Week 4 - Critical Infrastructure
Critical Infrastructure Protection in Homeland Security: Defending a Networked Nation, Second Edition. Ted G. Lewis. © 2015 John Wiley & Sons, Inc. Published 2015 by John Wiley & Sons, Inc.
195
Water and Water treatment
11
PPD-21 defines the security goal of the water and waste- water treatment sector as “… a secure and resilient drinking water and wastewater infrastructure that provides clean and safe water as an integral part of daily life, ensuring the economic vitality of and public confidence in the Nation’s drinking water and wastewater service through a layered defense of effective preparedness and security practices in the sector.” Note that the emphasis is on drinking water, which is approximately 15% of the country’s water supply chain. Agricultural and industrial water is excluded from this sector. Also note that water, in the form of hydroelectric power, is also connected to other CIKR sectors such as power and transportation.
This chapter traces the evolution of water as a valuable resource protected by legislation and regulation, to a critical infrastructure that supplies drinking water to 300 million Americans and is indirectly linked to food production (food/ agriculture infrastructure) as well as industrial production capacity. It then analyzes one of the nation’s largest water systems—the Hetch Hetchy network that supplies water to the San Francisco Bay Area. This case study once again illustrates risk assessment and shows how to optimally allo- cate water supply improvement funds for the protection and response to this CIKR’s hazards.
In addition, this chapter traces water supply legislation and shows how it has evolved from a public health issue (biological contamination of drinking water) to an environ- mental protection issue (chemical and radiological contami- nation) and finally to a terrorism and CIKR issue. The main contemporary concern is that terrorists might disrupt the supply of drinking water with a denial-of-service (DoS)
attack, biological contamination attack, or bombing. Additionally, environmental conditions may reduce the availability of water to the millions of people who depend on it by flooding power and treatment plants or destroying infrastructure through an earthquake. To illustrate these potential threats and propose strategies for protection and response, the San Francisco water system is analyzed against biological–treatment plant, earthquake–pipeline, and super- visory control and data acquisition (SCADA)–treatment plant threat–asset pairs using hypothetical data.
Finally, this chapter compares the RAMCAPTM frame- work recommended by the American Society of Mechanical Engineers (ASME) with fault tree analysis.1 The Department of Homeland Security (DHS) recommends RAMCAP be used for risk analysis of the water CIKR. Both RAMCAP and fault tree analysis use the familiar TVC formula for risk, but model-based risk analysis (MBRA) fault trees may be used for resource allocation. RAMCAP is an alternative risk assessment to MBRA’s network and fault tree analysis tools.
The following major topics and concepts are described in detail:
• Purity versus terrorism: Public health legislation at the turn of the twentieth century was focused on water purity and the prevention of disease. The U.S. Public Health Service (U.S. PHS) was responsible for protecting
1ASME Innovative Technologies Institute, LLC 1828 L Street, NW, Suite 906, Washington, DC, 20036 [email protected] (202) 785-7388, www. asme-iti.org
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
196 WATER AND WATER TREATMENT
drinking water in communities across the country. Today, the U.S. EPA has responsibility for protecting the water supply system from biological, chemical, and radiological contamination as well as countering DoS attacks perpetrated by terrorists.
• Drinking versus agricultural and industrial uses of water: By far, the preponderance of legislation and regulation of water has been aimed at drinking water, and yet over 80% of the water supply is used for agri- cultural and industrial applications. Intelligent life on this planet depends on water, but so does civilized food production and industrial economy.
• Safe Drinking Water Act (SDWA) of 1974: The SDWA of 1974 is the foundation upon which modern water regulation is based. It also transferred responsibility from the U.S. Public Health Department to the U.S. Environmental Protection Agency (U.S. EPA). The SDWA has been modified many times since 1974, but it still stands as the foundation for contemporary water safety.
• Bioterrorism Act of 2002: Title IV of the Public Health Security and Bioterrorism Preparedness Response Act extended the SDWA of 1974 to include a new threat: terrorism. It also directs water communities to perform vulnerability analysis for a new failure mode—DoS (cutting off the supply of water entirely).
• Case study: The massive and vital Hetch Hetchy water and power supply network of the San Francisco Bay Area is shown to be extremely critical due to the inter- dependencies among water, power, San Francisco International Airport, Silicon Valley computer industry, and surrounding metropolitan communities that depend on the Hetch Hetchy water supply. While its spectral radius is relatively low, its betweenness centrality is relatively high. Thus, it is resilient against cascade fail- ures but fragile against flow disruptions. Flow fractal dimension is less than 1 (0.76), suggesting vulnera- bility to DoS attacks on high-betweenness assets. Critical assets are the major pipelines, treatment plants, power plants, and large reservoirs.
• MBRA: MBRA uses hypothetical data to show how best to allocate risk reduction funds by protecting reser- voirs, treatment plants, pipes, and powerhouses against bombings, earthquakes, power outages, corrosion, and chem–bio attacks. The most critical assets in the San Francisco water system lie along a critical path defined by high betweenness. The most critical threat–asset pairs are shown to be high-consequence pairs threat- ened by earthquakes. Yet, sector vulnerability remains high because of flow fragility—pipelines are bottle- necks and lack redundancy.
• Interdependence: In many large municipal water supply systems, interdependencies exist among water,
agriculture, transportation (airports), and power gener- ation. This multiplies the criticality of water systems as one of the primary critical infrastructures. It is myopic to restrict our thinking to drinking water. In fact, other sectors depend heavily on nondrinking as well as drinking water. The water sector may have evolved out of public health concerns, but today, it is an essential component of economic well-being.
• Risk methods: RAMCAP is the recommended risk assessment tool for the water sector. It is based on the PRA equation—R = TVC—and uses a risk ranking strategy to allocate resources. In comparison, MBRA extends R = TVC by including fault tree logic and optimal resource allocation that minimizes risk. MBRA analysis of Hetch Hetchy (using hypothetical data) minimizes risk by allocating most funding toward earthquake retrofitting assets along the critical path defined by the highest-betweenness nodes and links of the Hetch Hetchy water and power network.
11.1 From Germs to terrorists
Prior to the development of the germ theory by Louis Pasteur in the 1880s, water was simply a resource to be exploited for powering water wheels and quenching the thirst of humans, animals, and crops. But soon after Pasteur developed his theory, water became a recognized vector for the trans- mission of diseases. Dr. John Snow showed how cholera was transmitted from wells to homes via water in 1885 [1]. And by 1914, the U.S. PHS began setting standards for the bacteriological purity of drinking water. But these stan- dards had to be promulgated by water utilities that served rather sizeable communities. Utilities maximized profit— sometimes at the expense of water purity—and small utilities were not closely monitored. As a consequence, it took the country decades to “purify” the drinking water consumed in the United States.
As more and more unhealthy substances were shown to exist in drinking water, they were added to the list of sub- stances regulated by the maximum contaminant level (MCL) standard. Bacteriological standards were revised in 1925, 1946, and again 1962. In 1960, a U.S. PHS study showed that only 60% of drinking water met PHS purity standards. Consequently, a 1962 revision increased the number of substances falling within the regulations to 28 substances— the most rigorous standards until 1974. Table 11.1 lists these substances.
A 1972 U.S. PHS study of the Mississippi River found 36 chemical contaminants remaining in drinking water after treatment plants had processed it. The treatment plants were not filtering out these hazardous chemicals, pollution, pesti- cides, and other chemical and radiological contaminants. Biological contamination was but one of many contaminants
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
FRoM GERMS To TERRoRISTS 197
in the Mississippi River water supply. Chemicals had become a bigger problem. The 1972 study underscored the impor- tance of filtering out nonbiological contamination and led to the creation of the modern foundation of water legislation— the SDWA of 1974.
11.1.1 SDWA
The SDWA establishes the foundation of modern regulations for protecting the purity of water and water systems. Because the list of contaminants had grown to include chemicals and other hazardous materials, the responsibility for protecting drinking water and associated processing systems was trans- ferred to the U.S. EPA. This foundational act was revised in 1986, and again in 1996 and 2002, but it remains the bedrock of water legislation.
The concept of water as a critical resource expanded once again as acts of terrorism multiplied during the 1990s. on May 22, 1998, President Clinton signed Presidential Decision Directive 63 (PDD-63), which identified, among other sectors, drinking water as one of America’s critical infrastructures. People cannot survive longer without food than without water. Terrorists merely need to deny water ser- vice for a few days or week to cause major disruptions in the health, environment, and commerce of the country.
By 2002, water “purity” legislation had evolved from biological to environmental and then to DoS “contamination.” PDD-63 identified the issue, but the Bioterrorism Act added terrorism to the list of contaminants. The Public Health Security and Bioterrorism and Response Act of 2002 was signed into law by President George W. Bush on June 12, 2002. It was the most significant event affecting water secu- rity since the SDWA of 1974. Title IV of this act addresses the water sector and provides a number of penalties for perpetrators of attacks on water systems.
Shortly after the Bioterrorism Act of 2002 was signed, the U.S. EPA completed the first classified Baseline Threat Report describing likely modes of terrorist attack and out- lining the parameters for vulnerability assessments by community water systems. This report remains classified. one can only speculate that the threats identified by the U.S. EPA report are similar to the ones identified in the case study described later in this chapter.
11.1.2 the Water information sharing and analysis Center
In December 2002, the U.S. EPA provided funds to the American Water Works Association (AWWA)—a professional society for water system professionals—to form the Water Information Sharing and Analysis Center (WaterISAC) as prescribed by the National Strategy for Critical Infrastructure Protection. The WaterISAC is a consortium of professional associations and vendors focused on the promotion of water- works safety and security. It brings together the private and public sector to implement the strategies of the SDWA and its descendants. It also provides training and education to its members in subjects such as vulnerability analysis and risk assessment.
The WaterISAC Board of Managers is comprised of water utility managers appointed by the national drinking water and wastewater organizations in the following. There are also two at-large seats, filled by the Board of Managers. Typical members are:
AWWA
Association of Metropolitan Sewerage Agencies
Association of Metropolitan Water Agencies
AWWA Research Foundation
National Association of Water Companies
National Rural Water Association
Water Environment Federation
Water Environment Research Foundation
The WaterISAC is a bridge between the public and private sectors operating within the water sector. It has established the following goals and provides the following products for its members:
table 11.1 these contaminants are regulated per the 1962 Public Health service standards
Alkylbenzene sulfonate (ABS) Arsenic Barium Beta and photon emitters Cadmium Carbon chloroform extract (CCE) Chloride Chromium Color Copper Cyanide Fluoride Gross alpha emitters Iron Lead Manganese Nitrate Phenols Radium-226 Selenium Silver Strontium-90 Sulfate Threshold odor number Total coliform Total dissolved solids Turbidity Zinc
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
198 WATER AND WATER TREATMENT
• Alerts on potential terrorist activity.
• Aggregation of information on water security from fed- eral homeland security, intelligence, law enforcement, public health, and environment agencies.
• Maintain databases of chemical, biological, and radio- logical (CBR) agents.
• Identify physical vulnerabilities and security solutions.
• Provide its members with notification of cyber vulner- abilities and technical fixes.
• Perform research and publish reports and other information.
• Provide a secure means for reporting security incidents.
• Recommend/provide vulnerability assessment tools and resources.
• Provide emergency preparedness and response resources.
• Provide secure electronic bulletin boards and chat rooms on security topics.
• Summarize open-source security information.
11.2 Foundations: sdWa oF 1974
The SDWA of 1974 assigns responsibility for water safety to the U.S. EPA. But the focus prior to 1974 was on biological purity. After 1974, the focus expanded to CBR purity. The shift from biological contamination to environmental pol- lutants signaled a phase shift in public policy regarding water. one more shift in policy direction occurred in 2002 when bioterrorism was added to the SDWA foundation.
Minor modifications in 1996 broadened the scope of responsibility of the U.S. EPA (see Table 11.2). The EPA now has responsibility for entire water supply systems—not just drinking water coming from household taps, but also the U.S. EPA is responsible for protecting the entire system including water from rivers, lakes, pipes, and treatment plants. This includes protection against physical, biological, chemical, radiological, and cyber threats. However, there are some exceptions to this policy.
The regulatory power of the U.S. EPA does not extend to all water systems. The regulation distinguishes community water supply systems from private drinking water systems
table 11.2 the 1996 sdWa amendments require u.s. ePa to enforce the following:
Consumer confidence reports All community water systems must prepare and distribute an annual report about the water they provide,
including information on detected contaminants, possible health effects, and the water’s source Cost–benefit analysis The U.S. EPA must conduct a thorough cost–benefit analysis for every new standard to determine whether
the benefits of a drinking water standard justify the costs drinking water state revolving fund States can use this fund to help water systems make infrastructure or management improvements or to help
systems assess and protect their source water microbial contaminants and disinfection by-products The U.S. EPA is required to strengthen protection for microbial contaminants, including Cryptosporidium,
while strengthening control over the by-products of chemical disinfection. Two new drinking water rules in November 1998 addressed these issues; others will follow
operator certification Water system operators must be certified to ensure that systems are operated safely. The U.S. EPA issued
guidelines in February 1999 specifying minimum standards for the certification and recertification of the operators of community and nontransient, noncommunity water systems
Public information and consultation SDWA emphasizes that consumers have a right to know what is in their drinking water, where it comes from,
how it is treated, and how to help protect it. The U.S. EPA distributes public information materials (through its Safe Drinking Water Hotline, Safe Water Website, and Water Resource Center) and holds public meetings, working with states, tribes, water systems, and environmental and civic groups, to encourage public involvement
small water systems Small water systems are given special consideration and resources under SDWA to make sure they have
the managerial, financial, and technical ability to comply with drinking water standards source water assessment programs Every state must conduct an assessment of its sources of drinking water (rivers, lakes, reservoirs, springs,
and groundwater wells) to identify significant potential sources of contamination and to determine how susceptible the sources are to these threats
Understanding the Safe Drinking Water Act, December 1999, EPA 810-F-99-008. U.S. EPA’s office of Ground Water and Drinking Water website: http://www.epa.gov/safewater/
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
THE BIoTERRoRISM ACT oF 2002 199
and other systems such as agricultural and industrial water. For example, it does not regulate private wells serving 25 or fewer consumers. Public or community water systems must serve at least 3300 consumers to fall within the EPA’s jurisdiction. In addition, the stringency of the law increases as the size of the water supply system increases.
The U.S. EPA does not assume full responsibility for enforcing the SDWA. Instead, its strategy is to partner with states, tribes, and private utilities. It aims to regulate and fund local enforcement of the National Primary Drinking Water Regulations, which define enforceable MCL for particular contaminants in drinking water. It specifies that certain proven methods of decontamination be used to treat water to remove contaminants. It also sets standards for drinking water communities according to the number of people served by the system.
11.3 tHe bioterrorism aCt oF 2002
Title IV of the Bioterrorism Act of 2002 extends the SDWA to cover terrorism and modern asymmetric threats such as SCADA attacks and insider attacks from employees of water treatment plants.2 Water SCADA includes the computer and digital network infrastructure that supports the surveillance and operation of water, power, and energy sectors.
The 2002 act recommends hardening of targets by adding intruder detection equipment; installing fences, gating, lighting, locks, and tamper-proof hydrants; and making improvements to industrial control systems (ICS)–SCADA hardware and software. It provides funds for training in oper- ations and the handling of chemicals. It requires that water- works employees and contractors submit to security screening and provides penalties for breach of confidentiality.
Some highlights of the act are as follows:
• Provides up to $160M in FY02 and “such sums as may be necessary” in FY03–FY05 to (1) perform physical and SCADA vulnerability analysis of all systems with 3300 or more consumers according to the following timetable:
March 2003 for communities of 100,000 or more
December 2003 for communities of 50,000–100,000
June 2004 for communities of 3,300–50,000 consumers
• Restricts who has access to vulnerability assessment information and specifies penalties of up to 1 year in prison for anyone who “recklessly reveals such assess- ments.” The results of RAMCAP risk assessments on water systems are confidential.
• Grants up to $5M for small communities (<3300 consumers).
• Requires all communities to develop an Emergency Response Plan to “obviate or significantly lessen impact of terrorist attacks.”
• Provides up to $15M in FY02 and “such sums as may be necessary” in FY03–FY05 to:
Work with the Center for Disease Control (CDC) to “prevent, detect, and respond” to CBRN con- tamination of water.
Review methods by which terrorists can disrupt supply or safety.
Review means of providing alternative supply in event of disruption.
Create a WaterISAC.
• Amends SDWA to extend wording about water safety to include wording about disruption of services by terrorists.
11.3.1 is Water for drinking?
After a century of focusing on biological, then environmental, and now terrorist threats to the water supply, the U.S. EPA is working with states, tribes, drinking water and wastewater utilities (water utilities), and other partners to enhance the security of water, waterworks, sources of water, and waste- water utilities. It has set the following objectives for itself:
1. EPA will work with the states, tribes, drinking water and wastewater utilities (water utilities), and other partners to enhance the security of water and waste- water utilities.
2. EPA will work with the states, tribes, and other partners to enhance security in the chemical and oil industry.
3. EPA will work with other Federal agencies, the building industry, and other partners to help reduce the vulnera- bility of indoor environments in buildings to chemical, biological, and radiological (CBR) incidents.
4. EPA will help to ensure that critical environmental threat monitoring information and technologies are available to the private sector, Federal counterparts, and state and local government to assist in threat detection.
5. EPA will be an active participant in national security and homeland security efforts pertaining to food, transportation, and energy.
6. EPA will manage its Federal, civil, and criminal enforcement programs to meet our homeland security, counter-terrorism, and anti-terrorism responsibilities under Presidential Decision Directives (PDD) 39, 62, and 63 and environmental civil and criminal statutes.
But the national strategy as implemented by the U.S. EPA addresses only a portion of the problem. In California, for example, 80% of the water managed via supply systems, 2http://www.fda.gov/oc/bioterrorism/PL107-188.html#title4
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
200 WATER AND WATER TREATMENT
treatment plants, aqueducts, and regulated utilities goes to agriculture, not drinking water. And this does not address the needs of industry. Water is needed to process silicon into computer chips in the $370 billion semiconductor industry. Without water, Silicon Valley would shrivel up as quickly as the Central Valley (major agricultural area of California). In addition, major hydroelectric power plants depend on the abundance of water to generate power for the San Francisco International Airport, for example. The famous Hetch Hetchy water supply system in Northern California provides water and power to 2.4 million inhabitants in the San Francisco Bay Area, but it also powers the San Francisco International Airport as well as itself. Without water, there is no power, and without power, there is no water.
Thus, the question is, “should the water sector be extended beyond drinking water?” Agricultural and industrial uses of water have become as important to national security as drinking water, so why not incorporate these interdependencies? These questions suggest that the concept of DoS—as applied to all water supply systems—is a major vulnerability to public health, agriculture, and the industrial base. Water directly affects at least three of the critical infrastructures defined in the national strategy and indirectly affects the other sectors.
The following case study illustrates the interdependency of water with the economy and livability of the San Francisco Bay Area. It underscores the vulnerability of a water supply that quenches the thirst of a major metropolitan area—one that serves the famous Silicon Valley, perhaps America’s most powerful generator of economic power, and is a “cousin” to the California Aqueduct system that supports one of the largest and most productive agricultural regions of the United States.
11.4 tHe arCHiteCture oF Water systems
Community water systems serve 3300 or more consumers. They are typically vertically integrated monopolies that own and operate all aspects of the water supply for a community (see Fig. 11.1). For example, the City and County of San Francisco owns and operates the San Francisco Public Utilities Commission (SFPUC) that provides water, waste- water, and electric power services to San Francisco and surrounding cities such as Alameda, San Mateo, and Santa Clara; Muni (public transportation); and San Francisco International Airport.
The SFPUC manages the collection of water from rivers and lakes; treatment facilities such as the Tracy and Sunol treatment plants studied in the previous chapter; storage in the form of temples and reservoirs; and distribution through a network of tunnels and pipelines. It owns and operates utility trucks and fire apparatus to protect its watershed located in the Hetch Hetchy region near Yellowstone Park in the Sierra Mountains—175 miles east of the Bay Area—and
is responsible for treating wastewater before discharging it into the San Francisco Bay and the Pacific ocean.3
In 1997, the city of Seattle Washington established Seattle Public Utilities (SPU) to provide water, sewer, drainage, and garbage services for 1.3 million people in King County, Washington. Similarly, District of Columbia Water and Sewer Authority (DC WASA) owns and operates the Washington, DC, water system including supplying drinking water, wastewater treatment, and fire hydrants since 1996, and the New York City Municipal Water Finance Authority is a public benefit corporation established by the New York City Municipal Water Finance Authority Act of 1984.
These vertical monopolies typically manage all levels shown in Figure 11.1:
• Collection of runoff from rivers and lakes in watershed territories such as the Hetch Hetchy lake area.
• Treatment of water prior to distribution to consumers such as the Sunol Treatment Facility.
• Storage of water in reservoirs or storage temples such as the 4-day supply held in storage tanks called temples around the city of San Francisco as well as reservoirs outside of the city.
• Distribution of water through pipes, tunnels, and rivers such as the Crystal Springs Tunnel south of San Francisco.
• Monitoring and control of the entire system is handled by an ICS–SCADA network as described in the previous chapter.
• Legislation provides the monopoly’s authority as well as the chemical, biological, and counterterrorism regulation as dictated by the federal government.
11.4.1 the law of the river
Not all water systems are regulated at the local level. For example, the Colorado River supplies water to 27 million con- sumers in 7 states and 2 countries. Under a contentious and complicated set of agreements going back to a 1922 ruling, the Colorado River water is shared according to compacts, federal laws, court decisions and decrees, contracts, and regulatory guidelines collectively known as “The Law of the River.”4 Upper Basin states (Colorado, New Mexico, Utah, and Wyoming) and Lower Basin states (Arizona, California, and Nevada) are allocated different amounts of water. Mexico was added in 1944. Various sovereign nations like the Navajo have sued the federal government since 1999, arguing that tribal rights have been ignored. Changes to the apportioned amounts have been proposed as recently as 2008 as part of the Presidential Election campaign. The Law of the River is likely to change again as water becomes more valuable.
3https://en.wikipedia.org/wiki/Sfpuc
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
THE HETCH HETCHY NETWoRK 201
11.5 tHe HetCH HetCHy netWork
San Francisco is well acquainted with disaster. The 8.3 magni- tude earthquake and subsequent fires of 1906 are reminders to the city that disaster is always just around the corner. In more modern times, the city suffered heavy damage in the 1989 Loma Prieta earthquake. These natural disasters have forced San Francisco to constantly hone the skills of its firefighters and emergency response personnel to deal with the unexpected:
At 5:04 P.M., Tuesday, october 17, 1989, as over 62,000 fans filled Candlestick Park for the third game of the World Series and the San Francisco Bay Area commute moved into its heaviest flow, a Richter magnitude 7.1 earthquake struck. It was an emergency planner’s worst-case scenario. The 20-sec- ond earthquake was centered about 60 miles south of San Francisco, and was felt as far away as San Diego and western Nevada. Scientists had predicted an earthquake would hit on this section of the San Andreas Fault and considered it one of the Bay Area’s most dangerous stretches of the fault.
over 62 people died, a remarkably low number given the [rush hour] time and size of the earthquake. Most casualties were caused by the collapse of the Cypress Street section. At least 3,700 people were reported injured and over 12,000 were displaced. over 18,000 homes were damaged and 963 were destroyed. over 2,500 other buildings were damaged and 147 were destroyed.
Damage and business interruption estimates reached as high as $10 billion, with direct damage estimated at $6.8 billion. $2 billion of that amount is for San Francisco alone and Santa Cruz officials estimated that damage to that county will top $1 billion.5
The water supply, however, was minimally impacted by the 1989 disaster. City workers sampled the quality of the water the next day and noted many breaks in lines, but no major disruptions in the availability of drinking water. The eight hills throughout the city lost power, and firefighters were forced to pump water from the bay to put out fires, but the city’s 4-day supply of water remained intact.
The greatest damage to the water system consisted of approx- imately 150 main breaks and service line leaks. of the 102 main breaks, over 90 percent were in the Marina, Islais Creek and South of Market infirm areas. The significant loss of service occurred in the Marina area, where 67 main breaks and numerous service line leaks caused loss of pressure.6
The damage was minor when considering the size and com- plexity of the city’s water system. Twelve gatemen run the whole system. “The system” contains over 1,300 miles of pipeline connecting 8,000 hydrants and 45,000 valves. It delivers 80 million gallons/day to 770,000 city dwellers. The SFPUC, which bills to 160,000 m, sells the surplus to another 1.6 million suburban users around the Bay Area.7
The major lesson learned from 1989 water supply damage was to buy more backup power systems. The earthquake tested the plumbing and purity of the water, not its avail- ability. San Francisco was lucky because water kept flowing into the city from 175 miles away. The Hetch Hetchy valley and reservoir located in the Yosemite National Park supplies most of the city’s water. What happens if this huge water resource dries up? This is the case of Hetch Hetchy, which experienced minor disruptions in 1997 and 2002.
SCADA network
Distribution network
Storage facility
Treatment facility
Collection source
Regulation
FiGure 11.1 Typical community water systems are vertically integrated natural monopolies as shown here.
4https://en.wikipedia.org/wiki/Colorado_River_Compact
5The october 17, 1989, Loma Prieta earthquake, http://www.sfmuseum.net/ alm/quakes3.html#1989 6Memorandum to Tom Elzey, PUC General Manager from Art Jensen, Acting General Manager, November 21, 1989. Museum of the City of San Francisco. 7http://Sfwater.org
table 11.3 input data for the top five assets in the mbra network model of Hetch Hetchy ranked according to consequences shows large differences in elimination costs
Name Threat
(%) Vulnerability
(%) Consequence $ (millions)
Prevention cost $ (millions)
Response cost $ (millions)
Risk initial $ (millions)
Risk reduced $ (millions)
Sunol Water Treatment 50.00 100.00 1000.00 20.00 100.00 500.00 9.90 Kirkwood Powerhouse 50.00 100.00 1500.00 10.00 25.00 750.00 12.96 Holm Powerhouse 50.00 100.00 1500.00 5.00 1.00 750.00 7.42 New Don Pedro Reservoir 50.00 100.00 1000.00 1000.00 10.00 500.00 5.00 Tracy Water Treatment 50.00 100.00 1000.00 25.00 25.00 500.00 9.81
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
202 WATER AND WATER TREATMENT
11.5.1 betweenness analysis
San Francisco maintains six municipal wells and 980 acres of lakes and land, but the bulk (65% or more) of its water comes from the pure lakes, reservoirs, and streams of the Hetch Hetchy. Hetch Hetchy is a network of 14 reservoirs, 22 pump- ing stations, several tunnels, and a number of treatment plants, filtration plants, and storage temples. This system delivers 400 million gallons of drinking water per day to 2.4 million customers. It is so big and complex that the first step is to identify the major components of the Hetch Hetchy network.
Figure 11.2 shows the expansive Hetch Hetchy network on top of a map of Northern California. This network con- sists of lakes, reservoirs, rivers, storage temples, treatment facilities, tunnels, and pipes needed to deliver water from mountain lakes to city dwellers.
Node and link robustness of 57 and 12%, respectively, suggests vulnerability due to an inadequate number of (redundant) links. Analysis should focus on this inadequacy. Because we are interested in the flow of water through these critical links, the nodes and links in Figure 11.2 are ranked by MBRA according to betweenness—the number of paths through each node/link. (The maximum number of paths turns out to be 402.)
Note there are two main links running horizontally across the Central Valley—the upper link is Hetch Hetchy’s power
transmission line, and the lower link is the pipeline and tunnel distribution link delivering water. Power is generated by several hydroelectric dams and then delivered to the Bay Area by a transmission line. Water is delivered through a pipeline system consisting of three pipes along some stretches on the way across the Central Valley.
The highest-ranking betweenness values lie along the water pipeline passing through the Sunol Treatment Facility (#1), continuing through the pipeline links around the southern end of the Bay, and then running North to San Francisco, via Silicon Valley. This series of high-betweenness pipes and nodes forms a critical path from source to destination.
The spectral radius of this network is 2.63 and its critical point is γ
0 = 24.9%:
log . .
.
. . .
q( ) = −
∴ = −
− ( ) =
0 19 0 29
0 19
0 29 2 63 0 2490
γρ
γ
This is a resilient network from the point of view of cascade failure. Individual component failure would have to exceed 24.9% to cause a complex catastrophe. However, flow simu- lation of this network shows that it is subject to high-risk failures because the fractal dimension for flow exceedence
FiGure 11.2 The Hetch Hetchy water and power supply network starts in the Hetch Hetchy region of Northern California and stretches 175 across California to the San Francisco Bay Area.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
CASCADE ANALYSIS 203
probability is 0.76—hence, the network is high risk. Flow simulation ignores Braess’s paradox, but since there is essen- tially one link between source water collection in the Hetch Hetchy region and distribution to consumers in the Bay Area, Braess’s paradox is not a factor in flow simulation. Vulnerability stems mainly from relatively low link robustness.
Furthermore, the low fractal dimension of flow exceedence (0.76) and low-risk robustness of 12% suggests high flow risk. Accidental or human-caused hazards any- where along this critical path will have major consequences. According to the betweenness centrality metric, the most critical nodes and links from Figure 11.2 are:
1. Sunol Treatment Facility
2. Bay Division Junction
3. Junctions 2 and 3
4. Coast Range Tunnel
5. Pipes 1–2–3–4
6. San Joaquin Pipeline
7. New Don Pedro Reservoir
8. Palo Alto
9. Tuolumne River
10. Foothill Tunnel
All of these assets lie along the critical transmission path from the collection source to the destination in San Francisco. Failure in any one of these nodes/links disrupts the flow of water. Note that the power transmission lines do not lie on this critical path even though a power outage would stop pumps and travel into and out of the San Francisco International Airport. Betweenness analysis has its limitations.
In fact, this network has a history of breakage. In November 2002, a leak in the critical path connecting Hetch Hetchy with the Bay Area treatment and distribution net- work cut the water supply to San Francisco in half. 210–240 million gallons/day stopped flowing to the Bay Area but for only a few days. Fortunately, there is a 4-day supply of water “in the system,” which buffered the effects of this accident.
11.6 CasCade analysis
The impact of a pipeline fault is likely to propagate down- stream in the form of DoS—water ceases to flow. Therefore, downstream cascade simulation can be used to estimate the downstream impact of a pipeline fault by assuming down- stream assets fail because of upstream failures. Assuming a PRA risk model—with TV equal to the probability of a subsequent failure downstream and C as the corresponding consequence—the simulation produces an exceedence distributions as shown in Figure 11.3.
Clearly, an investment in prevention reduces the long tail of the exceedence distribution—fractal dimension decreases to 1.8 from approximately 2.0. Moreover, the probability of consequences in excess of 4% of the total consequences (if all nodes and links failed) drops from 32 to 3%. Regardless, flow risk remains high, because the exceedence distribution of water disruption has a fractal dimension of 0.76. Cascade analysis is not adequate to account for all risk to the SFPUC system.
11.6.1 multidimensional analysis
Betweenness centrality identifies bottlenecks in the flow of water through the system. Degree centrality identifies superspreaders that magnify the spread of cascade failures. A combination of the two may provide a better model of self-organization in the SFPUC water supply. Combining betweenness and degree centrality produces a ranking of nodes and links as follows:
1. Sunol Treatment Facility
2. Junctions 1 and 2
3. New Don Pedro Reservoir
4. Palo Alto
5. Bay Division Junction
6. Holm Powerhouse
7. Kirkwood Powerhouse
8. San Joaquin Pipeline
9. HH Power Junction
10. Pulgas Temple
Alternatively, an upstream disruption of flow will have a downstream impact so it may make sense to rank nodes and links according to betweenness and height (distance from the source). This metric yields a slightly different list:
1. Sunol Treatment Facility
2. New Don Pedro Reservoir
100%
73 79 72
3
60
32 23
12 9
% Consequence
4 2 2 10987654321
% Consequence
Exceedence probability %Exceedence probability %
4321 75%
50%
25%
100%
75%
50%
25%
FiGure 11.3 Simulation of downstream cascades caused by a random failure of a node or link in Figure 11.2 shows improvement after an investment in prevention (vulnerability reduction). Left, before prevention; right, after vulnerability reduction.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
204 WATER AND WATER TREATMENT
3. San Joaquin Pipeline
4. Foothill Tunnel
5. Bay Division Junction
6. Coast Range Tunnel
7. Holm Powerhouse
8. Kirkwood Powerhouse
9. Tuolumne River
10. Pipes 1–2–3–4
11.6.2 blocking nodes
Blocking nodes are the nodes that hold the CIKR network together. Removal of blocking nodes eliminates cascades, but it also eliminates continuity of flow. So in this case, blocking nodes are the minimum number of nodes required to keep the water and electricity flowing. Therefore, the blocking nodes of the SFPUC water and power network are highly critical.
Theory predicts 1/2.63 = 38% of the nodes are blocking nodes, but simulation identifies 43%, or 12 nodes, as blocking nodes. Furthermore, applying the algorithm for finding blocking nodes in the SFPUC water network yields the following critical nodes, in alphabetical order:
1. Cherry Tunnel
2. Coast Range Tunnel
3. Crystal Springs Tunnel
4. Don Pedro Reservoir
5. Foothill Tunnel
6. Holm Power
7. Lake Lloyd Reservoir
8. Junction 1
9. Junction 2
10. Power Substation*
11. San Andreas Reservoir
12. Sunol Valley Treatment
Limited resources may prohibit hardening of all of these nodes, but doing so would prevent cascade failures to both the water flow and power flow. The blocking node algorithm does not distinguish between pipelines and power lines, so the set of blocking nodes for water only excludes the power station node (indicated in the list earlier by*).
11.7 HetCH HetCHy investment strateGies
In November 2002, San Francisco voters approved legisla- tion to finance the largest renovation in the history of their water delivery system. The $3.6 billion capital program funded 77 projects to repair, replace, and seismically upgrade
the water system’s aging pipelines, tunnels, reservoirs, and dams. Did they spend the money wisely? Flow analysis points to high risk, while cascade analysis suggests low risk. Should the SFPUC invest more in prevention or response? Does the threat of terrorist attack change the strategy? These questions are addressed by running a number of scenarios in MBRA:
• Risk reduction through prevention
• Risk reduction through response
• Risk and the rational attacker
The following results were obtained using hypothetical data. This analysis is educational, only, and should not be con- strued as accurate or appropriate results for Hetch Hetchy. Some of the values were exaggerated to make an educational point.
Figure 11.4 summarizes the results of an MBRA net- work analysis versus investment in each of the scenarios earlier. Prevention is defined as retrofitting infrastructure against hazardous earthquakes and storms, adding fencing and CCTV cameras, and preventing ICS–SCADA exploits. Protection attempts to anticipate hazards before they hap- pen and harden assets against potential damages. MBRA models the benefit of prevention by reducing vulnerability. (Remember, risk is TVC.)
Figure 11.4 shows how risk declines as the prevention budget increases up to $1000 million. Risk declines versus investment because vulnerability declines. (Initially, all vul- nerabilities are set to 100%.) At about $100 million, the curve flattens out, suggesting a rapid diminishing return on preven- tion investment. Prevention is less effective than response because of high prevention costs relative to consequences in the network model.
Investments in response typically involve investments in equipment and new technology to more rapidly respond to floods, fires, and other hazards. The goal of response funding is to reduce consequences. MBRA applies response funds to reduce consequences according to an exponential diminishing return curve. Consequences range from tens of millions to $1000 million in the model, so consequence reduction can go a long way toward risk reduction. (Remember, risk is TVC.)
Figure 11.4 shows a rapid decline in risk versus investment in response. In fact, it is the most effective strategy when investing more than $100 million. But the return quickly diminishes as investment approaches $400 million. Nonetheless, investment in response (consequence reduction) is the most effective strategy, because consequence reduction is relatively inexpensive in the hypothetical data used in this illustration. See Table 11.3 containing the 5 most consequential assets in the Hetch Hetchy network model.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
HETCH HETCHY INVESTMENT STRATEGIES 205
11.7.1 the rational actor attacker
MBRA uses a Stackelberg optimization model to evaluate rational actor attacks on networks (see Appendix B for details). Stackelberg is a simple idea: the network defender allocates prevention and response resources to minimize overall risk, while a human attacker allocates attack resources to maximize overall risk. In terms of MBRA, a prevention budget is used to reduce vulnerability, a response budget is used to reduce consequences, and an attack budget is used to increase threat probability. MBRA iterates between risk minimization and risk maximization by shifting budgets from one asset to another. If equilibrium exists—a stalemate between minimization and maximization—then MBRA stops and recalculates T, V, and C using optimal allocations.
If equilibrium does not exist, MBRA outputs may oscil- late back and forth, because more than 1 allocation satisfies the maximum–minimum requirement. For example, it is possible that many different patterns of allocation of pre- vention, response, and attack budgets produce an identical risk value. When this happens, MBRA outputs will change, forever.
The Stackelberg algorithm assumes a rational actor—an attacker that is as rational as the defenders. Rational actors attempt to optimize expected utility—attacker maximizes risk and defender minimizes risk. But not all terrorists are rational actors. Some attackers are opportunistic more than rational. In fact, threat is often modeled as a combination of intent and capability rather than the probability of a rational action. Intent and capability are used in MSRAM, for example, to obtain the probability of threat–asset pairs.
Assuming equilibrium exists, two of the curves in Figure 11.4 show a higher risk versus investment when an attacker budget is applied at the same time as prevention
and response budgets. Risk is generally higher because T is higher. once again, risk is reduced more by response funding than prevention funding even when a rational actor threatens a network.
Figure 11.5 shows results of a rational actor attack on the Hetch Hetchy network. Risk is weighted by both betweenness and degree and summed over all nodes and links:
R
normalized betweeness
normal
nodes links
= ∈ ∑
i i i i i i
i
i
b g t v c
b
g
,
:
: iized degree
threat probability
vulnerability probability
t
v i
i
:
:
cci : consequence
In this scenario, an attacker targets high-consequence assets because they increase risk more than low-consequence assets. Therefore, the attacker increases T for these high- value targets, and the defender attempts to reduce V and C. The process is iterative, first minimizing TVC by reducing VC, followed by maximizing TVC by increasing T.
As a result of Stackelberg iteration, the top five assets are identified:
1. Sunol Treatment Facility (C = $1000 million)
2. Kirkwood Powerhouse (C = $1500 million)
3. Holm Powerhouse (C = $1500 million)
4. New Don Pedro Reservoir (C = $1000 million)
5. Tracey Treatment Facility (C = $1000 million)
$– $200 $400 $600 $800 $1,000
$Investment
% o
f In
it ia
l ri
sk
100%
Risk reduction vs. Investment
%Risk (prevention) %Risk (response) %Risk (prevention+attacker) %Risk (response+attacker)
90%
80%
70%
60%
50%
40%
30%
20%
10%
0%
FiGure 11.4 Risk versus investment in both vulnerability reduction (prevention) and consequence reduction (response) when there is no threat and when a human attacker has resources shows that investment in response is a slightly better strategy.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
206 WATER AND WATER TREATMENT
Risk is optimal for both attacker and defender at $793 million (out of $19,450 million, initially), assuming preven- tion, response, and attack budgets are $100 million, $100 million, and $500 million, respectively. Allocation of bud- gets to prevention, response, and attack is shown in the upper graph of Figure 11.5. Forty-five percent of the prevention budget is allocated to Sunol and Tracy Treatment Facilities. No prevention funds are allocated to Holm and New Don Pedro Reservoir. Why?
The lower graph in Figure 11.5 explains why alloca- tions favor one asset over another. Funding goes to high- RoI assets. Note that Sunol and Tracy Treatment Facilities return more risk reduction per investment dollar than the other assets. Hence, MBRA allocates more prevention and response dollars to these high-RoI assets. Further
note that the attacker spends more on assets that do not leverage prevention dollars as well as response dollars. This is a consequence of Figure 11.4, which shows that prevention is less effective than response in terms of risk reduction. The attacker takes advantage of this weakness.
Both attacker and defender leverage RoI in two-party Stackelberg games such as this. Threat is increased when relatively large gains in risk are possible. Similarly, V and C are decreased when relatively large declines in risk are possible. The attacker tries to maximize T(VC) and the defender tries to minimize (T)VC, where the parentheses indicate holding x constant in (x) while varying T of VC. (RoI is determined by prevention and response costs and consequence.)
25%
20%
15%
10%
5%A ll
oc at
io n
as %
o f
bu dg
et
0% Sunol treatment
($1000) Kirkwood
powerhouse ($1500) Holm powerhouse
($1500)
Top 5 Assets
Top 5 Assets
Allocation to top 5 Assets
ROI for top 5 Assets $30
$25
$20
$15
$10
$5
$0
R O
I $/
$
New Don Pedro reservoir ($1000)
Tracy treatment ($1000)
Sunol treatment ($1000)
Kirkwood powerhouse ($1500)
Holm powerhouse ($1500)
New Don Pedro reservoir ($1000)
Tracy treatment ($1000)
% Prevention
% Response
% Attacker
FiGure 11.5 Results of Stackelberg optimization of defender and attacker allocations show that in both cases, players attempt to optimize return on investment (RoI) in order to optimize on risk.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
HETCH HETCHY THREAT ANALYSIS 207
11.8 HetCH HetCHy tHreat analysis
The foregoing network analysis says the Hetch Hetchy water network contains critical nodes and links along the critical path from collection sources through a pipeline network with vulnerable tunnels and junctions eventually reaching treatment plants and the consumer. More specifically, the network analysis identifies high-betweenness nodes as criti- cal, as well as high-degree nodes. The Stackelberg attacker– defender optimization further identifies upstream nodes such as the Holm and Kirkwood Powerhouses and key resources such as the New Don Pedro Reservoir as critical, because of their high consequences. But network analysis does not include a threat–asset pair analysis. What threats should be considered and how should limited budgets be applied to reduce vulnerability to these threats? These questions are addressed here.
When considering criticality due to betweenness, degree, and attacker risk, four assets rank high on all lists:
1. Sunol and Tracy Treatment Facilities
2. San Joaquin Pipeline and junctions such as Foothill and Coast Range Tunnels and Bay Division Junction
3. New Don Pedro Reservoir
4. Holm and Kirkwood Powerhouses
This list of critical nodes is narrowed down further to sim- plify the following threat analysis. As before, hypothetical values are used to protect the security of these real assets. Consider only the top four: Sunol Treatment (Sun), San Joaquin Pipeline (SJP), New Don Pedro Reservoir (NDP), and Holm Powerhouse (Holm) as representative. These four assets lie on the critical path and represent the major asset types—treatment, pipeline, storage/collection, and power generation.
The following threat–asset pairs are analyzed as shown in Figure 11.6 using hypothetical values of T, V, C, and pre- vention/elimination costs listed in Table 11.4. These threats
Hetch hetchy San joaquin ...
New don pedr...
Holm powerho...
ORSunol treatm...
Sun-power Ou...
OR OR
OR
NDP-biologic...
NDP-bomb
SJP-earthqua...
SJP-corrosio...
Holm-weather
Sun-CBRNE
Sun-SCADA ex...
FiGure 11.6 A fault tree model of Hetch Hetchy critical nodes identifies the most likely threat–asset pairs in the SFPUC water system.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
208 WATER AND WATER TREATMENT
are representative only, and clearly, they can be augmented by a much larger list.
• Sunol–SCADA, Sunol–Chemical, Biological, Radio- logical, Nuclear, and Explosive (CBRNE weapons), Sunol–power outage
• San Joaquin Pipes–corrosion, San Joaquin Pipes– earthquake
• New Don Pedro–bomb, New Don Pedro–biological
• Holm Powerhouse–weather
In Table 11.4, all threats are assumed to be 50% and all vulnerabilities are assumed to be 100% initially. Pipeline damages due to earthquakes are assumed to be the most consequential in California, with bombs and weather events next in order of severity. The Holm Powerhouse could be damaged by flooding or extreme weather such as the massive flooding that occurred in 1861. Pipeline corrosion and power outages are assumed to be the least consequential of all even though they are responsible for frequent disruptions. other threats that might be consid- ered include forest fires and vandals in search of copper from power lines.
The most critical threat–asset pairs apply to treatment facilities such as the Sunol plant. See the previous chapter for more on ICS–SCADA exploits. In addition to cyber exploits, the treatment facility is subject to closure due to a lack of power and also some kind of CBRNE attack. In fact, CBRNE attacks are not as unusual as one might expect.
11.8.1 Chem–bio threats
It is always difficult to estimate damages caused by an event that has yet to take place, but one common technique is to look at similar incidents that have taken place in the past. For example, the largest-ever chem–bio “attack” on drinking water occurred in Milwaukee, Wisconsin, in 1993. An unusually high volume of spring runoff was contami- nated by Cryptosporidium in fecal matter from cattle. The contaminated water entered the drinking water supply,
which was not treated properly by the Milwaukee treatment plant. Cryptosporidium causes diarrhea in animals and humans.
An analysis of the 1993 Milwaukee Cryptosporidium mishap suggests that chem–bio incidents are real, but per- haps not as devastating as we might think:
Cryptosporidium came to national attention in 1993 in Milwaukee, Wisconsin, where 400,000 people were sick- ened. The protozoan was traced to a water filtration plant that served a portion of Milwaukee with drinking water. An investigation found there was a strong likelihood the organism passed through the filtration process and entered the water supply distribution system. The actual origin of this organism has been speculated to come from animal operations located in the tributaries of Milwaukee River. These tributaries drain directly into Lake Michigan, just north of where the water intake is located. [2]
Estimated consequences from the Milwaukee’s Cryptosporidium outbreak were $75–118 million [3]. While this was—and still is—the largest known biological incident to affect drinking water in the United States, the per capita damages were modest—approximately $80/person for medical treatment and $160/person for loss of productivity. Rather conservative consequence estimates should be used when estimating the effects of a biological or chemical attack.
Chem–bio attacks on large bodies of water are not easy to do, because of the diluting effect of lakes and reser- voirs. It takes a large amount of contamination because the natural tendency of nature is to break down the molecular structure of chemicals and germs—which dilutes their effectiveness. In addition, the EPA has done a good job of regulating large water systems so that their treatment plants are equipped with chemical and biological detec- tion and purification equipment. For these reasons, the consequences of a successful chem–bio attack on the Sunol Treatment Facility are relatively low compared with earthquake, bomb, and weather damages. Similarly, elimination costs are typically low.
table 11.4 Hypothetical input values for the fault tree of Figure 11.6 indicate that earthquakes are the most consequential of all threats considered
Name Threat (%) Vulnerability (%) Elimination cost $ (millions) Consequence $ (millions)
SJP–earthquake 50.00 100.00 1000.00 2500.00 NDP–bomb 50.00 100.00 100.00 500.00 Holm—weather 50.00 100.00 40.00 100.00 Sun–CBRNE 50.00 100.00 15.00 50.00 NDP–biological 50.00 100.00 10.00 40.00 Sun–SCADA exploit 50.00 100.00 10.00 20.00 Sun–power outage 50.00 100.00 5.00 10.00 SJP–corrosion 50.00 100.00 10.00 10.00
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
HETCH HETCHY THREAT ANALYSIS 209
11.8.2 earthquake threats
Earthquakes are known to cause extreme damage to infra- structure in large cities. They are also known to do a lot of damage to pipelines. However, the consequences in terms of economic value are comparatively low. Nonetheless, California anticipates a 7.9 earthquake within the next 30 years, and much of the pipeline infrastructure has been put in place since the 1906 earthquake (8.2). In addition, pipes inside of tunnels may be impacted much more because of the tunnels, themselves. Therefore, consequences and elim- ination costs are relatively high as shown in Table 11.4.
A nonprofit industrial organization called the Bay Area Economic Forum (BAEF) does studies to support the economic well-being of the San Francisco Bay Area. In october 2002, the BAEF released a report titled “Hetch Hetchy Water and the Bay Area Economy.” This report estimated the impact of a 7.9 magnitude earthquake on the Bay Area, providing a sound basis for the estimated cost and damages expected of a major earthquake in this area of the country.
The BAEF report makes an impression: a 7.9 earthquake along the Hayward Fault would produce a loss in produc- tivity and physical damage of $17 billion. Similarly, the combined economic and infrastructure damage caused by an earthquake along the San Andreas Fault would exceed $28 billion!
The area covered by Figure 11.6 is perhaps one-half of the area considered in the BAEF study. Additionally, build- ings, highways, and pipelines have been earthquake hard- ened since the 2002 report. Therefore, an elimination cost of $1 billion was used in Table 11.4, because approximately one-half of the damage estimates used by the BAEF were attributed to economic losses, and the area residents have since spent $3.6 billion retrofitting infrastructure against earthquakes.
one notable exception may be the vulnerability of the pipeline passing through the Crystal Springs Tunnel near the Stanford Linear Accelerator off of Interstate 280. During the El Niño winter of 1996–1997, a landslide occurred on the northeast hillside above Polhemus Road in San Mateo County, which damaged homes and blocked Polhemus Road. The landslide temporarily buried the large water pipe running through the Crystal Springs Bypass Tunnel. The 96 inch pipeline transports an average of 90 million gallons of drinking water per day to communities in San Francisco and on the Peninsula, including San Mateo and parts of Silicon Valley. Ninety million gallons per day is 25% of the daily flow of Hetch Hetchy. The implication is that another storm, earthquake, or bomb attack could easily deny consumer access to 25% of the total water supply.
Another flaw in the model may be the absence of time-to- recover effects on consequence. The BAEF report estimates that repairing a pipeline takes 20 times as long as repairing a pumping station. Tunnels can take up to 30 times as much time. The fault tree model does not directly capture these delays, but delays can be quantified as economic loss. The fault tree lacks the expressive power to model time delays, but it does have the expressive power to model economic and productivity losses.
11.8.3 allocation to Harden threat–asset Pairs
MBRA fault tree analysis applies the PRA equations— R = TVC—to each threat–asset pair shown in Figure 11.6 and then sums each threat–asset pair risk to obtain overall risk of $1615 million. Elimination costs are applied to each threat–asset pair to reduce vulnerability V according to an exponential diminishing return curve. Therefore, risk also declines along a diminishing return curve as shown in Figure 11.7. of particular note is the much slower decline
100%
90%
80%
70%
60%
50%
40%
30%
20%
10%
0% $0 $200 $400 $600 $800 $1,000
Investment ($000)
SFPUC water risk, Vulnerability vs. Investment
%Risk %Vulnerability
R is
k, V
ul ne
ra bi
li ty
FiGure 11.7 Risk reduction and vulnerability versus investment shows that risk declines much faster than vulnerability. An investment of $600 million is required to reduce vulnerability below 50%.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
210 WATER AND WATER TREATMENT
in fault tree vulnerability—the probability that one or more threats occur—compared to risk. Why is it more difficult to reduce vulnerability?
Investment in the Sunol–power outage pair is very ineffi- cient compared to all other threat–asset pairs. For example, the ratio of initial risk to elimination cost is 0.50 for the Sun–power pair in Table 11.5 as compared with 1.25 for the SJP–earthquake pair. This means that investment in assuring a reliable power supply to the Sunol Treatment Facility returns very small reduction in vulnerability. For example, Sun–power vulnerability remains over 25% after a total investment of $600 million. (The fault tree uses oR gate logic, which means that only one or more threats need to occur to cause the entire fault tree to fail.)
The Hetch Hetchy system is only as secure as its least secure node or link. Therefore, a asset-threat pair such as the Sun–power outage pair that remains vulnerable after an investment means the entire system remains vulnerable. In this case, vulnerability is reduced from 100 to 38% after $600 million is invested. The overall RoI is $2.44/$, which is a positive return.
Table 11.5 shows the results of an investment of $600 million to reduce V for the eight threat–asset pairs of Figure 11.6. Most of the money goes toward earthquake retrofitting (82%) with protection for a bomb threat against New Don Pedro Reservoir (11%). Therefore, 93% of the investment aims to harden the pipelines and reservoir. This strategy was produced by MBRA. Is it a good strategy? Human policymakers might do well to modify the comput- er’s results if the Sunol Treatment Facility is considered more important than MBRA says it is.
11.9 analysis
The DHS and the WaterISAC recommend the use of RAMCAP to perform risk analysis on pipelines, water systems, and ICS. RAMCAP is an application of PRA—R = TVC—much like MBRA. But it does not perform resource allocation. Instead, the risk contribution of each threat–asset pair in an infrastruc- ture is calculated, and then assets are ranked according to
their risk. Risk ranking correlates well with MBRA resource allocation in this case, but in general, risk ranking is not guaranteed to yield an optimal allocation of limited funds:
Risk Ranking Strategy: Allocate risk elimination funds to the threat–asset pairs with the highest-ranking risk.
Risk Minimization Strategy: Allocate risk elimination funds to the threat–asset pairs according to the highest return on investment (ROI).
Complex CIKR analysis shows that self-organization in the form of high betweenness makes the SFPUC water sector highly vulnerable to DoS attacks and natural disasters. A limited and hypothetical analysis of threats suggests earth- quakes are of major concern, but other assets such as tunnels may pose a greater risk because their destruction is easy and the time to repair them is high. A collapsed tunnel could lead to a long period of DoS. For example, the BAEF report estimates that repairing a Hetch Hetchy tunnel can take up to 30 times as much time as any of the other components.
Furthermore, the interdependencies among water, power, and transportation (airports) make water even more critical for the San Francisco Bay Area. It is conceivable that a normal accident that starts in the water sector could cascade to power and then to transportation. CIKR analysis of the Hetch Hetchy water and power network indicates a rather high resilience to cascade failure. Theoretically, vulnera- bility of individual nodes and links would have to exceed 25% to lead to a complex catastrophe. While this is highly unlikely, it is not impossible.
11.10 exerCises
1. Which of the following is DHS’s mission in protecting the water sector? a. Environmental impact on water supplies b. Drinking water supplies c. Agricultural water supplies d. Industrial water supplies e. All of the above
table 11.5 most of $600 million is allocated to harden pipelines against earthquake damage
Name Threat
(%) Vulnerability
(%) Elimination cost
$ (millions) Consequence $ (millions) Risk initial
Allocation $ (millions)
Vulnerability reduced (%)
Risk reduced
SJP–earthquake 50.00 100.00 1000.00 2500.00 1250.00 492.19 10.37 129.58 NDP–bomb 50.00 100.00 100.00 500.00 250.00 64.27 5.18 12.96 Holm–weather 50.00 100.00 40.00 100.00 50.00 19.69 10.37 5.18 Sun–CBRNE 50.00 100.00 15.00 50.00 25.00 8.32 7.77 1.94 NDP–biological 50.00 100.00 10.00 40.00 20.00 5.94 6.48 1.30 Sun–SCADA exploit 50.00 100.00 10.00 20.00 10.00 4.44 12.96 1.30 SJP–corrosion 50.00 100.00 10.00 10.00 5.00 2.93 25.92 1.30 Sun–power outage 50.00 100.00 5.00 10.00 5.00 2.22 12.96 0.65
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
ExERCISES 211
2. When did responsibility for water security transfer from the Public Health Service (PHS) to the U.S. EPA? a. 1914 b. 1962 c. 1974 d. 2002 e. 2003
3. Why did regulation of water move from PHS to EPA? a. Emphasis shifted from biological to environmental
contamination. b. Emphasis shifted from biological to terrorism. c. The EPA had more money. d. PHS was abolished. e. Emphasis shifted from chemical to environmental
contamination.
4. The Bioterrorism Act of 2002 extends the SDWA of 1974 as follows: a. Includes acts of terrorism b. Requires vulnerability assessments c. Establishes the WaterISAC d. Specifies prison term penalties e. All of the above
5. Which of the following are critical nodes in the SFPUC water system (Hetch Hetchy) as determined by network analysis? a. New Don Pedro Pipeline b. The ICS–SCADA system c. Hetch Hetchy and Lake Lloyd Reservoirs d. Sunol Treatment Facility e. Merge #2 and Merge #3
6. optimal resource allocation finds the best allocation of budgets by maximizing: a. Threat b. Vulnerability c. Risk d. RoI e. Consequence
7. Resource allocation by risk ranking guarantees the following: a. Risk minimization b. optimal allocation of resources c. Maximum RoI d. Threat minimization e. None of the above
8. The foundation of the water sector’s safety and secu- rity is: a. The Bioterrorism Act of 2002 b. The 1974 SDWA c. PPD-63 d. PPD-21 e. The Homeland Security Act of 2002
9. Stackelberg game theory finds the best attacker and defender allocation by: a. Predicting future attacks b. Maximizing threat and minimizing vulnerability c. Minimizing threat and maximizing vulnerability d. Maximizing threat, vulnerability, and consequence e. Minimizing threat, vulnerability, and consequence
10. Earthquake experience has shown that the water supply is most vulnerable to: a. Broken pipes b. Contamination of the lakes and reservoirs c. Collateral fires and explosions d. Collapsing tunnels e. Collapsing freeways
11. The main lesson learned from San Francisco earth- quakes is: a. Pipes are vulnerable to earthquakes. b. Drinking water is no longer potable. c. Collapsing tunnels block the flow of water. d. 80% of the water is used for agriculture. e. Backup power is essential.
12. The largest water supply contamination disaster in the United States was: a. Hetch Hetchy, November 2002 b. Milwaukee, Wisconsin’s Cryptosporidium contami-
nation in 1993 c. The Loma Prieta earthquake in the San Francisco
Bay Area d. Hurricane Fran in 1996 e. Hurricane Dennis in 1999
13. In terms of time delays caused by the time to repair a water sector component, the Hetch Hetchy water supply is most vulnerable to: a. Broken pipes b. Collapsing tunnels c. Collapsing freeways d. Broken pumps and gates e. Insufficient budget
14. Which of the following is the least interdependent with the water sector? a. Transportation b. Power c. Agriculture d. Silicon Valley industry e. Public health
15. The major lesson learned from the 1989 earthquake in the San Francisco area relative to the water supply was: a. Buy more backup power systems. b. Retrofit power transmission lines. c. Backup the water supply to the airport. d. Harden tunnels. e. Duplicate treatment facilities.
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.
212 WATER AND WATER TREATMENT
reFerenCes
[1] U.S. Environmental Protection Agency. 25 Years of the Safe Drinking Water Act: History and Trends. Report No. US-EPA 816-R-99-007, December 1999. Available at http://www.epa. gov/safewater/consumer/trendrpt.pdf. Accessed June 29, 2014.
[2] Holman, R. E. Cryptosporidium: A Drinking Water Supply Problem. Water Resources Research Institute of the University of North Carolina. Special Report No. 12, November 1993.
[3] Corso, P. S., Kramer, M. H., Blair, K. A., Addiss, D. G., Davis, J. P., and Haddix, A. C. Cost of Illness in the 1993 Waterborne Cryptosporidium outbreak, Milwaukee, Wisconsin, Emerging Infectious Diseases, 9, 4, April 2003, pp. 426–431.
sidebar 11.1 HistoriCal timeline For tHe evolution oF Water saFety and Prevention oF terrorist attaCks on drinkinG Water
1880s—Louis Pasteur develops germ theory and notes that water is a vector 1885—Dr. John Snow proves cholera transmitted by drinking water 1914—U.S. PHS sets standards for the bacteriological quality of drinking water 1925, 1946, and 1962—U.S. PHS revises standards. The 1962 revision called for the regulation of 28 substances and established the most rigorous standards until 1974 1960—U.S. PHS study shows that only 60% of drinking water met PHS standards 1972—U.S. PHS study of Mississippi River reveals 36 chemicals contaminating drinking water processed by treatment plants 1974—SDWA establishes foundation of modern regulations for protecting the purity of water and water systems. Enforcement transferred to the U.S. EPA 1986, 1996—Revisions to SDWA of 1974 1993—Cryptosporidium outbreak in Wisconsin kills over 50 people and infects 400,000 consumers of public water May 22, 1998—President Clinton signed PDD-63 identifying drinking water as one of America’s critical infrastructures June 12, 2002—President Bush signs into law the Public Health Security and Bioterrorism and Response Act of 2002 August 1, 2002—The U.S. EPA completes the classified Baseline Threat Report describing likely modes of terrorist attack and outlining the parameters for vulnerability assessments by community water systems December 2002—WaterISAC becomes operational March 31, 2003—Water systems serving more than 100,000 people submit vulnerability assessments to the U.S. EPA December 31, 2003—Water systems serving between 50,000 and 100,000 people are required to submit vulnerability assessments to the U.S. EPA June 30, 2004—Water systems serving between 3,300 and 50,000 people are required to submit vulnerability assessments to the U.S. EPA
Lewis, T. G., & Lewis, T. G. (2014). Critical infrastructure protection in homeland security : Defending a networked nation. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-11-25 07:21:00.
C op
yr ig
ht ©
2 01
4. J
oh n
W ile
y &
S on
s, In
co rp
or at
ed . A
ll rig
ht s
re se
rv ed
.