18 Bridging the Vulnerability Paradigm to Critical Infrastructure …
331
The growing threat of terrorism in the mid 1990s set the stage for the political
framework of CI in a context of human security (Rinaldi et al. 2001; Moteff and
Parfomak 2004; Miller 2009; DHS 2013). However, knowledge about system-level
vulnerabilities in the U.S. dates from the first half of the twentieth century (Collier and
Lakoff 2008) including those that apply network analysis to utility systems vulnerability (Cagley 1964) and the oil industry (Thayer and Shaner 1960). Collier and
Lakoff trace historical definitions of “vital systems” developed by military strategist and intelligence economists that rose with the interwar offensive airpower and
derived theories of strategic bombing, nuclear threat and “critical targets”.
In current official planning documents, the latest definition of CI for is still
borrowed from the Homeland Security Act of 2002:
critical infrastructure includes systems and assets whether physical or virtual, so vital to
the US that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any
combination of those matters
Parallel to the institutionalization of CI in the US in the beginning of the twentyfirst century network science was maturing as a generalizable tool in various disciplines. From a mathematical perspective, network science studies the relationship
between elements named nodes, and their interconnections named links which
together form discrete structures that are also named graphs (Bollobás 1998; Latora
et al. 2017). Several approaches were built to understand critical infrastructure vulnerability through network science, some of these observed that the removal of critical
nodes aids rapid degradation of the network function (Gorman et al. 2004). Centrality
metrics, for instance, become key in critical infrastructure protection plans as they
calculate the importance of a node or link in relation to the full topological structure
to which they belong and enable a ranking process of assets or groups of assets
2
(Freeman 1977; Zhuge and Zhang 2009).
Some of these metrics were originally introduced by the social network analysis
community in the 1930s (Scott 2014) and have been adapted and enriched since then
to help inform the position of the node within the structure and how influential it
is. One milestone in the official integration and investment in network science as a
discipline for national security research was the 2005 National Academy of Sciences
investigation on the gap of structural dynamics and behavior of large infrastructure
networks. This investigation stated that much information had been gathered on
CI design, material, and individual asset structure, but the science of integrating
those assets into a whole interacting network with systemic behavior parameters
was underdeveloped and fragmented before then (National Research Council et al.
2005). This helps explain why the twenty-first century’s neo-emergence of network
science with complex systems traditionally finds empirical ground on the engineered
securitization of CI. Knowledge of topological structures illuminated the importance
2 Many different centrality formulas have been developed based on graph theory. The two most
common metrics rely on calculating the number of links attributed to each node such as degree and
eigenvector centrality and shortest paths calculations such as betweenness and closeness centrality
(Freeman 1978; Brandes et al. 2016; Latora et al. 2017).
331
The growing threat of terrorism in the mid 1990s set the stage for the political
framework of CI in a context of human security (Rinaldi et al. 2001; Moteff and
Parfomak 2004; Miller 2009; DHS 2013). However, knowledge about system-level
vulnerabilities in the U.S. dates from the first half of the twentieth century (Collier and
Lakoff 2008) including those that apply network analysis to utility systems vulnerability (Cagley 1964) and the oil industry (Thayer and Shaner 1960). Collier and
Lakoff trace historical definitions of “vital systems” developed by military strategist and intelligence economists that rose with the interwar offensive airpower and
derived theories of strategic bombing, nuclear threat and “critical targets”.
In current official planning documents, the latest definition of CI for is still
borrowed from the Homeland Security Act of 2002:
critical infrastructure includes systems and assets whether physical or virtual, so vital to
the US that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any
combination of those matters
Parallel to the institutionalization of CI in the US in the beginning of the twentyfirst century network science was maturing as a generalizable tool in various disciplines. From a mathematical perspective, network science studies the relationship
between elements named nodes, and their interconnections named links which
together form discrete structures that are also named graphs (Bollobás 1998; Latora
et al. 2017). Several approaches were built to understand critical infrastructure vulnerability through network science, some of these observed that the removal of critical
nodes aids rapid degradation of the network function (Gorman et al. 2004). Centrality
metrics, for instance, become key in critical infrastructure protection plans as they
calculate the importance of a node or link in relation to the full topological structure
to which they belong and enable a ranking process of assets or groups of assets
2
(Freeman 1977; Zhuge and Zhang 2009).
Some of these metrics were originally introduced by the social network analysis
community in the 1930s (Scott 2014) and have been adapted and enriched since then
to help inform the position of the node within the structure and how influential it
is. One milestone in the official integration and investment in network science as a
discipline for national security research was the 2005 National Academy of Sciences
investigation on the gap of structural dynamics and behavior of large infrastructure
networks. This investigation stated that much information had been gathered on
CI design, material, and individual asset structure, but the science of integrating
those assets into a whole interacting network with systemic behavior parameters
was underdeveloped and fragmented before then (National Research Council et al.
2005). This helps explain why the twenty-first century’s neo-emergence of network
science with complex systems traditionally finds empirical ground on the engineered
securitization of CI. Knowledge of topological structures illuminated the importance
2 Many different centrality formulas have been developed based on graph theory. The two most
common metrics rely on calculating the number of links attributed to each node such as degree and
eigenvector centrality and shortest paths calculations such as betweenness and closeness centrality
(Freeman 1978; Brandes et al. 2016; Latora et al. 2017).
