Impact assessment of defense architectures in cyber-physical systems: A quantitative approach
Abstract
Industrial Control Systems (ICS) and Cyber-Physical Systems (CPS) supporting critical infrastructure are increasingly exposed to sophisticated cyber threats. In this case, detection technologies such as Intrusion Detection Systems (IDS) and Endpoint Detection and Response (EDR) improve threat visibility. Nevertheless, both might fall short in operational continuity. In the other hand, on-going comprehensive studies that quantitatively assess the contribution of both mechanisms to system continuity and operational resilience are few. Hence, this study proposes a quantitative cyber resilience assessment framework to evaluate the operational impact of detection and recovery capabilities in industrial environments in this field. A Monte Carlo–based simulation model was developed to analyze four defense architectures: manual monitoring, IDS deployment, IDS+EDR integration, and a hardened architecture incorporating defense-in-depth mechanisms and immutable signed backups. System performance was evaluated using Time to Detect (TTD), Time to Recover (TTR), and Average Production Loss (APL) as resilience metrics. Results show that IDS deployment reduces median detection time by more than 90%, yet improvements in detection speed even alone provide limited reductions in operational downtime. In contrast, the hardened architecture reduced recovery time from 48 hours to 6 hours and decreased operational disruption by more than 50%. The findings demonstrate that recovery capability and data integrity assurance are dominant determinants of cyber resilience in ICS environments. The proposed resilience evaluation framework offers a reusable method for assessing cybersecurity investments and improving operational continuity across critical infrastructure sectors.