Review on Energy Resilience

profileharsh55
Managingtheriskofterrorismtointerdependentinfrastructuresystemsthroughthedynamicinoperabilityinputoutputmodel.SystemsEngineering.pdf

Managing the Risk of Terrorism to Interdependent Infrastructure Systems Through the Dynamic Inoperability Input–Output Model Chenyang Lian and Yacov Y. Haimes*

Center for Risk Management of Engineering Systems, University of Virginia, 112 Olsson Hall, PO Box 400736, Charlottesville, VA 22904-4736

Received 13 August 2005; Accepted 25 January 2006, after one or more revisions Published online in Wiley InterScience (www.interscience.wiley.com). DOI 10.1002/sys.20051

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM

ABSTRACT

This paper discusses the Dynamic Input–Output Inoperability Model (DIIM), which is an extension to the static Inoperability Input–Output Model (IIM). Based on Wassily Leontief’s Input–Output (I–O) model, both the IIM and the DIIM analyze how the system of interdepend- ent sectors can be adversely affected as a result of initial perturbations to other sectors through willful attacks or natural disasters. To model the industry/sector interdependencies, the DIIM uses the national and regional commodity-transaction data from the Bureau of Economic Analysis (BEA) and the Regional Input–Output Multiplier System (RIMS II). In contrast to most traditional dynamic I–O models, the DIIM introduces industry resilience

Regular Paper

241

Contract grant sponsors: This study is supported by the National Science Foundation, under a grant to the University of Virginia Center for Risk Management of Engineering Systems (NSF 0301553: Input-Output Risk Model of Critical Infrastructure Systems, May 2003– June 2007). This study is also supported by a grant from the Institute for Information Infrastructure Protection (I3P) under Grant 2003-TK-TX-0003 from the Office of Domestic Preparedness of the U.S. Department of Homeland Security.

*Author to whom all correspondence should be addressed (e-mail: [email protected]).

Systems Engineering, Vol. 9, No. 3, 2006 © 2006 Wiley Periodicals, Inc.

coefficients to measure the efficacy of sectors’ risk management options. The DIIM also incorporates the stochastic properties of a recovery through the Brownian motion, repre- senting short-term uncertainties. The paper uses two metrics to assess the consequences to the economic sectors of attacks. The DIIM methodology is demonstrated in detail through a two-by-two economy system. This is followed by an analysis of a terrorist attack scenario, using the DIIM and the BEA/RIMS II commodity-flow data of the 59 sectors in Virginia. © 2006 Wiley Periodicals, Inc. Syst Eng 9: 241–258, 2006

Key words: risks of terrorism; input–output inoperability model; dynamic IIM; dynamic recovery

1. BACKGROUND

Wassily Leontief [1951a; 1951b], who developed and promoted the Input–Output (I–O) Model for economic systems, is remembered as the “father of the I–O model” in economics. In recognition of his outstanding pioneering work, he was awarded the 1973 Nobel Prize in Economics. Leontief modeled the entire economy as a system of industry sectors that are interdependent on each other through their internal input–output com- modity flows. Ever since, scholars have been engaged in many aspects of I–O research to extend the theories and applications from the economic system to others, such as environmental, energy, and infrastructure sys- tems. Notable extensions of the I–O model include a nonlinear Leontief model [Krause, 1992], energy I–O analysis [Proops, 1984], environmental and water re- source I–O analysis [Lee, 1982; Haimes and Nainis, 1974; Haimes, 1977]. Miller and Blair [1985] published a comprehensive I–O model book marking the maturity of I–O analysis in the 20th century. Recent advances of I–O research are found in Lahr and Dietzenbacher [2001].

Interdependency analysis has been a major building block in systems engineering, built on the widely ac- cepted premise within the engineering community that systems are interdependent. This means that any effect on one part of the system can propagate and affect others within the system and among other external systems. The I–O model appeals to interdependency researchers and analysts because it is capable of captur- ing among the industry sectors of the economy the indirect ripple effects of a natural disaster or an attack. Rose et al. [1997] and Rose [2004] proposed an I–O model to estimate the regional economic impacts of electricity lifeline disruptions caused by earthquakes. Olsen et al. [1997] developed an I–O model for optimal deployment of flood protection. Leontief and Duchin [1986] applied the I–O models to predict the potential impacts of automation on the workforce. Haimes and Jiang [2001], Crowther and Haimes [2005], and Haimes et al. [2005a; 2005b] extended the principles of

the I–O model to develop the Inoperability Input–Out- put Model (IIM), with broad applications to critical infrastructure systems. Compared with other main- stream I–O research, the IIM focuses on the inoperabil- ity of infrastructure systems due to perturbations resulting from terrorist attacks or other interruptions to the industrial sectors of the economy. These adverse consequences are measured in economic loss and inop- erability (i.e., percentage of “dysfunctionality” relative to an ideal state). Thus, the IIM aims to utilize I–O analysis to provide a specific framework for the assess- ment and management of risks to infrastructure protec- tion and to homeland security. The successful recent applications of the IIM include assessing the threat to the United States from high-altitude electromagnetic pulse attacks and many others. In recent years, there have been many other notable quantitative methodolo- gies for interdependent infrastructure protection and modeling terrorist threats. Apostolakis and Lemon [2005] presented a method for identifying and prioritiz- ing vulnerabilities in infrastructures by employing graph theory and multiattribute utility theory. Paté-Cor- nell and Guikema [2002] described a systems analysis approach to setting priorities among countermeasures using probabilistic risk analysis.

Here the DIIM is proposed to model the recoveries of industry sectors following a disruptive event such as a terrorist attack or natural disaster. Based on the initial perturbations of sectors caused by the disruptive event and on the estimated recovery times, the model calcu- lates the inoperabilities and economic losses of interde- pendent sectors during the recovery period. However, the DIIM does not model the transient period during the event in which the sectors that are directly attacked become inoperable.

2. INTRODUCTION

The IIM was developed to assess the efficacy of risk management, evaluating the impacts of economic dis- ruption with and without applying risk mitigation meas- ures [Haimes and Chittester, 2005]. However,

242 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

enhancements were needed for aspects of the model that concern temporal and risk management evaluations. For example, it is imperative for decisionmakers to know: (i) How does a particular system recover over time? (ii) What are the associated economic losses? (iii) What can be done to minimize the losses during the recovery period after the attack? The DIIM addresses these questions. Although some dynamic aspects of the IIM were briefly and partially discussed in Haimes et al. [2005a], a more thorough analysis of the theoretical and methodological dimensions of the DIIM is pre- sented here. The concept of an industry interdepen- dency index is proposed to measure the degree of each sector’s dependency on other interconnected sectors of the economy. From the risk management perspective, the interdependency index of a sector can be decreased through hardening, prevention, and redundancy. This leads to a faster recovery of the economy and less economic loss following an attack. This paper further examines the framework for risk management through a multiobjective optimization formulation using the DIIM, which explicitly evaluates various risk manage- ment options based on cost and benefit tradeoff analy- sis.

Understanding the subject of randomness is critical for any attempt to apply probability theory to cata- strophic attacks. Probability theory [Gnedenko, 1963] has been very successfully applied in the natural sci- ences because of the regularities in the randomness of natural phenomena, whether in physics, astronomy, chemistry, or physiology. Unlike precipitation, with a vast database, terrorism scenarios do not seem to belong to a random process, and thus no single probability density function can be assigned to represent credible knowledge of the likelihood of such attacks. The inher- ent lack of regularity in the randomness of catastrophic attacks can be characterized as unknown nonstationary random events (not a process), because they are not only unknown and without historical precedence, but they are also changing in time. In terms of risk analysis, the question is how to deal with a not-unlikely extreme and possibly catastrophic event. Note: A not-unlikely event has an entirely different connotation from an unlikely one. The term unlikely implies that the observer has a sufficient level of belief or confidence that the event has a low probability of occurrence. On the other hand, the term not-unlikely implies that the observer has a suffi- cient level of belief or confidence that the event may occur, but without knowledge of its probability [Haimes, 2004].

Based on the above discussion, risk, which is a measure of the probability and severity of adverse ef- fects [Lowrance, 1976], will be represented in this paper only in terms of consequences, assuming a not-

unlikely probability of terrorist attacks. Once credible intelligence becomes available, then the expected value of risk supplemented by the conditional expected value of risk for extreme events [Asbeck and Haimes, 1984; Haimes 2004] can be used for the risk metric.

After the above introduction of the DIIM, the paper is organized as follows. Two basic applications of the dynamic model are described in Section 3, which em- phasizes the concept of industry resilience coefficients. Section 4 discusses the implications of the DIIM for risk management during the recovery of an economic sys- tem. Section 5 formulates the risk management as a multiobjective problem. To illustrate the model, Section 6 demonstrates the DIIM using data from the two-in- dustry economic system discussed in Miller and Blair [1985]. Section 7 presents an in-depth case study of a terrorist attack scenario using I–O data from the BEA/RIMS II databases to apply the DIIM to actual Virginia economic sectors. The paper concludes in Sec- tion 8.

3. DIIM FORMULATION

The formulation of the original Leontief I–O model is given in Eq. (1), where xi represents the total production output of Industry i. The Leontief technical coefficient aij indicates the ratio of the input from Industry i to Industry j, with respect to the overall production re- quirements of Industry j. In Eq. (1), ci represents the final demand of the ith industry, defined as the portion of Industry i’s total output for final consumption by end-users.

x = Ax + c ⇔    xi = ∑

j

aijxj + ci  Wi. (1)

Based on the classic Leontief I–O model, Santos and Haimes [2004] proposed the demand-reduction IIM. This enables quantitatively assessing the reduction of each sector’s economic output resulting from initial final-demand perturbations to a set of economic sectors. The concept of inoperability of an economic sector is defined as the percentage of output reduced from the ideal output, which is triggered by demand reduction. Formally, if x̂ is defined as the as-planned total produc- tion vector of the economy, and x

~ is the degraded total

production vector, the demand-based inoperability q is defined in

q = [(diag(x̂))−1(x̂ − x ~ )], (2)

where the operator diag(x̂) is the resulting diagonal matrix constructed from the given output vector x̂ as

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 243

Systems Engineering DOI 10.1002/sys

illustrated in Eq. (3) for a dimension of n (note that this notation will also be used later):

diag(x̂) = diag

   

x̂1 x̂2 I

x̂n

   

=

   

x̂1 0 I

0

0 x̂2 ...

. . .

. . . ... ... 0

0 I

0 x̂n

   

. (3)

The demand-reduction IIM is given in

q = [I – A*]–1c*, (4)

where the notation c*, defined in Eq. (5), is the percent- age vector of reduced final demand from the total nominal output and the notation A*, defined in Eq. (6), is the normalized interdependency square matrix:

c∗ = [(diag(x̂))−1 (ĉ − c~)], (5)

A∗ = [(diag(x̂))−1 A(diag(x̂))]. (6)

Note that the concepts and definitions in the demand- reduction IIM are all applicable to the DIIM, which extends the IIM with additional dynamic and stochastic elements. Since the early development of the Leontief I–O model, researchers have been investigating various forms of a dynamic Leontief I–O model [Sage, 1977]. The dynamic model given in Eq. (7) is one of the most widely accepted [Miller and Blair, 1985]:

x(t) = Ax(t) + c(t) + Bx . (t) (7)

In this basic dynamic form, the notation x(t) refers to the output vector of the economy sectors at time t. The vector c(t) represents the final demands of the sectors at time t. The square matrix A is the interdependency matrix, representing the interdependencies among all the economic sectors, which is analogous to matrix A in the static I–O model. The square matrix B is intro- duced in the dynamic model as the capital coefficient matrix, which measures the willingness of the economy to invest in capital resources (such as machines, land, structures, and software). When equilibrium is reached in the dynamic I–O model, Eq. (7) takes the same form as the static model in Eq. (1), where x

. (t) = 0 is assumed

at equilibrium. Revising the traditional dynamic I–O model and its

interpretations, Blanc and Ramos [2002] showed that the elements of B in Eq. (7) must be either zero or negative for the model of an economy system to be stable, assuming that A and B are constant, and only such condition can produce an economic behavior con- sistent with the static model, regardless of the initial conditions or final demands. Therefore, according to

Blanc and Ramos, the capital coefficient matrix B can be interpreted as an expression of short-term counter- cyclical policy, instead of long-term growth which was supported by the mainstream I–O research community for years. Blanc and Ramos considered a case where B = –I in Eq. (7), as represented in Eq. (8). From this they interpreted the dynamic model as describing the adjust- ment level of the economy’s production following in- formation about an imbalance in supply and demand at time t.

x . (t) = Ax(t) + c(t) – x(t). (8)

For a two-industry-economy, Eq. (8) can be specified as follows, where the left-hand-sides represents the adjustments of sectors and the right-hand-sides are their imbalances in supply and demand as discussed pre- viously:

  

dx1(t) = (a11x1(t) + a12x2(t) + c1(t) − x1(t))dt, dx2(t) = (a21x1(t) + a22x2(t) + c2(t) − x2(t))dt.

(9)

For different sectors of the economy, the pace of adjust- ment can vary greatly, depending on the characteristics of the sectors as well as the specific situations that arise. Therefore, for the two industries in Eq. (9), coefficients k1 and k2 can be added to describe the production adjustment rates respectively, as in

  

dx1(t) = (a11x1(t) + a12x2(t) + c1(t) − x1(t))k1dt, dx2(t) = (a21x1(t) + a22x2(t) + c2(t) − x2(t))k2dt.

(10)

In general, given that the dynamic process is not com- pletely deterministic, myriad factors can randomly af- fect the short-term behaviors of the sectors. Therefore, by adding a stochastic component and extending the Blanc and Ramos [2002] model, the dynamic extension of the IIM is formally introduced in Eq. (11), followed by detailed explanations of the parameters:

dx(t) Ax(t) + c(t) − x(t)

= Kdt + sdz, (11)

K = Diag(k1, . . . , kn), (12)

s = Diag(σ1, . . . , σn). (13)

The symbol dz in Eq. (11), when seen as dz = ε(t)√dt , is the Wiener process or the Brownian motion. This is used widely in the literature (see Luenberger [1998]) to represent the “random walk” of the variables. The term ε(t) is a standardized normal distributed random vari- able with mean zero and variance one. The diagonal

244 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

matrix K in Eq. (12) is the industry resilience coefficient matrix, with its ith nonzero diagonal element ki defined as the industry resilience coefficient, representing the resilience [Haimes et al., 1998] of the Sector i. The industry resilience coefficient matrix dictates an expo- nential dynamic process for the industrial sectors. The greater the ki value, the faster the economic system responds to an imbalance in supply and demand.

The diagonal matrix s in Eq. (13), the industry resilience deviation matrix, also measures the uncer- tainties of the dynamic process and the deviations of the industry resilience coefficient matrix K. Each nonzero diagonal element in the matrix, defined as the industry resilience deviation coefficient, implies the uncertain- ties of an economic sector during its dynamic process in the DIIM. The higher σ value indicates more volatil- ity in a sector; therefore, it is harder to control and predict the dynamic path of its behavior. In the context of a recovery from an attack or an incident, the industry resilience deviation coefficient, σ, is a manifestation of a sector’s characterizations (such as its structure, vul- nerabilities, etc.) and the nature of the attack or incident, as well as the functions of risk management policies and other external factors during the recovery period.

All the other variables in Eq. (11) have the same definitions as in Eqs. (1)–(8). In summary, in Eq. (11) the term Ax(t) + c(t) – x(t) reflects the interdependency among the sectors of the economy; the term Kdt repre- sents the exponential resilience of the economy for its demand and supply to be at the same level in the long term; and the term sdz captures the short-term random- ness of the dynamic process. Comparing the Leontief dynamic I–O model in Eq. (7) and the DIIM formula- tion in Eq. (9), it is obvious that the DIIM is equivalent to the Leontief dynamic model by setting the capital investment coefficient matrix B = –K–1. However, in the DIIM, B is not interpreted as an expression of the long-term growth of the economy. Rather, it is extended as a measure of the short-term resiliencies of industry sectors following disruptive events such as natural haz- ards or terrorist attacks. Since the resiliency of a sector is affected by risk management and public policies, the matrix B can be viewed as a risk management invest- ment coefficient matrix, representing the willingness to invest in risk management for economic sector disas- ters. To characterize the randomness of the recovery, the Wiener process is supplemented to the dynamic model. It has the capability of modeling the short-term random process, and the industry resilience deviation coeffi- cient (σ) provides a measure of volatility for the resil- ience coefficient k. Thus, the Wiener process in the DIIM formulation simulates the short-term uncertain- ties during the overall recovery trend. The effects of uncertainty from the Wiener process also depend on the

amount of imbalance between supply and demand in Eq. (9). Therefore, at the beginning of the recovery, significant uncertainties are presented, and as the eco- nomic system recovers, the uncertainties decrease until the new equilibrium is reached.

Applying Eq. (1) to the as-planned production sce- nario and Eq. (11) to the degraded production scenario, Eqs. (14) and (15) can be obtained:

Ax̂(t) + ĉ(t) – x̂(t) = 0, (14)

dx~(t) Ax~(t) + c~(t) – x~(t)

= Kdt + sdz. (15)

It follows that

d(x̂ − x~(t)) A(x̂ − x~(t)) + (ĉ − c~(t)) − (x̂ − x~(t))

= Kdt + sdz.

(16) From Eq. (6), Eq. (16) becomes the following form, in which the normalized interdependency square matrix A* follows the definition in Eq. (6):

d(x̂ − x ~ (t))

(diag(x̂))A∗(diag(x̂))−1(x̂ − x~(t)) + (ĉ − c~(t)) − (x̂ − x~(t)) =

Kdt + sdz. (17)

Equation (17) can be transformed to

d[(diag(x̂))−1(x̂ − x ~ (t))]

A∗(diag(x̂))−1(x̂ − x ~ (t)) + (diag(x̂))−1(ĉ − c~(t)) − (diag(x̂))−1(x̂ − x~(t))

=

Kdt + sdz. (18)

By definitions of q(t) and c*(t), the inoperability form of the DIIM is given in

dq(t) A∗q(t) + c∗(t) − q(t)

= Kdt + sdz. (19)

When the final equilibrium is reached, the DIIM has the same form as the static IIM in Eq. (4). Therefore, in this formulation, the DIIM encompasses the theoretical ba- sis for interdependency, the exponential resilience of the economy, the randomness of the dynamic process, and the static IIM.

The stochastic nature of the DIIM represents the multifaceted character of the dynamic process that in- volves many other aspects of our society that extend beyond the concept of the standard deviation s. This paper emphasizes the dynamic aspect of the IIM. How- ever, the stochastic portion is visited briefly in Section

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 245

Systems Engineering DOI 10.1002/sys

6.4, leaving extensive discussions on the stochastic aspects of the model for a future paper. When the stochastic part of the DIIM is ignored (s = 0), Eq. (11) is reduced to the form resulting in

x . (t) = K[Ax(t) + c(t) – x(t)], (20)

or it takes the inoperability form in Eq. (21), where q(t) is related to x(t) as in Eq. (2):

q . (t) = K[A*q(t) + c*(t) – q(t)] (21)

Equation (21) is a standard form of linear first-order differential equations [Edwards and Penney, 2000], and the solution to it is as follows, given the initial condition q(0):

q(t) = e−K(I−A ∗)t q(0) + ∫

0

t

Ke−K(I−A ∗)(t−z) c∗(z) dz. (22)

If the final demand c*(t) is stationary, then Eq. (22) can be further simplified as follows:

q(t) = (I − A∗)−1 c∗ + e−K(I−A ∗)t [q(0) − (I − A∗)−1c∗].

(23)

4. TWO BASIC DIIM APPLICATIONS

To reach equilibrium, the DIIM can be applied to the two basic types of the economy’s dynamic process. These are the demand-reduction dynamic and the dy- namic recovery associated with the production outputs of interdependent sectors. The demand-reduction dy- namic is the extension of the demand-reduction IIM that calculates the new equilibrium output of sectors, given demand-reduction perturbations caused by psychologi- cal effect. The DIIM is also applicable to model the recovery of the economy after disruptive events that degrade the production capacity of directly affected sectors, under fixed or variable final demands. As dem- onstrated in Section 3.2, a key contribution of the DIIM is extending the Leontief I–O from demand-based to supply-and-demand-equilibrium-based. When the model is applied to disruptive events such as terrorist attacks or natural disasters, the sector outputs (supplies) are reduced due to impacts of the events on production capacity. Thus, as modeled through the DIIM, during the recovery period the sector outputs (supplies) will increase to meet the final demands until the equilibrium is reached. The concept of recovery rate in the DIIM therefore is introduced to measure differing sector re- covery rates, given their imbalances in supply and de- mand.

4.1. Demand-Reduction Dynamics

The static demand-reduction IIM can be used to calcu- late the reduced output of economic sectors due to the initial final demand reduction from a set of sectors. The final demand reduction can result from various causes, one of which can be the psychological impact on con- sumers from a terrorist attack. The DIIM can be applied to the case of final demand reduction to show how the outputs change for every time period until equilibrium, after the initial perturbation to the final demand of the economy. The dynamic demand-reduction scenario can be described mathematically as the following: The term Ax(t) in Eq. (11) represents the intermediate demand of each sector at time t; therefore, the term Ax(t) + c(t) represents the total demand of the sectors including the intermediate and final demands. At equilibrium, the total demand Ax(t) + c(t) meets the total supply x(t). However, when there is a final demand reduction, c(t) is reduced to a smaller c

~ (t), which makes the term Ax(t)

+ c ~ (t) – x(t) negative. Therefore, according to Eq. (11),

the output supply x(t) starts to decline until it reaches a new level, x

~ (t), when the new equilibrium is achieved

(Ax ~ (t) + c

~ (t) – x

~ (t)).

The solution for the demand-reduction dynamics is as follows. For calculating convenience, we adopt the inoperability form of the DIIM. Formally, for the case of demand reduction in the DIIM, it is a given that at time zero, the economy is at a business-as-usual state (completely operable, q(0) = 0; i.e., inoperability is zero); but there are perturbations to the normalized final demand (c* > 0). It follows that Eq. (23) becomes

q(t) = [I − e−K(I−A ∗)t](I − A∗)−1c∗. (24)

Equation (24) fully describes the dynamic behavior of the sector that adjusts itself in the event of final demand reduction. In equilibrium, when t → ∞ , it can be ob- served from Eq. (24) that the inoperability is given by Eq. (25) if the demand reduction is held constant:

q(∞) = (I − A∗)−1c∗. (25)

Equation (25) is of the same form as the static demand- reduction IIM. It is also verified that when t = 0, according to Eq. (24), q(0) = 0, which is consistent with the demand-reduction assumption that the initial inop- erability is zero.

As discussed in the DIIM formulation, the industry resilience coefficient matrix K(t) in the demand-reduc- tion DIIM measures the speed of each sector’s adjust- ment to an imbalance in supply and demand. For each sector, a greater k(t) in the K matrix implies a more prompt adjustment of its output in response to a change

246 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

in final demand. Equation (24) confirms that the indus- try resilience coefficient can affect the dynamic process exponentially. The industry resilience coefficient is a characteristic of a particular economic sector; therefore, to further understand and estimate accurately the coef- ficient for each sector requires investigating an eco- nomic sector from a holistic perspective. One of the notable approaches to that end is to use Hierarchical Holographic Modeling (HHM) [Haimes, 1981, 2004], a method that has been used in many risk analysis applications for understanding complex systems.

4.2. Dynamic Recovery of the Sectors

The DIIM can also be applied to model the dynamic recovery of industry sectors after their production is interrupted by either natural disasters or terrorist at- tacks. In such a case, the output of the economy x(t) is reduced to a smaller x

~ (t). When the final demands are

assumed to be the same, the total demand of the sectors Ax

~ (t) + c(t) exceeds the output supply of the sectors

x ~ (t). As the affected sectors recover from their degraded

output, the mismatch between the demand and supply Ax

~ (t) + c(t) – x

~ (t)) decreases as well, until the point

when the sectors fully recover and have the capability to provide a level of output to meet total demand.

Formally, in the more realistic case of dynamic recovery, after an accident or attack, the initial output levels of the economic sectors are reduced, causing inoperability to these sectors (q(0) > 0). It is assumed that the final demand of each sector stays constant; therefore, c* = 0. In this case, Eq. (23) can be reduced to

q(t) = e−K(I−A ∗)tq(0). (26)

Equation (26) describes the dynamic recovery process of the economy following an interruption of its produc- tion. As t → ∞, it can be observed from Eq. (26) that q(t) → 0. In other words, as time progresses, the eco- nomic sectors recover from their initial inoperability back to their business-as-usual status, where all the sectors are totally operable as indicated in

q(∞) = 0 (27)

Similar to the demand-reduction case, in the dynamic recovery of the sectors, the industry resilience coeffi- cient matrix K determines the speed of exponential recovery for each economic sector according to the DIIM. (In the study assessing the impact of a high-alti- tude electromagnetic pulse (HEMP) attack on interde- pendent infrastructure sectors [Haimes et al., 2005a, 2005b], exponential recovery was chosen by the HEMP

Commission, which was established by Congress to provide an independent assessment of the HEMP threat against the United States [CRS, 2004].) The ith diago- nal element in the K matrix is a measure of the recovery time for the ith sector in the economy. Therefore, ki is defined as the interdependency recovery rate, which describes the recovery rate of Sector i.

To assess the interdependency recovery rate ki for Sector i, it is assumed that Sector i is attacked (qi(0) > 0) and other sectors are not initially perturbed (qj(0) = 0, j ≠ i). Applying Eq. (21), the recovery trajectory for Sector i becomes

q .

i(t) = −ki(1 − aii ∗)qi(0) (28)

The solution to Eq. (28) is

qi(t) = e −k

i (1 − a

ii

∗)qi(0) (29)

If it is assessed by experts that it takes Ti for Sector i to recover from its initial inoperability qi(0) > 0 (e.g., 100%) to a qi(Ti) (e.g., 1%) inoperability, the interde- pendency recovery rate can be assessed as Eq. (30), derived from Eq. (29):

ki = ln[qi(0) / qi(Ti)]

Ti  

1

1 − aii ∗    =

ωi Ti

=   

λ τ   i

 

1

1 − aii ∗    .

(30) Let the symbol ωi in Eq. (30) denote

ln[qi(0) / qi(Ti)]

1 − aii ∗

,

τ is the time when inoperability reduces to some value qτ , the recovery constant is λ, and collectively the ratio (λ/τ)i, representing the term ln[qi(0) / qi(Ti)] / Ti, is the recovery-rate parameter. The notation aii

∗ represents the ith diagonal element in the interdependency matrix A*. The smaller aii

∗ value, thus greater 1 – aii ∗ , indicates the

higher degree of dependence for the sector and hence faster recovery, taking into account interdependency with other sectors. Equation (30) implies that the greater aii

∗ leads to the greater interdependency recovery rate ki.

Therefore, the actual recovery rate ki of the ith sector is comprised of two components: its own recovery rate and its interdependency with other sectors. Due to its importance, the term 1 – aii

∗ is formally defined as the interdependency index for Industry i, denoted as θi, in

θi = 1 − aii ∗ . (31)

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 247

Systems Engineering DOI 10.1002/sys

To compare the degree of interdependency between the two arbitrary sectors of the economy, Sectors i and j, the ratio of their interdependency indices can be taken and defined as the interdependency ratio of Sectors i and j. It is denoted as ρij in

ρij = θi θj

= 1 − aii

1 − ajj ∗ . (32)

For the ith sector, we observe that its interdependency index θi, like the recovery rate λ/τ, also affects its recovery exponentially. Therefore, from the risk man- agement perspective, according to Eq. (30), if the inter- dependency index θi (or 1 − aii∗) of the ith sector can be decreased in the scenario of an terrorist attack or natural disaster, it will increase the interdependency recovery rate ki. This results in a quicker recovery, less economic loss, and fewer other losses. The reduction of a sector’s interdependency index can be achieved through various risk management options, including prevention efforts, adding redundancies, and many others.

5. MULTIOBJECTIVE FORMULATIONS

To manage risk, options must be adopted to affect either the recovery rate λ/τ or the interdependency index θi, or both, so that the interdependency recovery rate ki can be increased. This will speed up the recovery process and reduce potential losses during the recovery of the economy from an attack. In this context, the industry resilience coefficient matrix K can be viewed as the risk management investment coefficient matrix, which rep- resents the decision-maker’s willingness to invest in risk management. Therefore, this definition of K is comparable to the traditional definition of the capital investment coefficient matrix B in the economics litera- ture previously discussed and illustrated in Eq. (7).

If a finite set of n risk management options is defined as ri, i = 1, 2, …, n, and the cost function for risk management options is denoted as C = C((r1, r2, . . . , ri, . . . , rn)), a two-objective optimization problem can be formulated as in Eq. (33), and Pareto-optimal solutions [Haimes, 2004] can be generated for the risk-cost-bene- fit analyses using the DIIM. One or more risk manage- ment options can be chosen among the total n candidates.

Minimize r

1 ,r

2 ,...,r

i ,…r

n

Q = ∑ j=1

N

  

  x̂j ∫

0

qj(t, K(r1, r2, . . . , ri, . . . , rn)) dt   

  ,

Minimize r

1 ,r

2 ,...,r

i ,…r

n

C = C(r1, r2, . . . , ri, . . . , rn). (34)

In Eq. (33), the notation Q represents the total economic loss during the entire recovery period. For each sector of the economy, qj represents the inoperability and x̂j is its nominal output. Although the cost of risk manage- ment and the total economic loss are both measured in dollar units, they are treated as two noncommensurate objectives for a number of reasons. First of all, the sources of expense are different. The majority of the risk management cost most likely falls to the government, but the total loss will probably be spread among all industry sectors of the economy. In addition, risk man- agement is a deterministic investment in order to miti- gate the effects of a disaster or attack; however, the economic loss incurred during recovery has more un- certainties and usually involves stochastic distributions. Another important aspect is that in both risk manage- ment and loss from an attack, the economic metric is only one perspective. It is a surrogate of many other noncommensurate impacts, including political, social, and environmental considerations.

Equation (33) indicates that the overall economic loss is a function of the risk management investment coefficient matrix K. This functional relationship can be further specified by inserting Eq. (26) (the formula of the inoperability) into Eq. (33). A more explicit expression for the first objective in Eq. (33) can be derived in Eq. (34), in which the symbol I1×n represents a summation vector, which is an identity row-vector with the value 1 in each of the n columns. In Eq. (34), the risk management investment coefficient matrix K becomes the surrogate of the decision variable, which is manifested through the risk management options:

Minimize r

1 ,r

2 ,...,r

i ,…,r

n

Q =

I1×n[diag(x̂)(I − A ∗)−1K(r1, r2, . . . , ri, . . . , rn)

−1q(0)].

(34) It is evident from Eq. (34) that the total loss borne by the economy is a linear function of the reciprocals of the risk management investment coefficients. Moreover, a greater ki, i = 1, 2, …, n (the diagonal element of K) renders a smaller economic loss Q, with fixed nominal sector output, interdependency coefficients, and initial perturbations, Therefore, risk management options that result in higher values of the risk management invest- ment coefficients will reduce more of the overall eco- nomic loss following an attack. Equation (34) can be readily transformed into Eq. (35) by virtue of Eq. (30). Elements in the diagonal matrices diag(T) and diag(w) follow the same definitions as in Eq. (30):

Minimize r

1 ,r

2 , …,r

i ,...,r

n

Q =

248 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

I1×n[diag(x̂)(I − A ∗)−1diag(T(r1, r2, . . . ,

ri, . . . , rn))diag −1(w)q(0)] (35)

Equation (35) shows that in fact the overall economic loss incurred during the recovery is a linear function of the recovery times. Therefore, by shortening the recov- ery time of the attacked or damaged sectors, the overall economic loss can be reduced. In the following discus- sion, the matrix and vector notations are equivalently represented by their elements, which facilitate the inter- pretations of the multiobjective formulation at the sec- tor level. To this end, the matrix notations in Eqs. (34) and (35) are further simplified into more compact forms in Eqs. (36) and (37) respectively, as follows:

Minimize r

1 ,r

2 ,…,r

i ,…,r

n

Q =

∑ j=1

n   

 

  

  ∑ i=1

n

x̂idij   

 

qj(0) kj(r1, r2, . . . , ri, . . . , rn)

  

  , (36)

Minimize r

1 ,r

2 ,…,r

i ,…,r

n

Q =

∑ j=1

n   

 

  

  ∑ i=1

n

x̂idij   

  qj(0) ωj

Tj(r1, r2, . . . , ri, . . . , rn)   

  , . . . ,

(37)

where dij denotes the element in the ith row and jth

column of matrix (I – A*)–1. In Eqs. (36) and (37), if Sector j is not initially perturbed, qj(0) is zero; therefore, qj(0) disappears from the summation, leaving only those terms representing the sectors initially attacked. In Eq. (37), the overall economic loss is a linear function of the recovery times of the sectors initially affected by the attack, weighted by the term (∑i=1n x̂idij) qj(0) / ωj. The summation (∑i=1n x̂idij) represents the interdepen- dency of the economy, and the term measures qj(0)/ωj the degree of initial perturbation rendered by the attack. For example, if it is assumed that there are only two sectors, r and s, recovering from attacks and the risk management investment coefficients are the decision- variables in risk management, a multiobjective optimi- zation problem can be specified as in

Minimize r

1 ,r

2 ,...,r

i ,…,r

n

Q =

  

  ∑ i=1

n

x̂idir   

 

qr(0) kr(r1, r2, . . . , ri, . . . , rn)

+   

  ∑ i=1

n

x̂idis   

 

qs(0) ks(r1, r2, . . . , ri, . . . , rn)

,

Minimize r

1 ,r

2 ,...,r

i ,…,r

n

C = C(r1, r2, . . . , ri, . . . , rn).

Alternatively, this can be formulated in Eq. (39), where the recovery time of each sector is adopted as the surrogate of the decision variable:

Minimize r

1 ,r

2 ,…,r

i ,...,r

n

Q =

  

  ∑ i=1

n

x̂idir   

  qr(0) ωr

Tr(r1, r2, . . . , ri, . . . , rn)

+   

  ∑ i=1

n

x̂idis   

  qs(0) ωs

Ts(r1, r2, . . . , ri, . . . , rn),

Minimize r

1 ,r

2 ,...,r

i ,…,r

n

C = C(r1, r2, . . . , ri, . . . , rn). (39)

Equations (38) and (39) are multiobjective optimization problems that can be solved through a number of meth- ods, such as the Surrogate Worth Trade-Off (SWT) [Haimes, 2004]. Pareto-optimal solutions or the effi- cient frontiers for risk management can be derived to provide explicit tradeoffs and insights for the decision- makers. Note that, although the cost of risk manage- ment options is deterministic, the effectiveness and thus the efficacy of risk management is stochastic by its nature. In this multiobjective framework, the effective- ness of risk management is calculated through the de- terministic IIM as the reduced economic loss with risk management compared with the scenario if no risk management is deployed. Therefore, the deterministic effectiveness of risk management should be interpreted as the expected value of its actual stochastic distribu- tion. This multiobjective formulation for risk manage- ment is illustrated and discussed in more detail in the example in Section 7.

With the DIIM, a general risk management frame- work for an economic system is formulated in this section as multiobjective optimization problems. Deci- sion-makers need to balance the cost of risk manage- ment and its associated benefit, e.g., economic-loss reduction during the recovery period. Essentially, in the dynamic model, the implementation of more risk man- agement efforts results in a greater recovery rate for the economy sectors, which in turn shortens the recovery period and reduces potential damages. The system recovery is also a function of some random factors.

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 249

Systems Engineering DOI 10.1002/sys

6. AN ILLUSTRATIVE EXAMPLE: A TWO-INDUSTRY ECONOMIC SYSTEM

A two-industry economy example illustrates the theory and methodology of the DIIM, primarily to demon- strate its basic analytical concepts and procedures. Miller and Blair [1985] introduced the original static version of this example. In Table I, the numbers in the shaded cell are the amounts of commodities in mone- tary units (million of dollars) flowing between the industries. The third column represents the amount of the industries’ final demands and the third row of the table represents the amount of value added to the indus- tries. The last column and last row represent the total outputs and inputs of the industries.

It can be seen in the first column that Industry i uses a $150 million input from its own production as well as $200 million from the output of Industry j, and $650 million is the value added, which adds up to a total input of $1000 million for Industry i. The value added is measured as the sum of compensation of employees, taxes on production and imports less subsidies, and gross operating surplus [U.S. Department of Com- merce, BEA, 2005]. The first row shows that Industry i produces $150 million for its own internal intermediate consumption, $500 million as input to Industry j, and $350 million for its final demand. Therefore, the total output from Industry i equals its total input. The same is true for Industry j, and thus the entire economy is balanced (i.e., total input equals total output).

The commodity flow between the two industries in the shaded area of Table I can be denoted as matrix Z in

Z =   150 500 200 100

   . (40)

The Leontief technical coefficient matrix for the de- mand-side I–O model (A) is obtained by dividing each element of the commodity flow matrix (Z) by the respective column sum. For the two-industry example, this is constructed as Eq. (41). The symbols xm, xn are used to denote the total output of the industries and xmn represents the mth-row, nth-column element in ma- trix Z:

A = {xmn/xn} Wm,n =    150 / 1000 500 / 2000 200 / 1000 100 / 2000

  

=   0.15 0.25 0.20 0.05

   .

(41)

The normalized technical coefficient matrix A* used in the IIM is derived in Eq. (42) by applying Eq. (6):

A∗ =  

0.15 0.20(1000

2000 )

0.25(2000 1000

)

0.05    = 

 0.15 0.1

0.5 0.05

   .

(42)

The interdependency indices for the two industries can be calculated in Eq. (43) according to Eq. (31):

θi = 1 − aii ∗ = 0.15,

θj = 1 − ajj ∗ = 0.05. (43)

Therefore, it can be concluded from Eq. (43) that Indus- try i is three times more interdependent than Industry j. By its definition in Eq. (32), the interdependency ratio is 3 to 1.

This discussion can also be verified from the com- modity flows in Table I, in which half (500/1000) of Industry i’s total output is consumed by Industry j. However, only one-tenth (200/2000) of Industry j’s output is consumed by Industry i. Therefore, Industry i’s production is much more dependent on Industry j than vice versa. The interdependency index and inter- dependency ratio measure the degrees of interdepen- dency for the two industry sectors in this example.

6.1. Deterministic Demand-Reduction Dynamics

It is assumed in this case that the two industries are totally operable at time zero (qi(0) = qj(0) = 0), but there is a 10% demand reduction in Industry j (cj

∗ = 10%), which is causing the outputs of both industries to change. The system equations in (44) for this two-in- dustry economy can be derived according to Eq. (21) in its inoperability form:

  

qi(k + 1) − qi(k) = ki[0.15qi(k) + 0.5qj(k) + ci ∗ − qi(k)],

qj(k + 1) − qj(k) = kj[0.1qi(k) + 0.05qj(k) + cj ∗ − qj(k)].

(44) It is assumed for simplicity that the industry resilience coefficients for both industries are equal to 0.2 (ki = kj = 0.2). Their inoperability trajectories without risk management can be simulated in Figure 3 according to Eq. (44).

In Figure 1, Industry j’s inoperability increases ex- ponentially and stabilizes at around 11.2% at equilib-

Table I. Commodity Flow of a Two-Industry Economy (Millions of Dollars)

250 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

rium. Affected by the demand reduction in Industry j, Industry i also becomes inoperable and stabilizes with 6.6% inoperability. It can be verified that the inoper- abilities of the two industries at the equilibrium state are consistent with the results from the static demand-re- duction IIM model.

6.2. Deterministic Dynamic Recovery with Demand Reduction after Attacks

It is assumed that there is an attack on Industry j, which results in a 10% inoperability (qj(0) = 10%), but Indus- try i is not directly attacked (qi(0) = 0). It is assumed that the final demand reduction to Industry i is 0 (ci∗ = 0) and the final demand reduction to Industry j is 3% (cj∗ = 3%). If it is further assumed that ki = kj = 0.2, the dynamic recovery process with the final demand-reduc- tion scenario can be described in Figure 2 according to the simulation results from Eq. (44).

In Figure 2, Industry j recovers from its 10% inop- erability rendered by the attack and Industry i has become inoperable due to its interdependency with Industry j. However, the two industries cannot com- pletely recover to the totally operable state because of the demand reduction in Industry i. Their final inoper- abilities are determined by their demand reductions the same as they are in Section 6.1. It can again be verified that the final inoperabilities of the two industries at the

equilibrium state are consistent with the results from the static IIM.

6.3. Stochastic Recovery In the DIIM, the industry resilience deviation coeffi- cients are introduced to model the uncertainties of the industry resilience coefficients. The stochastic compo- nent in these equations is modeled through the Brownian motion, which reflects the short-term uncer- tainty of the industry recovery in contrast to the long- term exponential recovery process. Similar to the industry resilience coefficient, the industry resilience deviation coefficient also characterizes an economic sector during its recovery. To illustrate the stochastic aspect of the DIIM, the industry resilience deviation coefficients of the two industries are incorporated into this scenario. Furthermore, the industry resilience coef- ficients are derived from the recovery-time estimation instead of being directly given to the model as assump- tions. The following discussion describes the process.

Consider a terrorist attack scenario where Industry j is rendered 90% inoperable (10% operable) and Indus- try i is assumed to be not directly affected. Suppose that, due to some risk management actions, both industries can recover in 60 days from 100% inoperability to only 1%. From Eq. (30), the industry resilience coefficients for Industries i and j are calculated in

ki =   

λ τ   i

 

1

1 − aii ∗    = 0.0904,

kj =   

λ τ   j

 

1

1 − ajj ∗    = 0.0808, . . . , (45)

where 1 − aii∗ = 0.15, (λ / τ)i = 0.0136, 1 − ajj∗ = 0.05, and (λ / τ)j = 0.004. For both industries, the industry resil- ience deviation coefficients are assumed for simplicity to be half of their industry resilience coefficients in value (σi = 0.5ki, σj = 0.5kj). The system equations for this scenario can be formulated in Eq. (46) if the DIIM model in Eq. (9) is applied:

  

xi(t + ∆t) − xi(t) = [aiixi(t) + aijxj(t) + ci(t) − xi(t)][ki∆t + σi εi(t)√∆t ], xj(t + ∆t) − xj(t) = [ajixi(t) + ajjxj(t) + cj(t) − xj(t)][kj∆t + σj εj(t)√∆t ].

(46)

In Eq. (46), εi(t) and εj(t) are two independent random variables with standard normal distributions N(0,1), and the time increment ∆t is assumed to be 0.25 day. Through simulation, the recovery process of the two industries is depicted in Figure 3. For this scenario, the final demand of the economy is assumed to be constant. The outputs are measured in monetary units, although

Figure 1. Inoperability dynamics for demand-reduction sce- nario.

Figure 2. Sector recoveries with final demand reduction.

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 251

Systems Engineering DOI 10.1002/sys

they can be transformed into the inoperability form through Eq. (2).

In Figure 3, Industry j begins to recover right after the attack. Industry i is affected due to its interdepen- dency with Industry j, even though it is not directly attacked. When equilibrium is reached, Industries i and j are totally operable with their output levels at $1000 million and $2000 million, respectively. Unlike in the previous scenarios, the trajectories in Figure 3 are not smooth. This is caused by the short-term uncertainty during the recovery, modeled in the DIIM. The stochas- tic model therefore depicts the recovery of the eco- nomic sectors as an exponential form in the long run, combined with the stochastic characteristics in the short run. Figure 3 also reflects that, for both sectors, the degrees of uncertainty are higher at the beginning of the recovery period than they are in the later periods to- wards the end. In the final analysis, the stochastic component, as a supplementary parameter to the indus- try resilience coefficient in the DIIM, not only facilitates measuring recovery uncertainty for the economy sec- tors, it also enhances the detailed modeling capability of the DIIM.

7. ASSESSING AND MANAGING THE RISK OF A TERRORIST ATTACK TO INFRASTRUCTURE SYSTEMS USING THE DIIM AND THE BEA/RIMS II DATABASES

One advantage of using the IIM and the DIIM for interdependency analysis of economic sectors is that the underlying transaction data are readily available and supported by major ongoing data-collection efforts. The Bureau of Economic Analysis (BEA) of the U.S. Department of Commerce provides national I–O ac- counts, which can be used to generate the Leontief technical coefficient matrix for nearly 500 sectors of the U.S. economy. The Regional Input-Output Multiplier System (RIMS II) supplements and complements the national I–O account. It can be used to derive the Leontief technical coefficient matrix for economic sec- tors within a specific region. In the following example, the DIIM is applied to assess and manage the risks of a terrorist attack scenario using the BEA/RIMS II data- bases for the Commonwealth of Virginia.

7.1. Risk Assessment of Infrastructure Systems Using the DIIM

From the BEA/RIMS II data, the technical coefficient matrix A or A* can be generated for Virginia using the methods in Haimes et al. [2005a, 2005b]. From A*, the interdependency index of each sector can be calculated by Eq. (21). Table II lists the Interdependency Index for some sectors and their ratios with the truck transporta- tion sector.

The results in Table II show that the air transporta- tion and hospital and nursing sectors are among the most interdependent sectors in Virginia, while the in- surance and broadcasting sectors are comparatively less interdependent with other sectors of the economy. The Interdependency Ratio over Truck Transportation Sector column shows the relative degree of sector inter- dependency compared with truck transportation. Ac- cording to Table II, the insurance and broadcasting

Figure 3. Recovery of the industry sectors, with uncer- tainty.

Table II. Sector Interdependency Index Examples and Ratios with Truck Transportation (Virginia)

252 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

sectors are less interdependent on the truck transporta- tion sector than are other sectors.

To illustrate the DIIM method using the Virginia regional data from BEA/RIMS II, we assume that a terrorist attack renders 20% inoperability to the truck transportation sector, 50% inoperability to the broad- casting and telecommunications sector, and 60% inop- erability to the utilities sector. We assume that other sectors are initially unaffected in this scenario, and that no risk management was implemented. Individual sec- tor recovery times for these three sectors, from initial inoperability after the attack to 1% inoperability, are assessed as follows: 60 days for truck transportation, 30 days for broadcasting and telecommunications, and 10 days for utilities. According to the given assump- tions above, the industry resilience coefficient of the truck transportation sector can be calculated according to Eq. (29) as

kt = ln[qt(0) / qt(T)]

T

1

1 − at,t ∗

= 0.0557/day, . . . , (47)

where T = 60, qt(0) = 0.2, qt(T) = 0.01, and 1 – at,t ∗ =

0.1037. The symbol kt represents the resilience coeffi- cient of truck transportation. In this scenario, the sub- scripts t, b, a n d u are used to notate the truck transportation, broadcasting and telecommunications, and utilities sectors, respectively. The resilience coeffi- cients for the broadcasting and telecommunications and utilities sectors are calculated as kb = 0.1682/day and ku = 0.4124/day using the approach shown in Eq. (47). Since other sectors of the economy are not directly attacked, it is assumed that they can quickly adjust their outputs during the recovery period; therefore, for sim- plicity their coefficient values are set to 1 in this sce- nario.

Table III. Top 10 Inoperable Sectors in the Attack Scenario

Figure 4. Recovery of the top 5 inoperable sectors.

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 253

Systems Engineering DOI 10.1002/sys

Applying the DIIM in the inoperability form as in Eq. (19), the top 10 inoperable sectors can be deter- mined and presented through simulation in Table III.

The detailed recoveries of the five most-affected sectors are depicted in Figure 4. Truck transportation, broadcasting and telecommunications, and utilities be- gin to recover from their initial inoperabilities after the attack. Though not directly attacked, other sectors that are interdependent with these three are also affected and inoperable during the recovery period. Through the DIIM, the recovery process of the interdependent sec- tors of the economy is modeled more explicitly. The inoperability of each sector can be obtained through the model at any time during the recovery.

Another supplementary metric that can be used to assess the consequences of the attack scenario shows the economic losses in dollar units during the recovery. Figure 5 depicts the cumulative economic loss for the top five most-affected sectors over a 60-day period.

Table IV lists the total economic loss for the sectors, including those in Figure 5, after 60 days.

It is important to note that comparing Tables III and IV reveals that the severity rankings based on inoper- ability and economic loss are not necessarily identical. For example, the professional, scientific, and technical services sector is the third most-affected sector in terms of economic loss, but it is not in the top 10 list of sectors based upon the inoperability measure. Therefore, both

Figure 5. Cumulative economic loss of the top 5 affected sectors.

Table IV. Top 10 Sectors Having Economic Losses in the Attack Scenario

254 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

inoperability and economic loss metrics are important for the development of risk management options.

7.2. Risk Management of Infrastructure Systems Using the DIIM

Based on the risk assessment, the risk management options are considered and the multiobjective optimi- zation framework discussed in Section 4 is applied in this scenario to illustrate the cost-benefit tradeoff analy- sis and risk management efficacy calculation. This tradeoff analysis is enhanced through the deterministic DIIM by considering the economic impacts of an attack with and without risk management [Haimes and Chit- tester, 2005]. It is assumed that there are three risk management scenarios to reduce the recovery time of the truck transportation and broadcasting and telecom- munications sectors in this case study: (i) Risk manage- ment option rt, cost $19.9M, can reduce the recovery time of truck transportation from 60 days to 30 days. (ii) Risk management option rb, cost $75.6M, can re- duce the recovery time of broadcasting and telecommu- nications from 30 days to 10 days; and (iii) rt and rb can be combined. For simplicity, it is assumed that no risk management options are considered for the utilities sector in this scenario.

From Eq. (36), the economic losses for these three scenarios can be estimated by

Q =   

  ∑ i=1

n

x̂idit   

  qt(0) ωt

Tt(rt, rb) +   

  ∑ i=1

n

x̂idib   

  qb(0) ωb

Tb(rt, rb)

+   

  ∑ i=1

n

x̂idiu   

  qu(0) ωu

Tu. (48)

In summary, the economic loss, recovered economic loss, and the cost of risk management are presented for each of the three risk management options in Table V. The risk management costs are given by the assump- tions. When no risk management is taken, the overall economic loss can be derived by Eq. (48), where Tt(rr, rb) = 60 days and Tb(rt, rb) = 30 days. When risk management options rt and rb are considered, the recov- ery times for truck transportation and broadcasting and telecommunications sectors are reduced to 30 days and 10 days, respectively, in Eq. (48), and thus reduce the overall economic losses. The combination of rt and rb is also considered. The recovered economic loss in Table V is defined as the overall economic loss without

Table V. Costs and Benefits of the Three Risk Management Options

Figure 6. Costs and overall economic losses of the risk management options.

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 255

Systems Engineering DOI 10.1002/sys

risk management, minus its value when various risk management options are in place.

Figure 6 further illustrates the tradeoffs between the costs of risk management and its benefits (recovered economic losses). For example, the three options pre- sented in this case study are all Pareto-optimal solu- tions. Among them, (rt + rb) can recover most losses with the “no risk management” scenario, but it requires the highest risk management investment.

8. CONCLUSIONS

This paper discusses the theory, methodology, and ap- plications supporting the development of the DIIM. As an extension of the IIM, the DIIM captures the dynam- ics of the economic sector when there is a demand-re- duction perturbation or an interruption caused by an attack or a natural disaster. Two basic categories of dynamic scenarios using the DIIM are addressed: (i) demand reduction and (ii) the recovery of sectors from attacks. The DIIM uses two measures—inoperability and economic loss—to quantify the consequences of risks. Thus, it provides important metrics for quantify- ing the efficacy of risk management. An interdepen- dency index is also defined, as a measurement of one sector’s interdependency with other sectors. Industry resilience coefficients are introduced into the DIIM as key parameters which characterize both the sectors’ recovery speeds and the degrees of interdependency among them. These coefficients can be estimated through specific industry historical databases available or through expert opinions. One approach in this paper used surrogates for estimates of recovery times to cal- culate the industry resilience coefficients. In the event of disasters or terrorist attacks, the recovery time and the resilience coefficients are also affected by the de- ployment of risk management and public policies. Therefore, the industry resilience coefficients can rep- resent the efficacy of risk management efforts that are planned for each of the sectors. Cost-benefit-risk trade- off analyses can be conducted based upon the model and the framework proposed in this paper. One applica- tion of the DIIM is to assess the consequences to the economic system of a terrorist attack or natural disaster, using the BEA/RIMS II commodity-flow databases. As the example showed, the DIIM can calculate the inop- erabilities and economic losses for each of the sectors throughout a given recovery period.

The IIM and its dynamic model retain several as- sumptions and limitations inherited from the original Leontief I-O structure. These include linearity, lack of behavioral content, lack of substitution possibilities, and others [Rose, 2004]. Therefore, in order to generate

meaningful results in practice, the assumptions need to be verified to ensure the applicability of the model. Another limitation of the IIM and DIIM is that the models primarily deal with economic losses and asso- ciated risks; however, there are many other aspects of risk that are not directly reflected. These include life losses, personal freedom loss due to political changes, losses due to insurance, injuries, and changes in the international political landscape. In future research, the dynamic model can be expanded to include the transient period during the attack, which generates inputs to the recovery period that is addressed by the DIIM in this paper. In the current model, the capacity loss due to a major disruption is simplified as decreasing output. Therefore, another improvement of the model is to include capacity and resource constraint in major dis- ruptions. The paper introduces the concept of a not-un- likely event in the context of a single terrorist attack. Although this is a reasonable assumption, we recognize that it is difficult to predict under various assumptions all terrorist scenarios as well as their implications. To better understand the nature of a terrorist threat, it is imperative to identify the possible consequences of terrorist attacks to specific infrastructure systems. In future research, optimization of terrorist scenarios will also be incorporated in the proposed model to obtain more accurate results.

ACKNOWLEDGMENTS

This study is supported by the National Science Foun- dation, under a grant to the University of Virginia Center for Risk Management of Engineering Systems (NSF 0301553: Input-Output Risk Model of Critical Infrastructure Systems, May 2003-January 2006). This study is also supported by a grant from the Institute for Information Infrastructure Protection (I3P) under grant 2003-TK-TX-0003 from the Office of Domestic Pre- paredness of the US Department of Homeland Security. Points of view in this document are those of the authors and do not necessarily represent the official position of the US Department of Homeland Security of the Office of Domestic Preparedness. We are thankful for the reviewers’ comments and suggestions. Additionally we are thankful for the valuable inputs contributed by Dr. Joost Santos and Kenneth Crowther. We also highly appreciate the editorial assistance of Grace Zisk.

REFERENCES

G.E. Apostolakis and D.M. Lemon, A screening methodology for the identification and ranking of infrastructure vulner- abilities due to terrorism, Risk Anal 25 (2005), 361–376.

256 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys

E. Asbeck and Y.Y. Haimes, The partitioned multiobjective risk method, Large Scale Syst 6 (1984), 13–38.

M. Blanc and C. Romos, The foundations of dynamic input- output revisited: Does dynamic input-output belong to growth theory, http://www19.uniovi.es/econo/Documen- tosTrabajo/2002/258-02.pdf, 2002, last accessed April 6, 2004.

Congress Research Service (CRS), High Altitude Electro- magnetic Pulse (HEMP) and High Power Microwave (HPM) devices: Threat assessment, http://www.fas. org/man/crs/RL32544.pdf, 2004, last accessed August 2004.

K.G. Crowther and Y.Y. Haimes, Application of the inoper- ability input-output model (IIM) for systemic risk assess- ment and management of interdependent infrastructures, Syst Eng 8 (2005), 323–341.

C.H. Edwards and D.E. Penney, Elementary differential equa- tions with boundary value problems, 4th edition, Prentice Hall, Englewood Cliffs, NJ, 2000.

B.V. Gnedenko, The theory of probability, 2nd edition, Chel- sea, New York, 1963.

Y.Y. Haimes, Hierarchical analyses of water resources sys- tems: Modeling and optimization of large-scale systems, McGraw-Hill, New York, 1977.

Y.Y. Haimes, Hierarchical holographic modeling, IEEE Trans Syst Man Cybernet 11 (1981), 606–617.

Y.Y Haimes, Risk modeling, assessment, and management, 2nd edition, Wiley, New York, 2004.

Y.Y. Haimes and C.G. Chittester, A roadmap for quantifying the efficacy of risk management of information security and interdependent SCADA systems, J Homeland Secu- rity Emergency Management 2 (2005), 1–21.

Y.Y. Haimes and P. Jiang, Leontief-based model of risk in complex interconnected infrastructures, J Infrastructure Syst 7 (2001), 1–12.

Y.Y. Haimes and W.S. Nainis, Coordination of regional water resource supply and demand planning models, Water Re- sources Res 10 (1974), 1051–1059.

Y.Y. Haimes, N.C. Matalas, J.H. Lambert, B.A. Jackson, and J.F.R. Fellows, Reducing the vulnerability of water supply systems to attack, J Infrastructure Syst 4 (1998), 164–177.

Y.Y Haimes, B.M. Horowitz, J.H. Lambert, J.R. Santos, C. Lian, and K.G. Crowther, Inoperability input-output model (IIM) for interdependent infrastructure sectors: Theory and methodology, J Infrastructure Syst 11 (2005a), 67–79.

Y.Y Haimes, B.M. Horowitz, J.H. Lambert, J.R. Santos, K.G. Crowther, and C. Lian, Inoperability input-output model (IIM) for interdependent infrastructure sectors: Case study, J Infrastructure Syst 11 (2005b), 80–92.

U. Krause, Path stability of prices in a nonlinear Leontief model, Ann Oper Res 37 (1992), 141–148.

M.L. Lahr and E. Dietzenbacher, Input-output analysis: Fron- tiers and extensions, Palgrave, New York, 2001.

K.S. Lee, A generalized input-output model of an economy with environmental protection, Rev Econom Statist 64 (1982), 466–473.

W.W. Leontief, Input-output economics, Sci Am (October 1951a), 15–21.

W.W. Leontief, The structure of the American economy, 1919–1939: An empirical application of equilibrium analysis, 2nd edition, International Arts and Sciences Press, New York, 1951b.

W.W. Leontief and F. Duchin, The future impact of automat- ion on workers, Oxford University Press, New York, 1986.

W.W. Lowrance, Of acceptable risk, William Kaufmann, Los Altos, 1976.

D.G. Luenberger, Investment science, Oxford University Press, New York, 1998.

R.E. Miller and P.D. Blair, Input-output analysis: Foundations and extensions, Prentice-Hall, Englewood Cliffs, NJ, 1985.

J.R. Olsen, P.A. Beling, J.H. Lambert, and Y.Y. Haimes, Leontief input-output model applied to optimal deploy- ment of flood protection, J Water Resource Plan Manage- ment, 124 (1997), 237–245.

M.E. Paté-Cornell and S. Guikema, Probabilistic modeling of terrorist threats: A systems analysis approach to setting priorities among countermeasures, Mil Oper Res 7 (2002), 5–20.

J.L. Proops, Modeling the energy-output ratio, Energy Econom 6 (1984), 47–51.

A. Rose, “Economic principles, issues, and research priorities in hazard loss estimation,” Modeling spatial and economic impacts of disasters, Y. Okuyama and S. Chang (Editors), Springer, New York, 2004, pp. 13–36.

A. Rose, J. Benavides, S.E. Chang, P. Szczesniak, and D. Lim, The regional economic impact of an earthquake: Direct and indirect effects of electricity lifeline disruptions, J Regional Sci 37 (1997), 437–458.

A.P. Sage, Methodology for large-scale systems, McGraw- Hill, New York, 1977.

J.R. Santos and Y.Y. Haimes, Modeling the demand reduction input-output (I-O) inoperability due to terrorism of inter- connected infrastructures, Risk Anal 24 (2004), 1437– 1451.

U.S. Department of Commerce, Bureau of Economic Analy- sis (BEA), Glossary index, http://www.bea.gov/bea/ glossary/glossary_v.htm#value_added, 2005, last ac- cessed November 14, 2005.

MANAGING RISK OF TERRORISM TO INTERDEPENDENT INFRASTRUCTURE SYSTEMS VIA DIIM 257

Systems Engineering DOI 10.1002/sys

Chenyang Lian is a Ph.D. candidate at the University of Virginia. He received a Bachelor of Engineering degree from Tsinghua University, Beijing (2000) and a Master of Science in Computer Engineering from the University of Michigan—Dearborn (2003). Before he came to the University of Virginia, he worked as a residual value analyst for MSX, international in Michigan (2003). He is a member of IEEE and Society for Risk Analysis. He is a certified advanced SAS programmer.

Yacov Y. Haimes, Professor of Systems and Information Engineering at the University of Virginia, is the Founding Director (1987) of the University of Virginia’s Center for Risk Management of Engineering Systems, and holds the Lawrence R. Quarles Professorship in the School of Engineering and Applied Science. He is a member of the Systems and Information Engineering and Civil Engineering faculties. On the faculty of Case Western Reserve University for 17 years, he was Chair of the Systems Engineering Department. During the 1977–1978 sabbatical year, he was an AAAS/AGU Congressional Science Fellow, joining the staff of the Executive Office of President Carter, and later the staff of the House Science and Technology Committee. He is the recipient of several major awards in his field, including the Norbert Weiner Award from IEEE Systems, Man & Cybernetics, the Distinguished Achievement award from the Society for Risk Analysis, the Georg Cantor Award from the International Society on Multiple Criteria Decision Making, and the Warren A. Hall Medal from the Universities Council on Water Resources. He is a Fellow of the following professional societies: AAAS, IEEE, ASCE, AWRA, IWRA, INCOSE, and the Society for Risk Analysis (SRA). He also served as President of SRA. He has authored/co-authored six books and edited 20 conference proceedings; He has published more than 260 articles and technical papers, over 160 of which are in archival-refereed journals, and more than 100 in encyclopedia and in nonarchival journals. His most recent book is Risk Modeling, Assessment, and Management, Second Edition (Wiley, New York, 2004). He has worked extensively with the military and domestic agencies on boards and projects.

258 LIAN AND HAIMES

Systems Engineering DOI 10.1002/sys