Review on Energy Resilience

profileharsh55
Modeling-cascading-failures-in-interdependent-in_2016_Reliability-Engineerin.pdf

Reliability Engineering and System Safety 147 (2016) 1–8

Contents lists available at ScienceDirect

Reliability Engineering and System Safety

http://d 0951-83

n Corr Technol

E-m

journal homepage: www.elsevier.com/locate/ress

Modeling cascading failures in interdependent infrastructures under terrorist attacks

Baichao Wu a,b,n, Aiping Tang a, Jie Wu c

a School of Civil Engineering, Harbin Institute of Technology, 73 Huanghe Road, Harbin 150001, PR China b School of Civil Engineering, Northeast Forestry University, 26 Hexing Road, Harbin 150040, PR China c College of Environmental and Chemical Engineering, Heilongjiang University of Science and Technology, 2468, Puyuan Road, Harbin 150022, PR China

a r t i c l e i n f o

Article history: Received 19 May 2015 Received in revised form 7 October 2015 Accepted 12 October 2015 Available online 10 November 2015

Keywords: Cascading failure Critical infrastructures Infrastructure vulnerability Interdependencies Terrorist attacks

x.doi.org/10.1016/j.ress.2015.10.019 20/& 2015 Elsevier Ltd. All rights reserved.

esponding author at: School of Civil Engi ogy, 73 Huanghe Road, Harbin 150001, PR Ch ail address: [email protected] (B. Wu).

a b s t r a c t

An attack strength degradation model has been introduced to further capture the interdependencies among infrastructures and model cascading failures across infrastructures when terrorist attacks occur. A medium-sized energy system including oil network and power network is selected for exploring the vulnerabilities from independent networks to interdependent networks, considering the structural vulnerability and the functional vulnerability. Two types of interdependencies among critical infra- structures are involved in this paper: physical interdependencies and geographical interdependencies, shown by tunable parameters based on the probabilities of failures of nodes in the networks. In this paper, a tolerance parameter α is used to evaluation of the overloads of the substations based on power flow redistribution in power transmission systems under the attack. The results of simulation show that the independent networks or interdependent networks will be collapsed when only a small fraction of nodes are attacked under the attack strength degradation model, especially for the interdependent networks. The methodology introduced in this paper with physical interdependencies and geographical interdependencies involved in can be applied to analyze the vulnerability of the interdependent infra- structures further, and provides the insights of vulnerability of interdependent infrastructures to miti- gation actions for critical infrastructure protections.

& 2015 Elsevier Ltd. All rights reserved.

1. Instruction

With the advancement information technology, modern critical infrastructure systems are increasingly coupled and mutually depend on each other to provide essential functionality for social stabilization and economic prosperity. Most of these infrastructure systems are networked in nature and interdependent in complex ways, which means that failure of nodes in one network may lead to failure of dependent nodes in other networks, and the proce- dure may occur recursively, resulting in a cascade of failures of infrastructure systems. Cascading failures of critical infrastructure systems caused by recent disasters, ranging from large-scale power outages, to terrorist attacks, hurricanes and earthquakes, have exhibited highly vulnerabilities existing in interdependencies across critical infrastructure systems. Examples of significant cas- cading failures are the Northeast American power blackout in 2003 [1] and the terrorist attacks on the US in 2001.

neering, Harbin Institute of ina. Tel.: þ86 18045117728.

In the past few years, many researchers have paid much attention to the problem of interdependencies existing in critical infrastructure systems. Several frameworks and methods for characterizing and analyzing interdependencies among critical infrastructures have been suggested. One of the most cited fra- meworks proposed by Rinaldi et al. identified four categor- ies of critical infrastructure interdependencies: (1) geographical; (2) physical; (3) cyber; and (4) logical [2]. Many efforts are cur- rently being devoted to developing models or methods attempting to capture the interdependencies among critical infrastructures. An over view of methods and models are summarized in some literatures [3–6]. Those methods are divided into two coarse categories – the empirical approaches and the predictive approa- ches [7]. Empirical approaches aim at studying past events in order to increase our understanding of infrastructure dependen- cies [8], and predictive approaches include Leontief input–output model [9–17], agent based model [18–23], system dynamics model [24] network based model [7,25–38], and others [39–49]. Although the existing methods and models based on different viewpoints have their own merits and drawbacks discussed and summarized in some literatures [5,37], they are necessary in order

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–82

to appropriately and comprehensively address the issue of inter- dependencies, meaning there is no universal, all-encompassing model, which is supported by some literatures [7,40]. However some progresses have been made in modeling interdependencies among infrastructures, the challenges for modeling and under- standing of interdependencies among infrastructures are imm- ense, and the current efforts in this field are still in an early stage.

The terrorist attacks on critical infrastructures is one of the hot issues of modeling interdependencies among infrastructures, there are a few literatures attempting to capture the interdependencies based on a strategy of removing most connected node or most betweenness node or most flow edge [7,29,31,37,50]. Although the topology prop- erties along with function properties of infrastructures and physical interdependencies among infrastructures are concerned by the pre- vious studies, nearly all of them did not propose proper models or methods to model the geographical interdependencies among infra- structures which must be considered under terrorist attacks with specified site coordinates and specified affected ranges. There are a few literatures concerning about the geographical interdependencies among infrastructures and some meaningful frameworks are pro- posed [51,52]. The framework of Ref. [51] employs Monte Carlo net- work analysis and geographic analysis methods under a grid size to identification of critical locations across multiple infrastructures, while physical interdependencies among infrastructures have not been included which will underestimate the vulnerabilities of the coupled infrastructures. The method of Ref. [52] considers geographically localized attacks from the perspective of percolation theory and the results of the method demonstrates the potential high risk of localized attacks on spatially embedded network systems when dependencies considered, while the physical roles of nodes in individual infra- structure have not concerned, and within the range of each attack all nodes will be removed from the network which is not actual in ter- rorist attacks or explosions of dangerous chemicals.

To solve those problems mentioned above, a new attack model is introduced in this paper to further explore the vulnerabilities of critical infrastructures, especially when interdependencies are concerned.

This paper proposed an attack strength degradation model to model terrorist attacks, and the model not only considers the topology properties and function properties of critical infra- structures, but also includes the physical interdependencies and geographical interdependencies among critical infrastructures; a medium-sized energy system including oil network and power network is selected, the topologies of the two networks are extracted based on graph theory, and the roles or functions of different nodes of the extracted networks are also considered. To model the interdependencies between the oil network and the power network, geographical proximity is employed to establish the physical interdependencies defined by conditional prob- abilities of failure between the two networks before an attack, while the geographical interdependencies among critical infra- structures are provided after an attack by failure probabilities based on distance to disturbance center. Under the attack model, the vulnerabilities of the two networks are investigated under different coupling strengths among networks.

This paper is divided into five main sections. The second sec- tion introduces fundamental concepts and definitions from graph theory, as well as the definitions of the parameters used to char- acterize structural and functional vulnerabilities of the two net- works. The third section defines the attack strength degradation model and introduces the basic topologies of the two networks. The fourth section provides the results of the two networks responses under different coupling strengths among them, and the results under different strength of interdependencies are also discussed. Finally, the last section presents the main conclusions of this study and future works are proposed.

2. Definitions for evaluations the vulnerabilities of infra- structure systems

Infrastructure systems can be modeled as a directed graph G¼ (V,E) where V is the set of vertices V(G) that represent all the individuals and E is the set of edges E(G) that represent all the physical and dependency connections. The number of vertices in V (G) is termed the order N of the graph or |G|, and the number of edges in E|G| is termed its size M or ||G|| [53]. The vertex degree, d(v), of a vertex vV(G), is defined as the number of incoming and out- going edges connected to the vertex v. Vertex betweenness, b(v), of a vertex vAV(G), is defined as the total number of shortest paths between all pairs of vertices (i, j )AV(G) that pass through the vertex v, which is not an end for any path. The d(v) or b(v) of the network can be used for evaluation importance of a vertex of G when different removed strategy imposed.

The vulnerabilities of infrastructure networks can be learned from the decline of service rates after disturbances compared to the initial ones. Some network characteristics used in this study will be given in the next.

2.1. Service rate based on topology

The service level of an infrastructure network can be analyzed by the sum of edges based on topology of the network simply. For comparison with the initial service level, the poster service level of the network after a disturbance, the service rate based on topol- ogy, SRt, is defined as follows:

SRt ¼ ‖G‖poster ‖G‖initial

ð1Þ

where the poster means after the disturbance, and initial means before the disturbance, obviously, 0rSRtr1.

2.2. Service rate based on flow

The SRt can be used for the evaluation of vulnerability of the infrastructure network, while not detecting the differences based on the actual functions or roles of the nodes in the network. For instance, the functions or roles of the nodes in power network or oil network can be classified as generation, distribution and transmission, which must be considered in the evaluation of the vulnerabilities of the infrastructure networks. To solve the pro- blem mentioned above, the service rate based on flow, SRf, is defined as follows:

SRf ¼ P

‖clustersGi ‖posterP ‖clustersGj ‖initial

ð2Þ

where the clustersGi is the ith connected subgraph of G and includes at least one generation node and one distribution node. Obviously, 0rSRf r1.

2.3. Service rate based on network efficency

To compare the results of vulnerabilities based on the SRt and SRf, the network efficiency [54], E, the mean of inverse path length, is given in this paper. Service rate based on E, SRE, is defined as follows:

E ¼ 1 NðN�1Þ

X

i;jAV;ia j

1 dij

SRE ¼ Eposter Einitial

ð3Þ

where N is the order of G, dij is the shortest path from vertice i to vertice j, 0rSREr1.

Fig.1. Topological structure of the selected networks: (a) oil network; and (b) power network.

Table 1 Topological properties of the power network and oil network.

Network Network order, n

Network size, m

Generation node sum

Distribution node sum

Transmission node sum

Power network

218 299 5 187 26

Oil net- work

403 411 343 11 49

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–8 3

2.4. Interdependency Amplification

The Interdependency Amplification, IA, is used for evaluation of interdependency amplification effects when two and more inter- dependent infrastructures are disturbed under different coupled levels, given as follows:

IA ¼ NetworkSRindependency �Network SR interdependency ð4Þ

where NetworkSRIndependency represents the service rate mentioned above considering interdependencies among critical infrastructures, while representing the service rate mentioned above based on independency.

3. Attack strength degradation model and infrastructure networks

3.1. Infrastructure networks

Two real infrastructure networks, the power transmission grid and the oil transmission system in Saertu County, Daqing City, Hei- longjiang Province of China are taken as an example to explore their independent and interdependent response when disturbances occur- red. The function role of nodes in the power network includes gen- eration, substation and distribution; while the function role of nodes in the oil network includes storage, production, and transmission. The

topologies of the selected networks and the roles of their elements are shown in Fig. 1 and the topological properties of the networks are summarized in Table 1.

As shown in Fig.1, the correspondence between the power network and oil network is based on the roles of nodes in each network, the generation corresponding to the production, the distribution corresponding to the storage, and the substation corresponding to the transmission. For consistency and con- sideration of the role in each network, the roles of nodes in two networks are classified into generation, distribution and transmission. Based on the roles mentioned, the power network or oil network is modeled as a directed graph respectively in this study.

Fig.2. Attack strength degradation model.

Fig. 3. Power network characteristics based on the recalculated max d(v) under the attack with α¼0.1.

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–84

3.2. Attack strength degradation model

Attack strength degradation model proposed in this paper is defined as follows:

Attackstrengthnodei ¼ Attack strength center � log ð1þDiÞ ð5Þ

where Attackstrengthcenter is the attack strength of the attack center, AttackcenterZ0; Di is horizontal distance from nodei to the attack center, expressed in km; Attackstrengthnodei represents the attack strength at the ith node of the network. Fig. 2 shows the impact range of a attack under the attack strength degradation model, where a node is selected as the attack center, and the maximum radius of the impact range equals 1.718 km under the assumption that equals 1. Based on the attack strength degradation model, the nodes of networks in the impact range may be affected by the attack, and the attack strengths of the affected nodes are degraded from 1 to 0, which can be used for evaluation of the geographical interdependencies after the attack. In this paper, the geographical interdependencies based the attack strength degradation model are defined as follows:

Pf ailurenodei ¼ Attack strength nodei

ð6Þ

where Pf ailurenodei is failure probablity of the ith node, 0rP f ailure nodei

r1; when Attackstrengthnodei Z1, P

f ailure nodei

¼1; when Attackstrengthnodei r0, P f ailure nodei

¼0.

Fig. 4. Power network characteristics based on the recalculated max b(v) under the attack with α¼0.1.

4. Networks responses under the attack strength degradation model

4.1. Independent networks responses

The independent responses of power network and oil network under the attack strength degradation model are analyzed in the paper. Based on importance of vertex, the vertex with max degree d(v) or max betweenness b(v) is selected as the attack center by the model respectively, which means each attack aim at the node with recalcu- lated max d(v) or b(v) in the remained network. Additionally, the vertex betweenness b(v) is used as an approximation of the load L(v) that flows through each vertex v. It is assumed that the capacity of the nodes C(v) is proportional to the initial load L(v*) [55], given as follows:

CðvÞ ¼ ð1þαÞLðv�Þ ð7Þ where αZ0 is the tolerance parameter for the substations of the power network. When each attack on power network occurred, due to change of topology, when the actual L(v) is larger than its C(v), the vertex v is removed from the power network. The process is repeated until the L(v) of each vertex is no larger than the cor- responding C(v) in the power network.

The attack on the power network or the oil network is based on assumption that equals 1, the tolerance α of power network equals 0.1. Based on the selected node with recalculated max d(v) or b(v), the attack under on the mentioned model is repeated until there is no nodes in the network. The process is executed ten times inde- pendently and the average results of ten times are given in the next.

The results of the attack on power network under the men- tioned model are shown in Figs. 3 and 4, and the corresponding results of oil network are shown in Figs. 5 and 6. As shown in Fig. 3, the SRt of power network drops quickly from 1 when no attack occurs to 0.312 when attack times/N¼0.1; the SRf of power network decrease more quickly than the SRt from 1 to 0.006; and the SRE of power network shows similar decrease trends. Com- pared with results of Fig. 3, the results in Figs. 4–6 show similar decrease trends. The results obtained above show that the net- works are high vulnerabilities under the attack when only a small fractions of nodes are selected as the targets under the attack strength degradation model. Compared with the SRt and SRE, the SRf exhibits higher susceptibility to the vulnerabilities of the independent infrastructures under the attack.

Fig. 5. Oil network characteristics based on the recalculated max d(v) under the attack.

Fig. 6. Oil network characteristics based on the recalculated max b(v) under the attack.

Fig. 7. Oil network SRt based on the recalculated max b(v) under the attack.

Fig. 8. Oil network SRE based on the recalculated max b(v) under the attack.

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–8 5

4.2. Interdependent networks responses

In this paper, the vulnerabilities of the oil network are analyzed in view of the interdependencies between the two networks, considering two types of interdependencies: the physical inter- dependencies and the geographical interdependencies. Physical interdependencies exist between the power network and the oil network actually, the nodes in the oil network needing electric power provided by the power network for the normal operations of the oil network. In this study the physical interdependencies between the two networks are established based upon geo- graphical proximity. Based on the physical interdependence of oil network on power network, a set of conditional probabilities of failure is established and it is expressed as follows:

PðOijPjÞ ¼ PðOf ailurei jP f ailure j Þ ð8Þ

where Pj represents failure of the jth element of the power net- work; Oi is failure of the ith element of the oil network; P(Oi|Pj) is the value of the conditional probability of failure of element Oi given failure of element Pj. The conditional probability, P(Oi|Pj), is

an adjustable parameter, ranging from independence P(Oi|Pj)¼ P(Oi) to complete interdependence P(Oi|Pj)¼1. Further, the geo- graphical interdependencies between the two networks can be obtained based on the attack strength degradation model after an attack. The nodes with recalculated max b(v) of oil network are selected by the attack for exploring the vulnerability of oil network under the attack strength degradation model, considering the two mentioned interdependencies between the two networks. The process is executed ten times independently and the average results of ten times are given in the next.

Based on recalculated max b(v) of oil network, the results of the attack on interdependent networks are shown in Fig. 7–9. As shown in Fig. 7, the results of the SRt of oil network drops sharply under different dependence levels. Similar decreases trends of the results of the SRE and the SRf are shown in Figs. 8 and 9. Compared to the results under P(Oi|Pj)¼P(Oi), the corresponding IA effects of the results are shown in Fig. 10–12 respectively, and the similar trends are illustrated. Although the results mentioned above can provide some insights into the vulnerabilities of the oil network under the attack based on the attack strength degradation model, there are some seemingly paradoxically trends shown in Fig. 9. As shown in

Fig. 9. Oil network SRf based on the recalculated max b(v) under the attack.

Fig. 10. Oil network IA on SRt based on the recalculated max b(v) under the attack.

Fig. 11. Oil network IA on SRE based on the recalculated max b(v) under the attack.

Fig. 12. Oil network IA on SRf based on the recalculated max b(v) under the attack.

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–86

Fig. 9, the results of SRf under P(Oi|Pj)¼0.4 are lower than the results under P(Oi|Pj)¼1 after some attacks occurred. To explain this phe- nomenon, the geographical interdependencies and physical inter- dependencies among the two networks are investigated. When the attack based on node with the recalculated max b(v) in the remained oil network occurs, the two network will undergo the disturbance controlled by the geographical interdependencies at initial stage, making some of the nodes of the two networks in the attack range removed based on the geographical interdependencies defined above. The impact range of the first attack on the oil net- work based on the node of max b(v) is shown in Fig. 2 where the attack center is the node of oil network labeled with 230, the largest radius of the attack is 1718 m, and the nodes of the power network labeled with 155 and 22 are included in addition to the nodes of the oil network labeled with 272 and 304. The geographical inter- dependencies between the two networks are independent of the physical interdependencies. Based on the attack shown in Fig. 2, the results of removes of the mentioned nodes are uncertainty under the geographical interdependencies; furthermore, when some nodes of the power network are removed under the geographical interdependencies, causing the power flow redistribution in the remained power network under given tolerance α¼0.1, the nodes will be removed due to the overflows iteratively, while the nodes in oil network may be removed if they are dependent on the removed nodes in the power network based on the physical inter- dependencies. However the cascading effects among the two net- works only involve the unidirectional dependency from the oil network to the power network, the mutual dependencies among multiple infrastructures will be studied in the future work. Based on the initial results from the geographical interdependencies, the physical interdependencies control the variations of the two net- works. This is the reason for the paradoxically trends shown in Fig. 9. Compared with the SRt and SRE, the SRf also exhibits higher susceptibility to the vulnerabilities of critical infrastructures when interdependencies considered.

The previous results are based on fixed tolerance α¼0.1 under different physical interdependencies. In order to obtain the effects of the interdependent infrastructures under different α with fixed physical interdependency, a similar progresses are made. The process is executed ten times independently and the average results of ten times are shown in Figs. 13–15. According to Fig. 13, the vulnerability of oil network increases when α drops approxi- mately. The results shown in Figs. 14 and 15 also support the conclusion.

Fig. 13. Oil network SRt based on the recalculated max b(v) under the attack.

Fig. 14. Oil network SRE based on the recalculated max b(v) under the attack.

Fig. 15. Oil network SRf based on the recalculated max b(v) under the attack.

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–8 7

5. Conclusions and future work

To further understand and capture the interdependencies among infrastructures when terrorist attacks occur, this paper introduces an attack strength degradation model considering not only the properties of topology and function of critical infrastructures, but also the phy- sical interdependencies and geographical interdependencies among critical infrastructures. A medium-sized energy system including oil network and power network is selected for exploring the vulner- abilities from independent networks to interdependent networks based on the attack strength degradation model. It is argued that the proposed model enables studying the impact of interdependencies among infrastructures, and the model is useful for analyzing the vul- nerability of system of systems. Based on graph theory, the network properties SRt, SRf and SRE are proposed to describe the vulnerabilities of networks after attacks. Moreover, due to the location sensitiveness of the proposed model, the model may explore the critical locations in given areas when concerned infrastructures are involved in the model, which is practical in critical infrastructures protection.

The physical interdependencies and geographical inter- dependencies among critical infrastructures are obtained based on the geographical proximity of network elements, while the former are defined before attacks and the latter are defined based on the attack strength degradation model and obtained after attacks. The physical interdependencies are defined by conditional prob- abilities from independence to complete interdependence. The failures of substations in power network are caused by flow redistribution after attacks under tolerance α¼0.1.

The results of simulation shows that the independent networks or interdependent networks will be collapsed when attack times/ N¼0.1, indicating that the infrastructures will be very vulnerabile when only a small fraction of nodes are attacked under the attack strength degradation model, especially for the interdependent networks. The effects of different α of power network under fixed physical interdependency are also provided, the vulnerability of oil network increases when α drops approximately. However the paper only considers the unidirectional dependency from the oil network to the power network, and only involves two infrastructures.

The proposed attack strength degradation model should be further studied and complemented in the future. First, the model can be changed with a few modifications to model the other affected situations. Second, the model can also be used to analyze the vulnerabilities of inter- dependent networks based on other nodes selection criteria. Third, the identification of critical areas and mutual dependencies among multiple infrastructures will be needed in order to propose feasible protection schemes. Finally, restoration processes and times to repair the inter- dependent networks should be considered after the attack occurred.

Acknowledgments

This work is supported by supported by the Fundamental Research Funds for the Central Universities of China under Grant 2572014BB12. The findings, and conclusions or recommendations expressed in this work are those of the authors and do not necessarily reflect the views of the sponsors.

References

[1] Force. U-CPSOT. Final report on the August 14, 2003 blackout in the United States and Canada: causes and ecommendations. Washington, USA: Depart- ment of Energy; 2004.

[2] Rinaldi SA, Peerenboom JP, Kelly TK. Identifying, understanding, and analyzing critical infrastructure interdependencies. IEEE Control Syst Mag 2001;21:11–25.

B. Wu et al. / Reliability Engineering and System Safety 147 (2016) 1–88

[3] Pederson P, Dudenhoeffer D, Hartley S, Permann M. Critical infrastructure interdependency modeling: a survey of US and international research. Idaho National Laboratory, Technical report; 2006.

[4] Yusta JM, Correa GJ, Lacal-Arántegui R. Methodologies and applications for critical infrastructure protection: state-of-the-art. Energy Policy 2011;39:6100–19.

[5] Ouyang M. Review on modeling and simulation of interdependent critical infrastructure systems. Reliab Eng Syst Saf 2014;121:43–60.

[6] Hausken K, Levitin G. Review of systems defense and attack models. Int J Perform Eng 2012;8:355.

[7] Johansson J, Hassel H. An approach for modelling interdependent infra- structures in the context of vulnerability analysis. Reliab Eng Syst Saf 2010;95:1335–44.

[8] Utne IB, Hokstad P, Vatn J. A method for risk modeling of interdependencies in critical infrastructures. Reliab Eng Syst Saf 2011;96:671–8.

[9] Haimes YY, Jiang P. Leontief-based model of risk in complex interconnected infrastructures. J Infrastruct Syst 2001;7:1.

[10] Santos JR, Haimes YY. Modeling the demand reduction input–output (I–O) inoperability due to terrorism of interconnected infrastructures*. Risk Anal 2004;24:1437–51.

[11] Jiang P, Haimes YY. Risk management for Leontief-based interdependent systems. Risk Anal 2004;24:1215–29.

[12] Haimes YY, Horowitz BM, Lambert JH, Santos JR, Lian C, Crowther KG. Inop- erability input–output model for interdependent infrastructure sectors. I: Theory and methodology. J Infrastruct Syst 2005;11:67–79.

[13] Santos JR, Haimes YY, Lian C. A framework for linking cybersecurity metrics to the modeling of macroeconomic interdependencies. Risk Anal 2007;27:1283–97.

[14] Amin M. Energy infrastructure defense systems. Proc IEEE 2005;93:861–75. [15] Barker K, Haimes YY. Assessing uncertainty in extreme events: applications to

risk-based decision making in interdependent infrastructure sectors. Reliab Eng Syst Saf 2009;94:819–29.

[16] Crowther KG, Haimes YY. Development of the Multiregional Inoperability Input–Output Model (MRIIM) for spatial explicitness in preparedness of interdependent regions. Syst Eng 2010;13:28–46.

[17] Martinez-Mares A, Fuerte-Esquivel CR. A robust optimization approach for the interdependency analysis of integrated energy systems considering wind power uncertainty. IEEE Trans Power Syst 2013;28:3964–76.

[18] North MJ. Agent-based tool for infrastructure interdependency policy analysis. United States; 2000. p. 9 p..

[19] North MJ. Toward strength and stability-agent-based modeling of infra- structure markets. Soc Sci Comput Rev 2001;19:307–23.

[20] Barton DC, Eidson ED, Schoenwald DA, Stamber KL, Reinert RK. Aspen-EE: an agent- based model of infrastructure interdependency. United States; 2000. p. 123 p.

[21] Ng TL, Cai XM, Ouyang YF. Some implications of biofuel development for engineering infrastructures in the United States. Biofuels Bioprod Biorefin 2011;5:581–92.

[22] Chi BH, Stringer JSA, Moodley D. Antiretroviral drug regimens to prevent mother-to-child transmission of HIV: a review of scientific, program, and policy advances for sub-Saharan Africa. Curr HIV/AIDS Rep 2013;10:124–33.

[23] Oliva G, Panzieri S, Setola R. Agent-based input–output interdependency model. Int J Crit Infrastruct Prot 2010;3:76–82.

[24] Min HSJ, Beyeler W, Brown T, Son YJ, Jones AT. Toward modeling and simu- lation of critical national infrastructure interdependencies. IIE Trans 2007;39:57–71.

[25] Buldyrev SV, Parshani R, Paul G, Stanley HE, Havlin S. Catastrophic cascade of failures in interdependent networks. Nature 2010;464:1025–8.

[26] Huang X, Gao J, Buldyrev SV, Havlin S, Stanley HE. Robustness of inter- dependent networks under targeted attack. Phys Rev E 2011;83:065101.

[27] Johansson J, Hassel H, Zio E. Reliability and vulnerability analyses of critical infrastructures: comparing two approaches in the context of power systems. Reliab Eng Syst Saf 2013;120:27–38.

[28] Ouyang M, Duenas-Osorio L, Min X. A three-stage resilience analysis frame- work for urban infrastructure systems. Struct Saf 2012;36–37:23–31.

[29] Duenas-Osorio L, Craig JI, Goodno BJ, Bostrom A. Interdependent response of networked systems. J Infrastruct Syst 2007;13:185–94.

[30] Duenas-Osorio L, Craig JI, Goodno BJ. Seismic response of critical inter- dependent networks. Earthq Eng Struct Dyn 2007;36:285–306.

[31] Duenas-Osorio L, Vemuru SM. Cascading failures in complex infrastructure systems. Struct Saf 2009;31:157–67.

[32] Winkler J, Duenas-Osorio L, Stein R, Subramanian D. Performance assessment of topologically diverse power systems subjected to hurricane events. Reliab Eng Syst Saf 2010;95:323–36.

[33] Ouyang M, Dueñas-Osorio L. An approach to design interface topologies across interdependent urban infrastructure systems. Reliab Eng Syst Saf 2011;96:1462–73.

[34] Duenas-Osorio L, Rojo J. Reliability assessment of lifeline systems with radial topology. Comput-Aided Civil Infrastruct Eng 2011;26:111–28.

[35] Winkler J, Duenas-Osorio L, Stein R, Subramanian D. Interface network models for complex urban infrastructure systems. J Infrastruct Syst 2011;17:138–50.

[36] Ouyang M, Duenas-Osorio L. Efficient approach to compute generalized interdependent effects between infrastructure systems. J Comput Civ Eng 2011;25:394–406.

[37] Hernandez-Fajardo I, Dueñas-Osorio L. Probabilistic study of cascading failures in complex interdependent lifeline systems. Reliab Eng Syst Saf 2013;111:260–72.

[38] Bier VM, Hausken K. Defending and attacking a network of two arcs subject to traffic congestion. Reliab Eng Syst Saf 2013;112:214–24.

[39] Ge Y, Xing XT, Cheng QM. Simulation and analysis of infrastructure inter- dependencies using a Petri net simulator in a geographical information sys- tem. Int J Appl Earth Obs Geoinf 2010;12:419–30.

[40] Eusgeld I, Nan C, Dietz S. “System-of-systems” approach for interdependent critical infrastructures. Reliab Eng Syst Saf 2011;96:679–86.

[41] Eusgeld I, Nan C, IEEE. Creating a simulation environment for critical infra- structure interdependencies study 2009.

[42] Eusgeld I, Kroger W, Sansavini G, Schlapfer M, Zio E. The role of network theory and object-oriented modeling within a framework for the vulnerability analysis of critical infrastructures. Reliab Eng Syst Saf 2009;94:954–63.

[43] Chu CHK, Chu M. An integrated framework for the assessment of network operations, reliability, and security. Bell Labs Tech J 2004;8:133–52.

[44] Volkanovski A, Cepin M, Mavko B. Application of the fault tree analysis for assessment of power system reliability. Reliab Eng Syst Saf 2009;94:1116–27.

[45] Aiping Tang, Jinping Ou, Qinnian Lu, Kexu Zhang. Lifeline system network relia- bility calculation based on GIS and FTA. J Harbin Inst Technol 2006:398–403.

[46] Nganje W, Bier V, Han H, Zack L. Models of interdependent security along the milk supply chain. Am J Agric Econ 2008;90:1265–71.

[47] Hausken K. Protecting complex infrastructures against multiple strategic attackers. Int J Syst Sci 2011;42:11–29.

[48] Zhuang J, Bier VM, Gupta A. Subsidies in interdependent security with het- erogeneous discount rates. Eng Econ 2007;52:1–19.

[49] Kunreuther H, Heal G. Interdependent security. J Risk Uncertain 2003;26:231–49. [50] Wang S, Hong L, Ouyang M, Zhang J, Chen X. Vulnerability analysis of inter-

dependent infrastructure systems under edge attack strategies. Saf Sci 2013;51:328–37.

[51] Patterson SA, Apostolakis GE. Identification of critical locations across multiple infrastructures for terrorist actions. Reliab Eng Syst Saf 2007;92:1183–203.

[52] Berezin Y, Bashan A, Danziger MM, Li D, Havlin S. Localized attacks on spa- tially embedded networks with dependencies. Sci Rep 2015:5.

[53] Watkins JJ, Robin J. Graphs: an introductory approach. New York: John Wiley & Sons; 1990.

[54] Latora V, Marchiori M. Efficient behavior of small-world networks. Phys Rev Lett 2001:87.

[55] Motter AE, Lai YC. Cascade-based attacks on complex networks. Phys Rev E 2002:66.

  • Modeling cascading failures in interdependent infrastructures under terrorist attacks
    • Instruction
    • Definitions for evaluations the vulnerabilities of infrastructure systems
      • Service rate based on topology
      • Service rate based on flow
      • Service rate based on network efficency
      • Interdependency Amplification
    • Attack strength degradation model and infrastructure networks
      • Infrastructure networks
      • Attack strength degradation model
    • Networks responses under the attack strength degradation model
      • Independent networks responses
      • Interdependent networks responses
    • Conclusions and future work
    • Acknowledgments
    • References