different methodologies and techniques might be needed to accommodate analysis and understanding of these rapidly changing systems to ensure that threats are adequately accounted for.

The use of multiple methodologies for evaluating the vulnerability of critical infrastruc- ture, particularly networks, is essential for deepening our understanding of the implications of unplanned events. Further, by providing a spectrum of empirical results that are based on a multimethodological framework, one can better inform strategic plans and related policy mechanisms for securing these important systems.

A Typology of Approaches for Evaluating Network Vulnerability As noted previously, a vast array of approaches exist for analyzing infrastructure

networks. These approaches differ primarily in how disruption scenarios are assessed and

NETWORK VULNERABILITY ANALYSIS 577

understood. A disruption scenario, in this context, is the set of network facilities that are impacted, the degree to which they are disabled, and the operating conditions (e.g., network activity and arc/node capacities) of the network prior to the disruption. In some cases, an affected facility may be rendered completely inoperable by a disruption (e.g., a router failure in a telecommunications network). In other instances, a disruption may impact network activity to a lesser degree given that only some of the functionality of a facility may be lost, as might be the case with an accident blocking a single lane of an interstate highway segment. Once disruption scenarios are identified, impact assessment is possible. Impacts can range from those directly associated with network operation, such as connec- tivity, flow, or capacity reduction, to more complex associations, such as the economic impacts affecting the production and consumption of flows. For example, reconsider Figure 1. Suppose that three different scenarios are identified as important with respect to risk and vulnerability in the functioning of this critical infrastructure network. One scenario involves two important storage/compressor stations, or nodes 1 and 2 in the network. Another scenario details three significant transmission corridors, arcs A, B, and C in the network. A final scenario specifies one important storage/compressor station and two-corridors (node 3 and arcs D and E). Given that each scenario is important in some unique way, how can one synthesize and understand the vulnerability and risk to the network in this context? What happens when there are hundreds (or thousands or more) of important scenarios? Such a situation is precisely what was found in Matisziw and Murray (2009), where over 17 billion unique and potentially important interdiction scenarios were found for a portion of the U.S. interstate highway network.

A more pressing concern is the variety of methodological approaches available for vulnerability assessment. How can researchers, planners, or analysts be assured that the approach used to identify network vulnerabilities provides a complete picture of the situation? Troubling is the potential for a significant network vulnerability that is not identified in the planning process. In an effort to provide some insight into such problems, we present a typology of approaches for identifying important disruption scenarios and evaluating associated network vulnerabilities. From facility-specific analyses to system- oriented approaches, each of the outlined families of methods provides a unique perspec- tive on network vulnerability. However, the larger challenge is effective integration or use of all approaches to better inform vulnerability analysis.

Scenario-specific assessment. Scenario-specific approaches evaluate the potential ramifications of a specific disruption scenario or small set of scenarios. These types of approaches help to answer “what if ” questions regarding a particular disruption and can facilitate basic comparison between select scenarios of interest. For instance, one might be interested in the impact of losing an electrical substation, a bridge, a road segment, or a telecommunications router on network performance, or perhaps the economic relationships between regions. Scenario-specific approaches are useful when questions arise about the impact of a specific set of disruption scenarios perceived to be important. Since a limited number of scenarios are generally considered, these approaches can permit relatively detailed analysis of each scenario, such as more refined models of impacts to flow, changes

578 GROWTH AND CHANGE, DECEMBER 2008

to regional economic functions, incorporation of logistical and political considerations, environmental impacts, as well as detailed information on the costs involved in repairing or upgrading the facilities involved. Other parameters unique to each scenario can also be easily integrated in the analysis. Scenario-specific analyses are probably the most prevalent approach in practice, given their flexibility of application. Moreover, in many cases, planners and policy makers are only concerned with better understanding a facility’s role within a system versus how it compares with other facilities in terms of potential impact to the system as a whole. Figure 2 illustrates such a planning scenario. In Figure 2, portions of the U.S. interstate system in Ohio that are important to inter-MSA (metropolitan statistical areas) freight flows are shown. In this case, a planner might note the importance of the portion of Interstate highway 70 between Dayton and Columbus to inter-MSA traffic and seek to assess the potential impacts associated with a scenario involving the loss of all lanes of traffic between the two cities. To evaluate the impact of this scenario on network

FIGURE 2. PORTION OF THE INTERSTATE HIGHWAY SYSTEM IN OHIO.

NETWORK VULNERABILITY ANALYSIS 579

performance, analysis might involve network topology (e.g., nodal adjacency, internodal distance/cost, arc capacities) as well as some measure of network performance (e.g., graph theoretic metric, transportation cost, connectivity, flow, or some other derived measure). Given this information, network performance before and after the loss of this section of interstate highway could be measured, allowing the potential impact to be assessed.

Scenario-specific approaches have been applied in a range of planning contexts. For instance, Kim, Ham, and Boyce (2002) evaluate the potential economic impacts arising from several scenarios of transportation corridor disruptions stemming from an earthquake. Each of the scenarios is analyzed as to the commodity flows that might be affected and the transportation cost incurred. In another case, Suarez et al. (2005) consider the issue of sea rise and resulting impacts to transportation performance in a coastal area. They define disruption scenarios based on the levels of sea rise anticipated in various planning periods. Given the portions of the transportation system involved in these scenarios, impact to trip production/attraction and system performance is assessed. Alternatively, given sce- narios identified by expert opinion, Lambert and Sarda (2005) discuss potential impacts with respect to other, interdependent networks. Finally, in the context of assessing agency response to a disaster, Hood et al. (2003) discuss an integrated transportation assessment system for identifying potential disruption scenarios and assessing the efficiency of current operational response plans and/or developing new responses to identified scenarios.

The major benefits from this type of analysis are that important scenarios can be readily identified by domain experts and that relatively complex analytical approaches (quantita- tive or qualitative) can be used to evaluate each potential scenario. The focus on a limited number of scenarios also allows for nonlinear relationships between network locations as well as the many intricacies unique to each situation to be addressed. The end result of such analysis can provide a very detailed understanding on the ramifications of the particular scenarios assessed. The insights gained from this process can be of use in determining the value of a facility or set of facilities to network activity and related processes. For example, policy makers might be interested in better understanding who certain scenarios impact and who should therefore be involved in decisions regarding the associated facilities. This type of question is often of interest since many infrastructures have transitioned from local focus and management to a regional/national focus over time (e.g., electrical power industry).

The potential drawback to scenario-specific approaches is that relatively few scenarios are typically evaluated. First, planning based on analysis of a small subset of scenarios ignores threats posed by seemingly unrelated (and unevaluated) scenarios. A recent dis- ruption in the Sprint Nextel fiber optic network in the U.S. illustrates this point. Although the network has been designed to minimize service disruptions provided the loss of a single component, the simultaneous loss of multiple fiber optic linkages was a less anticipated planning consideration, particularly given the widespread service outages resulting from such a loss (CNN 2006; C|NET 2006). As mentioned earlier, many network infrastructures have been assembled incrementally over time by a variety of institutions and agencies and in some cases eventually merged together (e.g., transportation or the electrical grid). Therefore, a focus on a single component or portion of an infrastructure of local interest

580 GROWTH AND CHANGE, DECEMBER 2008

can produce misleading insights on vulnerability at larger scales. These are obviously problematic issues in terms of contingency planning. Second, the relative disruptive impact of scenarios is only in relation to the scenarios identified. Thus, potential exists for important scenarios to be overlooked, resulting in inaccurate characterizations of network vulnerability. That is, scenario-specific methods are really not ideal for establishing the potential of disruption scenarios relative to the system as a whole. This issue is frequently exacerbated since scenario-specific approaches are often conducted by a variety of agencies charged with managing different portions of an infrastructure. Thus, methods of analysis and evaluation criteria may differ from scenario to scenario, making comparison difficult.

Strategy-specific assessment. Related to the scenario-specific approaches in the Scenario-Specific Assessment section is what we term strategy-specific evaluations of network vulnerability. Strategy-specific approaches address questions such as: how vulner- able is a network to a structured or coordinated loss of facilities? In strategy-specific approaches, scenarios of interest are those following a hypothesized sequence or strategy of disruption. For instance, if a targeted attack to a network is of concern, then it might be assumed that the attackers would try to coordinate their attacks in terms of perceived facility importance.

Such approaches are precisely those of interest in much of the statistical physics research on infrastructure vulnerability. One common methodology is to rank network facilities (arcs/nodes) in order of their importance (usually based on their topological characteristics), then successively remove them, assessing the impact to network operation at each stage (see Albert, Hawoong, and Barabasi 2000). Other adaptations of this basic approach have also been proposed, such as recomputing facility importance and reranking facilities after each removal or simply randomized removal of arcs/nodes (see Albert, Albert, and Nakarado 2004; Holme et al. 2002). Given the Ohio interstate example in Figure 2, one might be interested in examining the impact associated with losing highway segments, sequentially with respect to the traffic volume they support. For example, the highway segment carrying the largest daily inter-MSA freight flow (I-77 between Cleveland and Akron) might be the first segment rendered inoperable in the network and the resulting impact to freight flow can be assessed. After this segment is lost and traffic readjusts, the segment supporting the next largest volume of inter-MSA traffic (I-75 between Hamilton and Cincinnati) is then rendered inoperable, and the incremental process of assessing impact to network operation subject to link failure continues.

Applying a strategy-specific approach to network evaluation is useful in assessing the vulnerability of different network configurations to identical attack strategies. For instance, a possible planning goal might be to select a network configuration least vulnerable to random loss of network nodes or arcs. To address this question, several networks could be evaluated with respect to their vulnerability to random attacks, offering insight on which appears to be more resilient to such an event.

There are obvious limitations to this type of approach since vulnerability com- parisons between networks are limited by the assumed attack strategy. That is, as with scenario-specific approaches, not all scenarios are evaluated; thus, inferences on relative

NETWORK VULNERABILITY ANALYSIS 581

vulnerability to any other scenarios of facility loss are only premised on the scenarios considered. While one network configuration might appear less vulnerable to a random loss of nodes, it might be more vulnerable to other types of losses that are not considered. Second, these types of approaches often need to make assumptions related to the way in which network losses will be coordinated. To do this, the relative importance of network facilities to system functionality are established before any analysis is conducted. Such assumptions can produce misleading results as many networked systems entail a complex mesh of interrelations between network components that are difficult to assimilate by evaluating the characteristics of individual facilities (Doyle et al. 2005). Further, analysis of the impacts of incremental loss of network arcs/nodes ignores combinatorial aspects of disruption where a certain number of network facilities may be simultaneously disabled. Yet another drawback to strategy-specific approaches is that the exact impact of a disruptive scenario is assumed to be readily measurable and necessarily needs to be comparable to impacts resulting from other scenarios. In other words, disruption impact is typically derived according to the same performance criteria for each scenario although other scenario-specific conditions may exist that either exacerbate or decrease the effect of a disruption.

Simulation assessment. If there are no a priori assumptions regarding facility/scenario importance to disruption vulnerability, then simulation-based analysis of disruptive sce- narios can be insightful. Simulation-based approaches seek to answer questions such as: how do disruptive/remediation scenarios compare with respect to their potential to impact infrastructure operation? Simulation analysis acknowledges that for any network, there are many possible planning scenarios to be considered. Even for moderately sized networks, uncovering potential vulnerabilities and associated scenarios can be challenging, given the complex spatial relationships between origins and destinations. In simulation-based approaches, the goal is to evaluate a suitable number of scenarios to obtain an effective characterization of the range of possible impacts (see Matisziw, Murray, and Grubesic, forthcoming). For instance, if a network is composed of n nodes and the complete loss of one

network node is a major planning concern, then n n

n1 1 ⎛ ⎝⎜

⎞ ⎠⎟

= −( ) !

! feasible scenarios exist and

might warrant attention. If a two node loss is of interest, then there are n n

n2 2 2 ⎛ ⎝⎜

⎞ ⎠⎟

= −( ) !

! feasible scenarios. The situation becomes more complex when a partial disruption to network facilities occurs. Further, simulation assessment of scenarios can also involve specification of many other parameters, such as the performance metric used to evaluate disruption, probabilistic information, as well as characterizations specific to the temporal and spatial scale of analysis. This is important since network activity and other operating conditions can exhibit a large degree of temporal and spatial variability, as can mitigation and repair strategies needed to restore system operation following a disruptive event. Given informa- tion on the dynamic nature of network conditions, simulation can also be used to explore important shifts and changes in network vulnerability in relation to such variability.

Simulation-based approaches are especially useful for describing the range of possible scenarios when complete scenario enumeration is not an option. For instance, one approach

582 GROWTH AND CHANGE, DECEMBER 2008

might be to randomly generate a sample of scenarios and assess their relative disruptive potential. Regardless of how the range of feasible scenarios is characterized, interpretation is possible through comparison with other scenarios. As an example, consider a disruption which simultaneously disables three of the interstate highway segments in Figure 2. Since there are 34 segments in the generalized network shown, 5,984 such scenarios exist, each having a unique impact on network operation (Figure 3). As can be observed from the graphic, there is a scenario involving the loss of three highway segments that could potentially impact over 22,000 trucks per day. This scenario is an upper bound on network disruption. Alternatively, there are some scenarios that have no impact on inter-MSA flow. These scenarios represent a lower bound on network disruption. What simulation seeks to do is to characterize the range of scenario impacts in between these bounds. In this particular case, it is clear that the range of possible impacts is skewed, with a majority of scenarios resulting in lower levels of flow disruption. However, several scenarios are identified that could potentially be very disruptive to inter-MSA trucking.

Clearly, there is great value in this type of approach, because it provides a more complete basis from which to assign scenario likelihood values and begin to prioritize scenarios in terms of management and disruption mitigation decisions. Also, given that many scenarios are derived, it then is possible to better understand how changes to one scenario (e.g., remediation) might impact other scenarios (see Ellison et al. 1999). Thus, instead of viewing scenarios myopically, potential ramifications of management and/or remediation become more apparent. Simulation can also enhance the flexibility of analysis given that disruption scenarios across multiple geographic scales can be readily identified and compared. Another notable benefit to scenario simulation is that analysis of large

0

5,000

10,000

15,000

20,000

25,000

loss of 3 arcs

d ai

ly t

ru ck

s d

is ru

p te

d

arc loss scenariorange

greatest impact

least impact

FIGURE 3. SCENARIOS INVOLVING THE LOSS OF THREE HIGHWAY ARCS AND THEIR IMPACT ON DAILY TRUCK TRAFFIC.

NETWORK VULNERABILITY ANALYSIS 583

networks is easily accommodated, an aspect that is often a limiting factor in other modeling approaches.

Given its numerous benefits, simulation is also a popular means for assessing network vulnerability. For example, Houck et al. (2004) use a simulation-based approach to assess scenarios of network disruptions based on both component failure and on overloading of network capacity in a telephony infrastructure. Given a particular type of disruptive scenario, simulation results are reported regarding how network performance (e.g., blocked calls) is impacted. Others, such as Jenelius, Petersen, and Mattsson (2005), address the more simplistic problem of evaluating scenarios involving the loss of a single arc in a network. Given that the number of scenarios in this case is equivalent to the number of arcs in the network, all scenarios are easily enumerated, and network performance for the scenarios is summarized according to a variety of derived measures.

While simulation certainly has benefits, it also has the potential to overlook important scenarios. Of course, provided the network is small enough and the range of partial disruptions is minimal, then all feasible scenarios could be enumerated and the impact of each scenario could then be assessed. A complete evaluation of all scenarios guarantees that the disruption(s) resulting in the worst possible impact to infrastructure (worst-case scenario) have been identified, allowing an upper bound on network vulnerability to be established. Such an upper bound is desirable for providing a benchmark for any other scenario considered. From a planning standpoint, it is much easier to defend scenario prioritization once potential impact, relative to the entire network, has been established. In general, simulation and enumeration approaches provide a good way of identifying scenarios that may not have been identified otherwise. However, the capability of system- atic simulation to find a large number of scenarios does come at the cost of some necessary reduction in analytical detail. As in the case of strategy-specific approaches, the comparison of scenarios across a system assumes that the impact of each scenario has somehow been normalized with respect to the system as a whole. Again, this is reflected in the perfor- mance measure assessed. Given that hundreds or thousands of scenarios may be potentially important in any networked system, accounting for the unique conditions underlying each scenario may no longer be a viable option.

Mathematical modeling assessment. In vulnerability analysis, the ability to charac- terize a range of disruptive scenarios is important. However, in many cases, the scenario(s) resulting in the greatest potential impact to network operation is of most interest. This is the scenario that planners and policy makers are often interested in when making decisions on where to direct funds for reinforcing or hardening a network to potential threats (Bryson et al. 2002; Gilbert et al. 2003; Qiao et al. 2007; Salmeron, Wood, and Baldick 2004). If the scenario(s) posing the greatest risk to an infrastructure can be identified, then mitiga- ting vulnerability is possible. While scenario simulation can offer insight, mathematical modeling approaches have been specifically devised to answer questions regarding which network components are most vital to infrastructure operation.

Mathematical modeling approaches seek to identify those scenarios with the poten- tial to most affect network operation with respect to the loss or hardening of facilities.

584 GROWTH AND CHANGE, DECEMBER 2008

Establishing bounds on infrastructure vulnerability is paramount in the evaluation of any disruption scenarios. For a network, both simulation and complete enumeration can potentially identify all worst-case scenarios. However, given that billions or more scenarios might exist in networks of modest size, enumeration quickly becomes computationally intractable. Therefore, mathematical modeling approaches have been developed to facili- tate the search for worst-case scenarios. These types of models are premised on well-known mathematical properties that permit extrema (e.g., worst-case or best-case scenarios) to be probably identified without the burden of complete enumeration.

Consider the Ohio interstate highway network in Figure 2 and the scenarios involving the loss of three highway segments and their impact on inter-MSA trucking shown in Figure 3. In this instance, the scenario resulting in worst-case disruption of inter-MSA trucking flows disrupts approximately 22,000 trucks per day, while the least disruptive scenario has no impact on trucking flows. Mathematical programming methods allow such extreme scenarios to be identified without having to completely evaluate all other scenarios, which may not always be possible with alternative methods.

Mathematical modeling approaches are useful in the search for potentially important scenarios, especially since the topologies of infrastructures are often complex and relation- ships between infrastructure facilities and network activity can be difficult to reconcile. In other words, those scenarios with the greatest potential to impact network operation may not always involve the most obvious facilities and are instead related to the functioning of the system as a whole. Further, as with simulation, mathematical modeling approaches have the added capability of being able to identify scenarios that pose the greatest threat to system vulnerability. Hence, while scenario-specific analysis might indicate a high level of impact associated with a particular scenario of local interest, mathematical modeling approaches can place these scenarios within a wider, system-oriented perspective.

Various optimization approaches for assessing network vulnerability have been proposed. For instance, Church, Scaparra, and Middleton (2004) seek to identify the scenarios involving the sets of supply facilities that, if disrupted, would introduce the greatest inefficiency or the greatest reduction in service coverage in an existing system of supply-and-demand locations. Two mathematical programming models, the r-interdiction median and the r-interdiction covering problem are proposed for finding worst-case scenarios. Another example is that of Murray, Matisziw, and Grubesic (2007), who evaluate scenarios of router loss in a telecommunications network. A spatial optimization problem, the flow interdiction model (FIM), is proposed to identify those scenarios of router loss that result in the greatest decrease to system connectivity and flow. In the context of evalua- ting electric grid vulnerabilities, Salmeron, Wood, and Baldick (2004) apply a different mathematical programming model to identify interdiction scenarios that maximize the minimum cost of power generation and unserved demand. While the models mentioned above deal with discrete information/decisions, mathematical programming approaches have also been proposed to account for probabilistic network conditions and disruptive events (see Church and Scaparra 2007a; Cormican, Morton, and Wood 1998). In other related work, researchers have utilized mathematical programming to investigate the

NETWORK VULNERABILITY ANALYSIS 585

possibility of optimally fortifying a network to decrease vulnerability to disruption (see Church and Scaparra 2007b; Qiao et al. 2007).

While the approaches discussed above consider network performance from the perspec- tive of those utilizing the network, vulnerability can also be understood as the outcome of an ongoing strategic game between those using the network and those wishing to disrupt network operations. Using mathematical programming techniques to model the goals and constraints of both network users and disruptors, game theoretic approaches have been devised to study how such competitive relationships impact network vulnerabilities. For instance, Bell (2000, 2003) uses game theory to identify the set of network nodes or arcs that are most likely to be disrupted in such a noncooperative game between a network user and disruptor. In his case, a single worst-case scenario is not identified but rather a set of network components that are likely to be involved in a worst-case scenario(s).

As with the other approaches, there are limitations to mathematical modeling methods. First, networks can be very structurally and operationally complex. Hence, there may be many variables and relationships that need to be accounted for in the mathematical model specification, which can be challenging. Second, a focus on the worst-case scenario(s) may be limiting in some respects in that little indication is provided on the relevance of alternative scenarios, which may not be as damaging, but still create problems for the operational continuity of infrastructure systems. Additionally, limitations often exist on feasible model size and the ability to effectively obtain a model solution. Finally, as with many of the system-wide approaches detailed in this section, certain generalizations on the impacts resulting from disruption (e.g., performance measures) are often necessary for scenario comparisons to be made.

Combining Methodologies For any infrastructure, there are many perspectives on what aspects and conditions

constitute vulnerabilities warranting further attention. Thus, vulnerability assessment necessitates analysis methodologies that can accommodate the range of paradigms (e.g., hard, soft, critical), foci (e.g., structural/physical, operational, environmental, social), and modes of impact measurement of those charged with addressing vulnerabilities in critical infrastructures. Many methodologies do exist in this respect. Scenario-specific, strategy- specific, simulation, and mathematical modeling approaches can be used to address dif- ferent aspects of network vulnerability and each can play an important role in developing a thorough understanding of where vulnerabilities exist and their potential impacts to network operation, socioeconomic systems, or the environment. For instance, the in-depth analysis possible through scenario-specific approaches can provide essential information on the anatomy of a particular disruption scenario. Strategy-specific approaches can be employed to compare network structures based on the susceptibility to different types of disruption strategies. Scenario simulation and evaluation is useful for characterizing the range of possible impacts emanating from disruption and searching for important sce- narios. Mathematical modeling methods are beneficial since they can identify worst-/best- case scenarios with respect to the system as a whole.

586 GROWTH AND CHANGE, DECEMBER 2008

However, in isolation, each of the approaches discussed in the third section have practical limitations in their ability to inform questions pertaining to network vulnerability. Additionally, there are many aspects of network vulnerability for which analysis via a single methodology is not appropriate. Therefore, integration of these methodological approaches is certainly desirable given the wealth of information that they could yield when used in conjunction. In particular, there are several ways in which these four methodologies can be combined to facilitate greater understanding of infrastructure vulnerabilities. First, different methodologies can be used simultaneously within a single paradigm to address a common goal or to provide greater context for identified vulnerabilities. For instance, one goal might be to search for scenarios that represent the greatest vulnerabilities to network connectivity in a situation where mathematical programming is not practical. In such a case, scenarios could be identified interactively (scenario specific), by a particular disruption strategy, and by simulation using the identical measure of disruption impact (e.g., connectivity loss). Second, another rationale for combining methodologies is that vulnerabilities are constantly changing. As a result, the dynamic nature of vulnerabilities can require different analysis methodologies. In such instances, it might be beneficial to supplement or temporarily replace one methodology with another methodology to handle the changing nature of the problem. For example, planners may initially be interested in exploring a system for potentially important scenarios with the aid of scenario simulation. After sources of vulnerability are pinpointed and protected against, continuing vulnerabi- lity analysis efforts might include monitoring of such scenarios via more in-depth study, requiring scenario-specific methods. This additional scenario monitoring might require the assessment of scenario qualities that are more difficult to quantify, thus necessitating techniques from other paradigms to be used. Third, it can be beneficial to combine methodologies in situations where they could complement one another. For instance, a mathematical programming approach might have identified many alternative optima (e.g., worst-case scenarios). Planners might then wish to do more in-depth study of these scenarios to further establish or reject their importance. Similarly, different methodologies can be used to calibrate or train approaches. As an example, a planner might be interested in identifying worst-case scenarios with respect to a measure of scenario disruption that is very difficult to quantify. In such a case, experts may be brought in to interactively identity scenarios fitting the criteria and then algorithms could be trained to look for similar types of scenarios. Another important application in this regard is in reducing/simplifying the search for vulnerabilities. In this case, domain experts might be enlisted to identify scenarios or components of networks that are known to have a very limited effect on network vulnerability. These components could then be removed to expedite the search for vulnerabilities using other methods. However, such ad hoc reductions are known to jeopardize the possibility of probably identifying a worst-case scenario (Matisziw, Murray, and Grubesic 2007). Finally, methods might be combined to juxtapose various perspectives on vulnerability and assess trade-offs between the different interpretations. For example, mathematical programming might be used to identify important scenarios with respect to some measure of network performance. Scenarios important with respect to environmental

NETWORK VULNERABILITY ANALYSIS 587

impact might then be identified through the advice of domain experts. The impact of these environmental scenarios with respect to network performance can then be computed so that trade-offs between environmental consequences and structural consequences can better be understood. Grubesic et al. (2008) provide other examples of this type of analysis.

Mingers and Brocklesby (1997) acknowledge that there are many obstacles in com- bining methodologies in these ways, but such obstacles are not insurmountable and must be negotiated to address the multifaceted nature of complex, real-world problems. Some progress in combining analysis approaches has been made, especially in the area of decision support systems. For instance Snediker, Murray, and Matisziw (2008) propose a spatial decision support system (SDSS) specifically geared toward evaluation of network infrastructures. Their developed SDSS supports analysis across all four approaches dis- cussed in this article and provides an interface for cross-approach/performance measure scenario comparison and assessing the distributional aspects associated with potential scenarios and the facilities involved. Further, their SDSS permits interactive evaluation, visualization, and comparison of scenarios, which are aspects particularly important to establishing scenario likelihood probabilities and better informing the decision-making process in general. Although initial progress in this direction is encouraging, there is still much to be done. For instance, other methodologies have been developed for understanding and prioritizing identified scenarios such as filtering and ranking methods (see Haimes, Kaplan, and Lambert 2002), data envelopment analysis (see Srdjevic, Medeiros, and Porto 2005), as well as multisystem, multiperspective approaches such as Hierarchical Holographic Modeling (see Haimes 1981). Incorporating these options in an SDSS would further assist in moving beyond vulnerability assessment to a more formal risk analysis.

Implications for policy and planning. While multimethodological frameworks are appealing options for evaluating and/or informing public policy, accounting for network vulnerability, both in theory and in practice, is an exceedingly complex task. In part, there is a relatively uneasy relationship between the government and the private sector. Recent estimates indicate that nearly 85 percent of the critical infrastructure is privately held in the U.S. (Ahlers 2004). Needless to say, the federal government is keenly aware of this statistic, yet it is hesitant to add layers of regulation to the private sector in an effort to protect critical infrastructure. While the “Protected Critical Infrastructure Information” program operated by the Department of Homeland Security asks that companies share information on their critical assets, the emphasis on voluntary information sharing and adoption of standards, from a regulatory standpoint, is weak, at best.

This muted federal response leaves much of the burden for identifying network vulner- abilities and securing critical infrastructure to individual system operators, both public and private. Unfortunately, in an era where global economic competition continues to increase and operating budgets continue to decrease, planning survivable systems can be difficult. In many cases, efficiency and survivability are competing objectives. For example, efficient network topologies, such as hub-and-spoke systems, exploit economies of scale for transporting goods, services, and people. Hub-and-spoke systems are also extremely vulnerable to targeted attacks and exhibit relatively poor survivability characteristics

588 GROWTH AND CHANGE, DECEMBER 2008

(Grubesic, O’Kelly, and Murray 2003). Similarly, just as hubs serve as collection and redistribution points for air and telecommunications traffic, Perrow (2007) notes that many “concentrated” industries have a concentrated spatial distribution of facilities. As a result, concentrated spatial interdependencies often represent the most significant problem in the realm of public policy and planning, particularly in the context of vulnerability (Grubesic and Murray 2006). For example, the National Security Telecommunications Advisory Committee (2003) released a report highlighting the potential vulnerabilities that exist when telecommunication assets are concentrated in collocation sites and “telecom hotels.” The loss of these assets, particularly when subject to a targeted attack, has the potential to adversely affect network performance and government and business functions. More importantly, recent research suggests that the impacts of these losses extend well beyond the infrastructure and/or sector hit. Again, one only needs to consider the August 2003 electrical blackout in North America, where a variety of interlinked infrastructures (e.g., telecommunication, water, transportation, and emergency systems) were also impacted.

The multimethodological approach to vulnerability assessment suggested in this article is highly beneficial in addressing such situations. Since critical assets often span multiple geographic scales (e.g., local, regional, national), it is imperative that methods of vulner- ability analysis reflect this diversity and the associated range of implications that can occur. While it is important for managers of critical assets to evaluate the vulnerability of their respective infrastructures to disruption, consideration of a single portion of an infrastruc- ture independent of the larger system can lead to over- or underestimation of a scenario’s significance across various geographic scales. Therefore, it is essential to explore a wide range of scenarios over multiple geographic cases to enhance the understanding of how network components interact and resulting vulnerabilities.

Conclusions Assessing network vulnerability to disruption is a complex task given that for any

network there may be many agencies charged with maintaining and managing different portions of the network, many aspects of its operation of concern, as well as many methods of analysis that can be applied to gain insight on network vulnerabilities. Policy develop- ment relies heavily on insights obtained from vulnerability analysis and thus is susceptible to bias introduced given the analysis methodology selected. Being aware of the sources of bias associated with the various methodological approaches to vulnerability analysis is important to ensure that developed policy is effective and that limited resources to address vulnerability issues are appropriately prioritized.

Scenario identification and assessment is an essential component of any vulnerability analysis. In this article, four general classes of approaches for identifying important scenarios (scenario-specific, strategy-specific, simulation, and mathematical modeling) are discussed. Each of these approaches to scenario identification has its benefits and drawbacks related to the assumptions made and the type of analysis permitted. In particular, each methodology has the potential to overlook potentially important scenarios, which can obviously have negative repercussions in policy development. To minimize the risk of

NETWORK VULNERABILITY ANALYSIS 589

overlooking critical scenarios and enhance the overall level of preparedness for a network disruption, this article suggests that a more complete analysis of network vulnerability should incorporate aspects of each of the approaches in a multimethodological context.

NOTE 1. In addition to the use of inaccurate data for modeling generator loads, the East-Central Reliability

Council had no precise definition of “critical facilities” such as the 345 k-V lines that contributed

to the cascading failure, did not follow appropriate guidelines for conducting long-range regional

and interregional system planning studies and assessments, failed to conduct multiple contingency

or extreme conditions assessments, and failed to incorporate monitoring tools that provided high-

level geographic visualizations of the system and its quickly degrading conditions (NERC 2005).

REFERENCES Ahlers, M. 2004. Federal security program draws few responses. CNN. http://www.cnn.com/2004/

ALLPOLITICS/04/16/infrastructure.security/index.html (accessed September 22, 2008).

Albert, R., I. Albert, and G.L. Nakarado. 2004. Structural vulnerability of the North American power

grid. Physical Review E 69(025103): 1–4.

Albert, R., J. Hawoong, and A.-L. Barabasi. 2000. Error and attack tolerance of complex networks.

Nature 406: 378–382.

Anderson, P.L., and I.K. Geckil. 2003. Northeast blackout likely to reduce US earnings by $6.4 billion.

AEG Working Paper 2003–2002.

Bell, M.G.H. 2000. A game theory approach to measuring the performance reliability of transport

network. Transportation Research Part B 34: 533–545.

———. 2003. The use of game theory to measure the vulnerability of stochastic networks. IEEE

Transactions on Reliability 52(1): 63–68.

Bertalanffy, L. von 1950. An outline of general systems theory. British Journal for the Philosophy

of Science 1(2): 134–165.

Boulding, K.E. 1956. General systems theory—the skeleton of science. Management Science 2:

197–208.

Bryson, K.-M., H. Millar, A. Joseph, and A. Mobolurin. 2002. Using formal MS/OR modeling to

support disaster recovery planning. European Journal of Operational Research 141: 679–688.

Church, R.L., and M.P. Scaparra. 2007a. Analysis of facility systems’ reliability when subject to attack

or a natural disaster. In Critical infrastructure: Reliability and vulnerability, ed. A.T. Murray and

T.H. Grubesic, 221–241. Berlin, Germany: Springer-Verlag.

———. 2007b. Protecting critical assets: the r-interdiction problem with fortification. Geographical

Analysis 39(2): 129–146.

Church, R.L., M.P. Scaparra, and R.S. Middleton. 2004. Identifying critical infrastructure: The median

and covering facility interdiction problems. Annals of the Association of American Geographers

94(3): 491–502.

CNN.com. 2006. Cut cable quiets Sprint service in West. http://www.cnn.com/2006/US/01/09/

sprint.outage/index.html (accessed September 22, 2008).

Cormican, K., D. Morton, and K. Wood. 1998. Stochastic network interdiction. Operations Research

46: 184–197.

590 GROWTH AND CHANGE, DECEMBER 2008

C|net News.com. 2006. Sprint Nextel suffers service outage. http://news.cnet.com/Sprint-Nextel-

suffers-service-outage/2100-1037_3-6024922.html (accessed September 22, 2008).

Davis, T. (Chairman). 2006. A failure of initiative. United States House of Representatives. http://

www.gpoaccess.gov/katrinareport/mainreport.pdf (accessed September 22, 2008).

Doyle, J.C., D.L. Alderson, L. Li, S. Low, M. Roughan, S. Shalunov, R. Tanaka, and W. Willinger.

2005. The “robust yet fragile” nature of the internet. PNAS 102(41): 14497–14502.

Electricity Consumers Resource Council (ELCON). 2004. The economic impacts of the August

2003 blackout. http://www.elcon.org/Documents/EconomicImpactsOfAugust2003Blackout.pdf

(accessed September 22, 2008).

Ellison, R.J., R.C. Linger, T. Longstaff, and N.R. Mead. 1999. Survivable network system analysis:

A case study. IEEE Software July/August: 70–77.

Gilbert, P.H., J. Isenberg, G.B. Baecher, L.T. Papay, L.G. Spielvogel, J.B. Woodard, and E.V. Badolato.

2003. Infrastructure issues for cities—countering terrorism threats. Journal of Infrastructure

Systems 9(1): 44–54.

Grubesic, T.H., T.C. Matisziw, A.T. Murray, and D. Snedicker. 2008. Comparative approaches for

assessing network vulnerability. International Regional Science Review 31(1): 88–112.

Grubesic, T.H., and A.T. Murray. 2005. Geographies of imperfection in telecommunication analysis.

Telecommunications Policy 29(1): 69–94.

———. 2006. Vital nodes, interconnected infrastructures and the geographies of network surviva-

bility. Annals of the Association of American Geographers 96(1): 64–83.

Grubesic, T.H., M.E. O’Kelly, and A.T. Murray. 2003. A geographic perspective on commercial

Internet survivability. Telematics and Informatics 20(1): 51–69.

Haimes, Y. 2006. On the definition of vulnerabilities in measuring risks to infrastructure. Risk Analysis

26(2): 293–296.

Haimes, Y.Y. 1981. Hierarchical holographic modeling. IEEE Transactions on Systems, Man, and

Cybernetics 11(9): 606–617.

Haimes, Y.Y., S. Kaplan, and J.H. Lambert. 2002. Risk filtering, ranking and management framework

using hierarchical holographic modeling. Risk Analysis 22(2): 383–397.

Holme, P., B.J. Kim, C.N. Yoon, and S.K. Hee. 2002. Attack vulnerability of complex networks.

Physical Review E 65(056109): 1–14.

Hood, J.N., T. Olivas, C.B. Slocter, B. Howard, and D.P. Albright. 2003. Vulnerability assessment

through integrated transportation analysis. Transportation Research Record 1822: 18–23.

Houck, D.J., E. Kim, G.P. O’Reilly, D.D. Picklesimer, and H. Uzunalioglu. 2004. A network surviv-

ability model for critical national infrastructures. Bell Labs Technical Journal 8(4): 153–172.

Jackson, M.C. 2006. Creative Holism: A critical systems approach to complex problem situations.

Systems Research and Behavioral Science 23: 647–657.

Jackson, M.C., and P. Keys. 1984. Towards a system of systems methodologies. The Journal of the

Operational Research Society 35(6): 473–486.

Jenelius, E., T. Petersen, and L.-G. Mattsson. 2005. Importance and exposure in road network

vulnerability analysis. Transportation Research Part A 40: 537–560.

Kim, T.J., H. Ham, and D.E. Boyce. 2002. Economic impacts of transportation network changes:

Implementation of a combined transportation network and input–output model. Papers in Regional

Science 81(2): 223–246.

NETWORK VULNERABILITY ANALYSIS 591

Lambert, J.H., and P. Sarda. 2005. Terrorism scenario identification by superposition of infrastructure

networks. Journal of Infrastructure Systems December: 211–220.

Matisziw, T.C., and A.T. Murray. 2009. Modeling s-t path availability to support disaster vulnerability

assessment of network infrastructure. Computers & Operations Research 36(1): 16–26.

Matisziw, T.C., A.T. Murray, and T.H. Grubesic. 2007. Evaluating vulnerability and risk in

interstate highway operation. Proceedings of the Transportation Research Board Annual Meeting.

Washington, DC.

———. Forthcoming. Exploring the vulnerability of network infrastructure to interdiction. The Annals

of Regional Science.

Mingers, J., and J. Brocklesby. 1997. Multimethodology: Towards a framework for mixing

methodologies. Omega 25: 489–509.

Murray, A.T., T.C. Matisziw, and T.H. Grubesic. 2007. Critical network infrastructure analysis:

Interdiction and system flow. Journal of Geographical Systems 9: 103–117.

National Security Telecommunications Advisory Committee. 2003. Vulnerabilities Task Force Report:

Concentration of assets: Telecom hotels. http://www.ncs.gov/nstac/reports/2003/Telecom%

20Hotels.pdf (accessed September 22, 2008).

North American Electric Reliability Council (NERC). 2004. Final report on the August 14, 2003

blackout in the United States and Canada: Causes and recommendations. http://www.nerc.com/

~filez/blackout.html (accessed September 22, 2008).

———. 2005. NERC report to the US-Canada power system outage task force on the status of

the August 2003 blackout recommendations. http://www.nerc.com/~filez/blackout.html (accessed

September 22, 2008).

Perrow, C. 1999. Normal accidents. Princeton, NJ: Princeton University Press.

———. 2007. The next catastrophe. Princeton, NJ: Princeton University Press.

Qiao, J., D. Jeong, M. Lawley, J.-P.P. Richard, D.M. Abraham, and Y. Yih. 2007. Allocating security

resources to a water supply network. IIE Transactions 39: 95–109.

Renesys Corporation. 2004. Impact of 2003 blackouts on Internet communications. http://www.

renesys.com/tech/presentations/pdf/Renesys_BlackoutReport.pdf (accessed September 22, 2008).

Salmeron, J., K. Wood, and R. Baldick. 2004. Analysis of electric grid security under terrorist threat.

IEEE Transactions on Power Systems 19(2): 905–912.

Sillicon Valley Business Journal (SVBJ). 2002. U.S. internet traffic tops 100 petabytes. http://

sanjose.bizjournals.com/sanjose/stories/2002/05/06/daily40.html (accessed September 22, 2008).

Snediker, D., A.T. Murray, and T.C. Matisziw. 2008. Decision support for network disruption

mitigation. Decision Support Systems 44(4): 954–969.

Srdjevic, B., Y.D.P. Medeiros, and R.L.L. Porto. 2005. Data envelopment analysis of reservoir system

performance. Computers and Operations Research 32(12): 3209–3226.

Suarez, P., W. Anderson, V. Mahal, and T.R. Lakshmanan. 2005. Impacts of flooding and climate

change on urban transportation: A systemwide performance assessment of the Boston Metro Area.

Transportation Research Part D 10: 231–244.

U.S. Department of Homeland Security. 2004. Securing our homeland. http://www.dhs.gov/xlibrary/

assets/DHS_StratPlan_FINAL_spread.pdf (accessed September 22, 2008).

U.S. Department of Transportation (USDOT). 2006. Freight in America. http://www.bts.

dot.gov/publications/freight_in_america/ (accessed September 22, 2008).

592 GROWTH AND CHANGE, DECEMBER 2008