Publication Details
Abstract
Objective: Cyber containment in critical infrastructure is a dual-risk decision: insufficient isolation permits lateral movement, while excessive isolation can interrupt electricity, water, healthcare, transportation, and communications. This study introduces Adaptive Service-Preserving Containment (ASPC), which estimates compromise uncertainty, forecasts attack spread, models critical-service dependencies, predicts operational consequences, and repeatedly selects the smallest boundary satisfying safety and residual-risk constraints. Method: Unlike a purely conceptual treatment, ASPC was implemented in a stochastic graph-based test environment and evaluated against full isolation, rule-based containment, and a cyber-centric AI baseline. Results: Across 450 paired trials on seen topology families and 300 on held-out topologies, ASPC achieved attack spread statistically indistinguishable from full isolation while sharply reducing unnecessary isolation and safety violations. On unseen topologies, ASPC averaged 1.49 additional compromised nodes, 3.91% unnecessary isolation, 1.27 containment epochs, 5.76 recovery epochs, 0.51 safety violations, and 92.30% critical-service availability. Its availability exceeded the other methods by 14.49–74.75 percentage points. Ablations showed that continuous reassessment was necessary to contain delayed footholds and that the service-dependency model prevented coarse over-isolation. Novelty: Results support ASPC as a testbed-validated resilience controller, while remaining subject to the limitations of synthetic topology, simplified physical dynamics, and simulated telemetry.