A Metric Selection Framework for Quantitative Evaluation of Cyber Resilience 


Vol. 14,  No. 5, pp. 332-342, May  2025
https://doi.org/10.3745/TKIPS.2025.14.5.332


PDF
  Abstract

This study proposes a framework for selecting quantitative metrics to evaluate cyber resilience. Based on an analysis of various service types certified under information security and personal data protection management systems (ISMS-P), a pool of candidate resilience metrics was derived. The validity of the selected metrics was evaluated according to five key criteria defined in this study: objectivity, reproducibility, scalability, practicality, and resilience representation. In addition, the principles of mutual exclusivity (ME) and collective exhaustiveness (CE) were applied as supplementary criteria to eliminate redundancy and ensure the general applicability of the evaluation framework. As a result, 12 quantitative resilience metrics were selected. Among them, a detailed empirical analysis was conducted on the Transactions Per Second (TPS) metric, which measures transaction throughput in systems such as web services, focusing on its variation and interpretation under TCP SYN flooding attack scenarios. The proposed metric selection framework establishes a standardized evaluation framework for objectively measuring cyber resilience, thereby providing a basis for effectively responding to and enhancing resilience against continuously evolving cyber threats.

  Statistics


  Cite this article

[IEEE Style]

H. Kang, J. Sung, H. Cho, "A Metric Selection Framework for Quantitative Evaluation of Cyber Resilience," The Transactions of the Korea Information Processing Society, vol. 14, no. 5, pp. 332-342, 2025. DOI: https://doi.org/10.3745/TKIPS.2025.14.5.332.

[ACM Style]

Hye-Jin Kang, Ji-Hyun Sung, and Harksu Cho. 2025. A Metric Selection Framework for Quantitative Evaluation of Cyber Resilience. The Transactions of the Korea Information Processing Society, 14, 5, (2025), 332-342. DOI: https://doi.org/10.3745/TKIPS.2025.14.5.332.