-
Magnetism in metastable and annealed compositionally complex alloys
Nan Tang, Lizabeth Quigley, Walker L. Boldman, Cameron S. Jorgensen, Rémi Koch, Daniel O'Leary, Hugh R. Medal, Philip D. Rack, and Dustin A. Gilbert.
Publication Year: 2022-05-10 18:47:57
[Link to Article] Compositionally complex materials (CCMs) present a potential paradigm shift in the design of magnetic materials. These alloys exhibit long-range structural order coupled with limited or no chemical order. As a result, extreme local environments exist with a large variations in the magnetic energy terms, which can manifest large changes in the magnetic behavior. In the current work, the magnetic properties of (Cr, Mn, Fe, Ni) alloys are presented. These materials were prepared by room-temperature combinatorial sputtering, resulting in a range of compositions with a single bcc structural phase and no chemical ordering. The combinatorial growth technique allows CCMs to be prepared outside of their thermodynamically stable phase, enabling the exploration of otherwise inaccessible order. The mixed ferromagnetic and antiferromagnetic interactions in these alloys causes frustrated magnetic behavior, which results in an extremely low coercivity (<1mT), which increases rapidly at 50 K. At low temperatures, the coercivity achieves values of nearly 500 mT, which is comparable to some high-anisotropy magnetic materials. Commensurate with the divergent coercivity is an atypical drop in the temperature dependent magnetization. These effects are explained by a mixed magnetic phase model, consisting of ferro-, antiferro-, and frustrated magnetic regions, and are rationalized by simulations. A machine-learning algorithm is employed to visualize the parameter space and inform the development of subsequent compositions. Annealing the samples at 600 °C orders the sample, more-than doubling the Curie temperature and increasing the saturation magnetization by as much as 5×. Simultaneously, the large coercivities are suppressed, resulting in magnetic behavior that is largely temperature independent over a range of 350 K. The ability to transform from a hard magnet to a soft magnet over a narrow temperature range makes these materials promising for heat-assisted recording technologies. -
Optimization of twice-daily direct flyover data collection for satellite observations at uncertain locations
AB Hoskins, HR Medal, E Rashidi. AB Hoskins, HR Medal, E Rashidi (2022) Advances in Space Research 70 (4), 1013-1031
Publication Year: 2022-05-03 21:21:47
[Link to Article] -
The wireless network jamming problem subject to protocol interference using directional antennas and with battery capacity constraints
JD Huff, WB Leonard, HR Medal. (2022). International Journal of Critical Infrastructure Protection 39, 100572
Publication Year: 2022-05-03 21:21:06
[Link to Article]Wireless networks support the operation and maintenance of a variety of critical infrastructure, and keeping these networks functional in the face of adversarial adversity is a paramount concern of infrastructure managers. Supporting these networks’ continued operability requires a robust understanding of wireless-network functionality, including of the ways in which adversaries may seek to jam such networks using recently developed capabilities. However, past work on wireless network jamming subject to protocol interference has focused on using omnidirectional antennas for the target and the jamming attack nodes and has not considered battery-capacity impacts on the success of these jamming efforts. Based on a field test of an ad hoc network performed by Ramanathan et al. (2005) in which the authors found that directional antennas offer an “order-of-magnitude improvement in the capacity and connectivity of an ad hoc network,” the work in this field should be extended to include directional antennas. By incorporating directional antennas, analysts may more realistically model antennas present in everyday use. In addition, battery capacity of the wireless network nodes can impact the effectiveness of a jamming attack and should be considered. By considering battery capacity, researchers are sure to take into account real-world scenarios in which energy limitations might affect actual network performance. The mathematical model discussed in this paper demonstrates the way in which network jamming is affected by directional antennas, battery capacity, and node density to determine how these factors would impact a robust jamming attack. Particularly noteworthy results include the finding that high battery capacity can offer as much as half an order of magnitude of improvement in data transmission over lower battery capacity in certain cases. These results show that the model could be used to aid decision makers in understanding how to design a network that is robust against jamming attacks.
-
A stochastic programming model with endogenous uncertainty for proactive supplier risk mitigation of low-volume-high-value manufacturers considering decision-dependent supplier performance
Rui Zhou, Bhuiyan, Tanveer Hossain, Michael Sherwin, and Medal, H.. Zhou, Rui, Tanveer Hossain Bhuiyan, Hugh R. Medal, Michael D. Sherwin, and Dong Yang. "A stochastic programming model with endogenous uncertainty for selecting supplier development programs to proactively mitigate supplier risk." Omega 107 (2022): 102542.
Publication Year: 2022-03-17 18:57:48
[Link to Article]Poor supplier performance can result in delays that disrupt manufacturing operations. By proactively managing supplier performance, the likelihood and severity of supplier risk can be minimized. In this paper, we study the problem of selecting optimal supplier development programs (SDPs) to improve suppliers’ performance with a limited budget to proactively reduce supplier risks for a manufacturer. A key feature of our research is that it incorporates the uncertainty in supplier performance in response to SDPs selection decisions. This uncertainty is endogenous (decision-dependent), as the probability of supplier performance depends on the selection of SDPs, which introduces modeling and algorithmic challenges. We formulate this problem as a two-stage stochastic program with decision-dependent uncertainty. We implement a sample-based greedy algorithm and an accelerated Benders’ decomposition method to solve the developed model. We evaluate our methodology using the numerical cases of four low-volume, high-value manufacturing firms. The results provide insights into the effects of the budget amount and of the number of SDPs on the firm’s expected profit. Numerical experiments demonstrate that an increase in budget results in profit growth, e.g., 5.09% profit growth for one firm. At a lower budget level, increasing the number of available SDPs results in more profit growth. The results also demonstrate the significance of considering uncertainty in supplier performance and considering multiple supplier risks for the firm. In addition, computational experiments demonstrate that our algorithms, especially our greedy approximation algorithm, can solve large-sized problems in a reasonable time. -
Risk-averse Bi-level Stochastic Network Interdiction Model for Cyber-security
Bhuiyan, Tanveer Hossain, Hugh R. Medal, Apurba K. Nandi, and Mahantesh Halappanavar. (2022) Risk-averse bi-level stochastic network interdiction model for cyber-security risk management." International Journal of Critical Infrastructure Protection 32 (2021): 100408.
Publication Year: 2021-06-17 18:53:24
[Link to Article]Bhuiyan, Tanveer Hossain, Hugh R. Medal, Apurba K. Nandi, and Mahantesh Halappanavar.This paper proposes a methodology to enable a risk-averse, resource constrained cyber network defender to optimally deploy security countermeasures that protect against potential attackers with an uncertain budget. The proposed methodology is based on a risk-averse bi-level stochastic network interdiction model on an attack graph–maps the potential attack paths of a cyber network–that minimizes the weighted sum of the expected maximum loss over all attack scenarios and the risk of substantially large losses. The conditional-value-at-risk measure is incorporated into the stochastic programming model to reduce the risk of substantially large losses. An exact algorithm is developed to solve the model as well as several acceleration techniques to improve the computational efficiency. Numerical experiments demonstrate that the acceleration techniques enable the solution of relatively large problems within a reasonable amount of time: simultaneously applying all the acceleration techniques reduces the average computation time of the basic algorithm by 71% for 100-node graphs. Using metrics called mean-risk value of stochastic solution and value of risk-aversion, computational results suggest that the stochastic risk-averse model provides substantially better network interdiction decision than the deterministic (ignores uncertainty) and risk-neutral models when 1) the distribution of attacker budget is heavy-right-tailed and 2) the defender is highly risk-averse.
-
Atomistic modeling of meso-timescale processes with SEAKMC: A perspective and recent developments
Sho Hayakawa, Jake Isaacs, Hugh R Medal, Haixuan Xu.
Publication Year: 2021-06-15 18:49:02
[Link to Article]On-the-fly kinetic Monte Carlo (kMC) methods have recently garnered significant attentions after successful applications to various atomic-scale problems using a timescale outside the reach of classical molecular dynamics. These methods play a critical role in modeling atomistic meso-timescale processes, and it is therefore essential to further improve their capabilities. Herein, we review one of the on-the-fly kMC methods, Self-Evolving Atomistic kinetic Monte Carlo (SEAKMC) and propose two schemes that considerably enhance the efficiency of saddle point searches (SPSs) during the simulations. The performance of these schemes is tested using the diffusion of point defects in bcc Fe. In addition, we discuss approaches to significantly mitigate limitations of these schemes, which further improves their efficiencies. Importantly, these schemes improve the SPS efficiency not only for SEAKMC but also for other on-the-fly kMC methods, broadening the applications of on-the-fly kMC simulations to complex meso-timescale problems.
-
Identifying and mitigating supply chain risks using fault tree optimization
Sherwin, M., Brown, K. J., Medal, H., and Mackenzie, C.. Michael D. Sherwin, Hugh R. Medal, Cameron A. MacKenzie & Kennedy J. Brown (2020) Identifying and mitigating supply chain risks using fault tree optimization, IISE Transactions, 52:2, 236-254
Publication Year: 2020-06-17 17:56:20
[Link to Article] Although supply chain risk management and supply chain reliability are topics that have been studied extensively, a gap exists for solutions that take a systems approach to quantitative risk mitigation decision making and especially in industries that present unique risks. In practice, supply chain risk mitigation decisions are made in silos and are reactionary. In this article, we address these gaps by representing a supply chain as a system using a fault tree based on the bill of materials of the product being sourced. Viewing the supply chain as a system provides the basis to develop an approach that considers all suppliers within the supply chain as a portfolio of potential risks to be managed. Next, we propose a set of mathematical models to proactively and quantitatively identify and mitigate at-risk suppliers using enterprise available data with consideration for a firm’s budgetary constraints. Two approaches are investigated and demonstrated on actual problems experienced in industry. The examples presented focus on Low-Volume High-Value (LVHV) supply chains that are characterized by long lead times and a limited number of capable suppliers, which make them especially susceptible to disruption events that may cause delays in delivered products and subsequently increase the financial risk exposure of the firm. Although LVHV supply chains are used to demonstrate the methodology, the approach is applicable to other types of supply chains as well. Results are presented as a Pareto frontier and demonstrate the practical application of the methodology. -
A stochastic programming model with endogenous and exogenous uncertainty for reliable network design under random disruption
Bhuiyan, T. H. and Medal H.. Bhuiyan, T. H., Medal, H. R., & Harun, S. (2020). A stochastic programming model with endogenous and exogenous uncertainty for reliable network design under random disruption. European Journal of Operational Research, 285(2), 670-694.
Publication Year: 2020-06-10 18:43:31
[Link to Article] Designing and maintaining a reliable and efficient transportation network is an important industrial problem. Integrating infrastructure protection with the network design model is efficient as these models provide strategic decisions to make a transportation network simultaneously efficient and reliable. We studied a combined network design and infrastructure protection problem subject to random disruptions where the protection is imperfect and multi-level and the effect of disruption is imperfect. In this research, we modeled a resource-constrained decision maker seeking to optimally allocate protection resources to the facilities, and construct links in the network to minimize the expected post-disruption transportation cost (PDTC). We modeled the problem as a two-stage stochastic program with both endogenous and exogenous uncertainty: a facility’s post-disruption capacity depends probabilistically on the protection decision, making the uncertainty endogenous, while the link construction decision directly affects the transportation decision. We implemented an accelerated L-shaped algorithm to solve the model and predictive modeling techniques to estimate the probability of a facility’s post-disruption capacity for a given protection and disruption intensity. Numerical results show that solution quality is sensitive to the number of protection levels modeled; average reduction in the expected PDTC is 18.7% as the number of protection levels increases from 2 to 5. Results demonstrate that the mean value model performs very poorly as the uncertainty increases. Results also indicate that the stochastic programming model is sensitive to the estimation error of the predictive modeling techniques; on average the expected PDTC becomes 6.38% higher for using the least accurate prediction model. -
Connected Infrastructure Network Design Under Additive Service Utilities
Li, X. and Medal, H.. Connected Infrastructure Network Design Under Additive Service Utilities. Transportation Research Part B 120, 99–124.
Publication Year: 2019-10-01 00:00:00
[Link to Article] An infrastructure system usually contains a number of inter-connected infrastructure links that connect users to services or products. Where to locate these infrastructure links is a challenging problem that largely determines the efficiency and quality of the network. This paper studies a new location design problem that aims to maximize the total weighted benefits between users and multiple services that are measured by the amount of connectivity between users and links in the network. This problem is investigated from both analytical and computational points of view. First, analytical properties of special cases of the problem are described. Next, two integer programming model formulations are presented for the general problem. We also test intuitive heuristics including greedy and interchange algorithms, and find that the interchange algorithm efficiently yields near-optimum solutions. Finally, a set of numerical examples demonstrate the proposed models and reveal interesting managerial insights. In particular, we found that a more distance-dependent utility measure and a higher concentration of users help achieve a better total utility. As the population becomes increasingly concentrated, the optimal link design evolves from a linear path to a cluster of links around the population center. As the budget level increases, the installed links gradually sprawl from the population center towards the periphery, and in the case of multiple population centers, they grow and eventually merge into one connected component. -
A Model-Based Systems Engineering Approach to Critical Infrastructure Vulnerability Assessment and Decision Analysis
Huff, J. D., Medal, H., and K. A. Griendling. Submitted to Systems Engineering 22(2), 114–133.
Publication Year: 2019-09-01 00:00:00
[Link to Article]Securing critical infrastructure against attack presents significant challenges. As new infrastructure is built and existing infrastructure is maintained, a method to assess the vulnerabilities and support decision makers in determining the best use of security resources is needed. In response to this need, this research develops a methodology for performing vulnerability assessment and decision analysis of critical infrastructure using model‐based systems engineering, an approach that has not been applied to this problem. The approach presented allows architects to link regulatory requirements, system architecture, subject matter expert opinion and attack vectors to a Department of Defense Architecture Framework (DoDAF)‐based model that allows decision makers to evaluate system vulnerability and determine alternatives to securing their systems based on their budget constraints. The decision analysis is done using an integer linear program that is integrated with DoDAF to provide solutions for how to allocate scarce security resources. Securing an electrical substation is used as an illustrative case study to demonstrate the methodology. The case study shows that the method presented here can be used to answer key questions, for example, what security resources should a decision maker invest in based on their budget constraints? Results show that the modeling and analysis approach provides a means to effectively evaluate the infrastructure vulnerability and presents a set of security alternatives for decision makers to choose from, based on their vulnerabilities and budget profile. -
NATO Human View Executable Architectures for Critical Infrastructure Analysis
Huff, J. D., Leonard, W., B. Smith, K. Griendling, and Medal, H.. Engineering Management Journal. 31:4, 224-245.
Publication Year: 2019-08-01 00:00:00
[Link to Article]Engineering managers are responsible for the secure operation of critical infrastructure systems and need tools and methods to identify and mitigate potential insider threats such as physical damage to equipment, information leakage, malware, and identify theft. This research examines the benefit of development and analysis of the NATO Human View to aid engineering managers with this responsibility. In an illustrative case study, the NATO Human View is used to analyze electrical grid personnel; the results demonstrate that the NATO Human View can be used to enable engineering managers to make investment decisions that can mitigate security threats. -
Stochastic Programming Solution for Placement of Satellite Ground Stations
Aaron Hoskins, Hugh Medal. To appear in Annals of Operations Research.
Publication Year: 2019-07-01 00:00:00
Disaster recovery efforts are enhanced through the collection and dissemination of satellite data, which is downloaded from satellites to ground stations. The optimal ground station locations vary depending on the location of the disaster, but ground station construction occurs before the realization of a disaster. Thus, a stochastic optimization problem arises: decide the location of ground stations before disasters with uncertain locations. We use a stochastic programming approach to select the location of ground stations given a set of potential disaster scenarios. The objective is to maximize the expected amount of data downloaded. The problem formulation consists of a two-stage stochastic program where the first-stage determines the locations of the ground stations and the second-stage schedules the uploading and downloading of data. We solve the problem using the L-shaped method; we find that it significantly outperforms solving the deterministic equivalent problem directly. We also find that an alternate second-stage formulation significantly improves solution time. The optimized set of ground stations found by our algorithm is compared to the set of ground stations operated by the National Oceanic and Atmospheric Administration’s; results confirm that the current placement is effective and demonstrate the benefit in adding additional ground stations. -
Wireless LAN transmitter location under the threat of jamming attacks
David Schweitzer and Medal, H. (2019).. Computers and Operations Research 106, 14–27.
Publication Year: 2019-06-17 18:47:04
[Link to Article]This paper studies the optimal placement of wireless access points in a network under the threat of jamming. We addressed this problem with a tri-level mixed-integer program. In the top level, the defender seeks to optimally place a set of capacity-limited access points to maximize total connectivity. In the middle level, an attacker seeks to optimally place a set of jammers that may be relocated between time periods to minimize total connectivity. In the bottom level, demand points seek to connect to capacitated access points such that their connections maximize their network utility. This model was examined from two viewpoints: a non-additive model in which connections were jammed if they fell within a jammer’s radius, and an additive model in which connections were jammed if enough jamming power was interfering with the connection. We proposed a solution methodology which solved a modified bi-level program efficiently via implicit enumeration and dynamic constraint generation. We showed that the addition of just one access point provided a significant increase to network connectivity, different topologies had different robustness when different utility functions were considered, and optimal jammer placement varied significantly across different topologies. Through our experiments on five topologies, we found the Spacious and Median topologies were closest to the optimal access point placement.
-
A stochastic programming model with endogenous uncertainty for incentivizing fuel reduction treatment under uncertain landowner behavior
Bhuiyan, T. H., Moseley, M., Medal, H., E Rashidi, and R Grala (2019).. European Journal of Operational Research 277(2), 699–718.
Publication Year: 2019-05-17 18:48:15
-
A mixed-integer programming approach for optimizing flow jamming attacks
Satish Vadlamani, Hugh Medal, David Schweitzer, Apurba Nandi, Burak Ekşioğlu. Vadlamani, S., Schweitzer, D., Medal, H., Nandi, A., & Eksioglu, B. (2018). A mixed-integer programming approach for locating jamming devices in a flow-jamming attack. Computers & Operations Research, 95, 83-96.
Publication Year: 2018-08-01 00:00:00
[PDF] [Link to Article] The ubiquitous nature of wireless networks makes them increasingly prone to jamming attacks as such attacks become more sophisticated. In this paper, we seek to gain understanding about a particular type of jamming attack: the flow-jamming attack. Toward this end, we provide a mixed-integer programming model for optimizing the location of jamming devices for flow-jamming attacks. An accelerated Benders decomposition approach was used to solve the model. We solved the problem for two realistic networks and 12 randomly generated networks and found that the Benders approach was computationally faster than CPLEX for nearly all the problem instances, particularly for larger problems with 1000 binary variables. The experimental results show that optimally locating jamming devices can increase the impact of flow-jamming attacks. Specifically, as the number of possible locations increases the jammers' efficacy increases as well, but there is a clear point of diminishing returns. Also, adding lower-powered jammers to work in conjunction with higher powered jammers significantly increases overall efficacy in spite of the power difference. -
An attacker-defender model for analyzing the vulnerability of initial attack in wildfire suppression
Rashidi, E., Medal, H., and Hoskins, A.. Naval Research Logistics 65(2), 120–134.
Publication Year: 2018-06-01 00:00:00
Wildfire managers use initial attack (IA) to control wildfires before they grow large and become difficult to suppress. Although the majority of wildfire incidents are contained by IA, the small percentage of fires that escape IA causes most of the damage. Therefore, planning a successful IA is very important. In this article, we study the vulnerability of IA in wildfire suppression using an attacker-defender Stackelberg model. The attacker's objective is to coordinate the simultaneous ignition of fires at various points in a landscape to maximize the number of fires that cannot be contained by IA. The defender's objective is to optimally dispatch suppression resources from multiple fire stations located across the landscape to minimize the number of wildfires not contained by IA. We use a decomposition algorithm to solve the model and apply the model on a test case landscape. We also investigate the impact of delay in the response, the fire growth rate, the amount of suppression resources, and the locations of fire stations on the success of IA. -
Mitigating a pyro-terror attack using fuel management
Eghbal Rashidi, Hugh Medal. To appear in IISE Transactions.
Publication Year: 2018-01-01 00:00:00
We study a security problem in which an adversary seeks to attack a landscape by setting a wildfire in a strategic location, whereas wildfire managers wish to mitigate the damage of the attack by implementing a fuel treatment in the landscape. We model the problem as a min–max Stackelberg game with the goal of identifying an optimal fuel treatment plan that minimizes the impact of a pyro-terror attack. As the adversary's problem is discrete, we use a decomposition algorithm suitable for integer bi-level programs. We test our model on three test landscape cases located in the Western United States. The results indicate that fuel treatment can effectively mitigate the effects of an attack: implementing fuel treatment on 2, 5, and 10% of the landscape, on average, reduces the damage caused by a pyro-terror attack by 14, 27, and 43%, respectively. The resulting fuel treatment plan is also effective in mitigating natural wildfires with randomly placed ignition points. The pyro-terrorism mitigation problem studied in this article is equivalent to the b-interdiction-covering problem where the intermediate nodes are subject to interdiction. It can also be interpreted as the problem of identifying the b-most-vital nodes in a one-to-all shortest path problem. -
Analyzing the robustness of an array of wireless access points to mobile jammers
Schweitzer, David, Ruholla Jafari-Marandi, and Hugh Medal. Computers & Industrial Engineering 107 (2017): 25-38
Publication Year: 2017-08-01 00:00:00
[Link to Article]We present an approach for measuring the vulnerability of a wireless network. Our metric, n-Robustness, measures the change in a network’s total signal strength resulting from the optimal placement of n jammers by an attacker. Toward this end, we develop a multi-period mixed-integer programming interdiction model that determines the movement of n jammers over a time horizon so as to minimize the total signal strength of users during a sustained jamming attack. We compared several solution approaches for solving our model including a Lagrangian relaxation heuristic, a genetic algorithm, and a stage decomposition heuristic. We tested our approach on a wireless trace dataset developed as part of the Wireless Topology Discovery project at the University of California San Diego. We found that the Lagrangian approach, which performed best overall, finds a close-to-optimal solution while requiring much less time than solving the MIP directly. We then illustrate the behavior of our model on a small example taken from the dataset as well as a set of experiments. Through our experiments we conclude that the total signal power follows a sigmoid curve as we increase the number of jammers and access points. We also found that increasing access points only improves network robustness initially; after that the benefit levels off. In addition, we found that the problem instances we considered have an n-Robustness of between 39 and 69%, indicating that the value of the model parameters (e.g., number of jammers, number of time periods) has an effect on robustness.
-
A maximal covering location-based model for analyzing the vulnerability of landscapes to wildfires: Assessing the worst-case scenario
Eghbal Rashidi, Hugh Medal, Jason Gordon, Robert Grala, Morgan Varner. European Journal of Operational Research, Volume 258, Issue 3, Pages 1095–1105
Publication Year: 2017-05-01 00:00:00
[PDF] [Link to Article]In this research, we study the vulnerability of landscapes to wildfires based on the impact of the worst-case scenario ignition locations. Using this scenario, we model wildfires that cause the largest damage to a landscape over a given time horizon. The landscape is modeled as a grid network, and the spread of wildfire is modeled using the minimum travel time model. To assess the impact of a wildfire in the worst-case scenario, we develop a mathematical programming model to optimally locate the ignition points so that the resulting wildfire results in the maximum damage. We compare the impacts of the worst-case wildfires (with optimally located ignition points) with the impacts of wildfires with randomly located ignition points on three landscape test cases clipped out from three national forests located in the western U.S. Our results indicate that the worst-case wildfires, on average, have more than twice the impact on landscapes than wildfires with randomly located ignition points.
-
Satellite Constellation Design for Forest Fire Monitoring Via a Stochastic Programming Approach
Aaron Hoskins, Hugh Medal, Eghbal Rashidi. To appear in Naval Research Logistics.
Publication Year: 2017-03-01 00:00:00
There is significant value in the data collected by satellites during and after a natural disaster. The current operating paradigm in practice is for satellites to passively collect data when they happen to fly over a disaster location. Conversely, this article considers the alternative approach of actively maneuvering satellites to fly directly overhead of the disaster site on a routine basis. Toward this end, we seek to compute a satellite constellation design that minimizes the expected maneuver costs for monitoring an unknown forest fire. In this article, we present a 2‐stage stochastic programing model for this problem as well as a accelerated L‐shaped decomposition approach. A comparison between our approach and the current operating paradigm indicates that our solution provides longer duration data collections and a greater number of data collections. Analysis also shows that our proposed solution is robust over a wide array of scenarios. -
Botnet Detection Using Graph-Based Feature Clustering
Chowdhury, S., Khanzadehdaghalian, M., Akula, R., Zhang, F., S. Zhang, Medal, H., M. Marufuzzaman, and L. Bian. To appear in Journal of Big Data.
Publication Year: 2017-01-01 00:00:00
Detecting botnets in a network is crucial because bots impact numerous areas such as cyber security, finance, health care, law enforcement, and more. Botnets are becoming more sophisticated and dangerous day-by-day, and most of the existing rule based and flow based detection methods may not be capable of detecting bot activities in an efficient and effective manner. Hence, designing a robust and fast botnet detection method is of high significance. In this study, we propose a novel botnet detection methodology based on topological features of nodes within a graph: in degree, out degree, in degree weight, out degree weight, clustering coefficient, node betweenness, and eigenvector centrality. A self-organizing map clustering method is applied to establish clusters of nodes in the network based on these features. Our method is capable of isolating bots in clusters of small sizes while containing the majority of normal nodes in the same big cluster. Thus, bots can be detected by searching a limited number of nodes. A filtering procedure is also developed to further enhance the algorithm efficiency by removing inactive nodes from consideration. The methodology is verified using the CTU-13 datasets, and benchmarked against a classification-based detection method. The results show that our proposed method can efficiently detect the bots despite their varying behaviors. -
Jamming Attacks on Wireless Networks: A Taxonomic Survey
Satish Vadlamani, Burak Ekşioğlu, Hugh Medal, Apurba Nandi. International Journal of Production Economics, Volume 172, Pages 76–94
Publication Year: 2016-01-29 00:00:00
[PDF] [Link to Article]Defense against jamming attacks has been an increasing concern for the military and disaster response authorities. The military uses jamming attacks as a tool to attack and disrupt terrorist׳s communications, because the open nature of wireless networks makes them vulnerable to various attacks. Many studies and a few survey papers are available in the literature, but none of these papers classify the attacks or the defense strategies by the type of wireless network affected, the attacker or defender׳s perspective, the type of game used to model the problem, such as Bayesian game, Stackelberg game, or the type of solution methodology, such as mathematical programming model and algorithm. This paper provides a comprehensive survey and a taxonomic classification to help interested researchers find the gaps in the literature and guide them to research areas that need to be explored.
-
Proactive Cost-Effective Risk Mitigation in a Low Volume High Value Supply Chain Using Fault-Tree Analysis
Michael D. Sherwin, Hugh Medal, Steven A. Lapp. International Journal of Production Economics, Volume 175, Pages 153–163
Publication Year: 2016-01-25 00:00:00
[PDF] [Link to Article]In this paper we use a well-accepted methodology, fault-tree analysis, to identify delay risks and proactively propose a cost-effective mitigation strategy within a low volume high value supply chain. The basis for the assessment is the bill of materials of the product being studied. The top-level event of interest represents the delay in delivering a product to a customer and lower-level events represent the probabilities associated with delays caused by quality and capability deficiencies within the supply chain of the product being studied. Supply chain risk mitigation strategies have been well documented in academic literature. However, much of what has been documented addresses such topics as facility location, inventory buffers, and is generally focused on response strategies once the risk has been realized. This paper presents a robust method to reduce the likelihood of delays in material flow by representing the system of suppliers within a supply chain as a fault-tree and proactively determining the optimum mitigation strategy for the portfolio. The approach is illustrated via real-world numerical scenarios based on hypothetical data sets and the results are presented.
-
Optimal traffic calming: A mixed-integer bi-level programming model for locating sidewalks and crosswalks in a multimodal transportation network to maximize pedestrians’ safety and network usability
Eghbal Rashidi, Mohsen Parsafard, Hugh Medal, Xiaopeng Li. Transportation Research Part E: Logistics and Transportation Review, Volume 91, Pages 33–50
Publication Year: 2016-01-20 00:00:00
[PDF] [Link to Article]We study the effect that installing sidewalks and crosswalks, as traffic calming facilities, has on the safety and usability of a transportation network with automobile, public transit and walking as modes of transportation. A mathematical programming model is proposed for this problem whose objective is to minimize the safety hazard for pedestrians and the total transportation cost of the network. We utilize a customized greedy heuristic and a simulated annealing algorithm for solving the problem. The computational results indicate that installing sidewalks and crosswalks at proper locations can reduce the overall transportation cost and improve pedestrians’ safety.
-
Interdicting Attack Graphs to Protect Organizations from Cyber Attacks: A Bi-Level Attacker-Defender Model
Apurba K. Nandi, Hugh R. Medal, Satish Vadlamani. Computers & Operations Research, Volume 75, Pages 118–131
Publication Year: 2016-01-18 00:00:00
[PDF] [Link to Article]Today's organizations are inherently open and connected, sharing knowledge and ideas in order to remain innovative. As a result, these organizations are also more vulnerable to information theft through different forms of security breaches caused by hackers and competitors. One way of understanding the vulnerability of an information system is to build and analyze the attack graph of that system. The attack graph of an information system contains all the paths that can be used to penetrate the system in order to breach critical assets. Although existing literature provides an abundance of attack graph generation algorithms, more methods are required to help analyze the attack graphs. In this paper, we study how best to deploy security countermeasures to protect an organization by analyzing the vulnerability of the organization through the use of its attack graph. In particular, we present an approach to find an optimal affordable subset of arcs, called an interdiction plan, on an attack graph that should be protected from attack to minimize the loss due to security breaches. We formulate this problem as a bi-level mixed-integer linear program and develop an exact algorithm to solve it. Experiments show that the algorithm is able to solve relatively large problems. Two heuristic methods, one with and the other without a heuristic to solve the master problem and both limiting the master problem branch-and-bound tree to only one node solve the large problems remarkably well. Experiments also reveal that the quality of an interdiction plan is relatively insensitive with respect to the error in the estimate of the attacker's budget, and that the breach loss drops sharply at the beginning, then levels off before finally dropping sharply again with increases in the security budget.
-
Models for Removing Links in a Network to Minimize the Spread of Infections
Apurba K. Nandi, Hugh R. Medal. Computers & Operations Research, Volume 69, Pages 10–24
Publication Year: 2016-01-15 00:00:00
[PDF] [Link to Article]Minimizing the spread of infections is a challenging problem, and it is the subject matter in many different fields such as epidemiology and cyber-security. In this paper, we investigate link removal as an intervention strategy and study the relative effectiveness of different link removal methods in minimizing the spread of infections in a network. With that in mind, we develop four connectivity-based network interdiction models and formulate these models as mixed integer linear programs. The first model minimizes the number of connections between infected and susceptible nodes; the second the number of susceptible nodes having one or more connections with infected nodes; the third the total number of paths between infected and susceptible nodes; and the fourth the total weight of the paths between infected and susceptible nodes. We also propose heuristic algorithms to solve the models. The network interdiction models act as link removal methods, i.e., each return a solution consisting of a set of links to remove in the network. We compare the effectiveness of these four methods with the effectiveness of an existing link removal method, a method based on link betweenness centrality, and random link removal method. Our results show that complete isolation of susceptible nodes from infected nodes is the most effective method in reducing the average number of new infections (reduce occurrence) under most scenarios, and the relative effectiveness of the complete isolation method increases with transmission probability. In contrast, removing the highest probability transmission paths is the most effective method in increasing the average time to infect half of the susceptible nodes (reduce speed) under most scenarios, and the relative effectiveness of this method decreases with transmission probability.
-
Allocating Protection Resources to Facilities When the Effect of Protection is Uncertain
Hugh R. Medal, Edward A. Pohl, Manuel D. Rossetti. IIE Transactions 48(3), 220–234.
Publication Year: 2016-01-10 00:00:00
[PDF] [Link to Article] We study a new facility protection problem in which one must allocate scarce protection resources to a set of facilities given that allocating resources to a facility only has a probabilistic effect on the facility’s post-disruption capacity. This study seeks to test three common assumptions made in the literature on modeling infrastructure systems subject to disruptions: 1) perfect protection, e.g., protecting an element makes it fail-proof, 2) binary protection, i.e., an element is either fully protected or unprotected, and 3) binary state, i.e., disrupted elements are fully operational or non-operational. We model this facility protection problem as a two-stage stochastic program with endogenous uncertainty. Because this stochastic program is non-convex we present a greedy algorithm and show that it has a worst-case performance of 0.63. However, empirical results indicate that the average performance is much better. In addition, experimental results indicate that the mean-value version of this model, in which parameters are set to their mean values, performs close to optimal. Results also indicate that the perfect and binary protection assumptions together significantly affect the performance of a model. On the other hand, the binary state assumption was found to have a smaller effect. -
The wireless network jamming problem subject to protocol interference
Hugh R. Medal. Networks 67(2), 111–125
Publication Year: 2016-01-05 00:00:00
[PDF] [Link to Article] We study the following questions related to wireless network security: Which jammer placement configuration during a jamming attack results in the largest degradation of network throughput? and Which network design strategies are most effective in mitigating a jamming attack? Although others have studied similar jammer placement problems, this article is the first to optimize network throughput subject to radio wave interference. We formulate this problem as a bi-level mixed-integer program, and solve it using a cutting plane approach that is able to solve networks with up to 81 transmitters, which is a typical size for studies in wireless network optimization. Experiments with the algorithm also yielded the following insights into wireless network jamming: (1) increasing the number of channels is the best strategy for designing a network that is robust against jamming attacks, and (2) increasing the range of the jammer is the best strategy for the attacker. -
A Bi-objective Analysis of the R-All-Neighbor P-Center Problem
Hugh R. Medal, Chase E. Rainwater, Edward A. Pohl, Manuel D. Rossetti. Computers & Industrial Engineering, Volume 72, Pages 114–128
Publication Year: 2014-01-30 00:00:00
[PDF] [Link to Article]In this paper we consider a generalization of the p-center problem called the r-all-neighbor p-center problem (RANPCP). The objective of the RANPCP is to minimize the maximum distance from a demand point to its r th-closest located facility. The RANPCP is applicable to facility location with disruptions because it considers the maximum transportation distance after (r-1) facilities are disrupted. While this problem has been studied from a single-objective perspective, this paper studies two bi-objective versions. The main contributions of this paper are (1) algorithms for computing the Pareto-efficient sets for two pairs of objectives (closest distance vs rth-closest distance and cost vs. rth-closest distance) and (2) an empirical analysis that gives several useful insights into the RANPCP. Based on the empirical results, the RANPCP produces solutions that not only minimize vulnerability but also perform reasonably well when disruptions do not occur. In contrast, if disruptions are not considered when locating facilities, the consequence due to facility disruptions is much higher, on average, than if disruptions had been considered. Thus, our results show the importance of optimizing for vulnerability. Therefore, we recommend a bi-objective analysis.
-
A Multi-objective Integrated Facility Location-Hardening Model: Analyzing the Pre- and Post-Disruption Tradeoff
Hugh R. Medal, Edward A. Pohl, Manuel D. Rossetti. European Journal of Operational Research, Volume 237, 257– 270
Publication Year: 2014-01-25 00:00:00
[PDF] [Link to Article]Two methods of reducing the risk of disruptions to distribution systems are (1) strategically locating facilities to mitigate against disruptions and (2) hardening facilities. These two activities have been treated separately in most of the academic literature. This article integrates facility location and facility hardening decisions by studying the minimax facility location and hardening problem (MFLHP), which seeks to minimize the maximum distance from a demand point to its closest located facility after facility disruptions. The formulation assumes that the decision maker is risk averse and thus interested in mitigating against the facility disruption scenario with the largest consequence, an objective that is appropriate for modeling facility interdiction. By taking advantage of the MFLHP’s structure, a natural three-stage formulation is reformulated as a single-stage mixed-integer program (MIP). Rather than solving the MIP directly, the MFLHP can be decomposed into sub-problems and solved using a binary search algorithm. This binary search algorithm is the basis for a multi-objective algorithm, which computes the Pareto-efficient set for the pre- and post-disruption maximum distance. The multi-objective algorithm is illustrated in a numerical example, and experimental results are presented that analyze the tradeoff between objectives.
-
Robust Facility Location: Hedging Against Failures
Ivan Hernandez, Jose Emmanuel Ramirez-Marquez, Chase Rainwater, Edward Pohl, Hugh Medal. Reliability Engineering & System Safety, Volume 123, Pages 73–80
Publication Year: 2014-01-20 00:00:00
[PDF] [Link to Article] While few companies would be willing to sacrifice day-to-day operations to hedge against disruptions, designing for robustness can yield solutions that perform well before and after failures have occurred. Through a multi-objective optimization approach this paper provides decision makers the option to trade-off total weighted distance before and after disruptions in the Facility Location Problem. Additionally, this approach allows decision makers to understand the impact on the opening of facilities on total distance and on system robustness (considering the system as the set of located facilities). This approach differs from previous studies in that hedging against failures is done without having to elicit facility failure probabilities concurrently without requiring the allocation of additional hardening/protections resources. The approach is applied to two datasets from the literature. -
Vulnerability Assessment and Re-routing of Freight Trains Under Disruptions: A Coal Supply Chain Network Application
Ridvan Gedik, Hugh Medal, Chase Rainwater, Ed A. Pohl, Scott J. Mason. Transportation Research Part E, Volume 71, 45–57
Publication Year: 2014-01-08 00:00:00
[PDF] [Link to Article]In this paper, we present a two-stage mixed integer programming (MIP) interdiction model in which an interdictor chooses a limited amount of elements to attack first on a given network, and then an operator dispatches trains through the residual network. Our MIP model explicitly incorporates discrete unit flows of trains on the rail network with time-variant capacities. A real coal rail transportation network is used in order to generate scenarios to provide tactical and operational level vulnerability assessment analysis including rerouting decisions, travel and delay costs analysis, and the frequency of interdictions of facilities for the dynamic rail system.
-
Models for reducing the risk of critical networked infrastructures
Hugh Medal, Stevenson J. Sharp, Ed Pohl, Chase Rainwater, Scott J. Mason. International Journal of Risk Assessment and Management, Volume 15 (No. 2/3), Pages 99-127
Publication Year: 2011-01-01 00:00:00
[PDF] [Link to Article] In this paper, we review the literature studying how to reduce the disruption risk to critical networked infrastructures. This is an important area of research because huge consequences result from infrastructure disruptions. As a result, this research area has grown a lot in the last decade. In this review we discuss articles from the literature, place them into categories, and suggest topics for future research. Our review shows that although this area is growing in popularity, there are still many important opportunities for future work.
Working Drafts
-
Computing the Vulnerability of Multi-Hop Wireless Networks: A Search for the Best Interference Model
Medal, H. and Schweitzer, D. Tech. rep. Starkville, MS: Mississippi State University.
Publication Year: 2017-01-01 00:00:00 -
Network interdiction model for cyber security against bounded rational attacker
Nandi, A. K., M. Halappanavar, Medal, H., and Bhuiyan, T. H. Tec
Publication Year: 2017-01-01 00:00:00 -
Risk-averse Bi-level Stochastic Network Interdiction Model for Cyber-security
Bhuiyan, T. H., Nandi, A. K., Medal, H., and M. Halappanavar Tech. rep. Starkville, MS: Mississippi State University.
Publication Year: 2017-01-01 00:00:00 [PDF] [Link to Article]
Under Review
-
A spatial branch-and-bound approach for maximization of non-factorable monotone continuous submodular functions.
H Medal, I Ahanor H Medal, I Ahanor (2022). A spatial branch-and-bound approach for maximization of non-factorable monotone continuous submodular functions
Publication Year: 2022-08-03 21:25:18 [Link to Article] -
Predicting Supplier Reliability in a Low Volume High Value Supply Chain Using Machine Learning.
Mike Sherwin, Medal, H., and C Mackenzie (2020). Tech. rep. Knoxville, TN: University of Tennessee.
Publication Year: 2020-06-17 18:56:29
Under Revision
-
A Multi-modal User Equilibrium Traffic Assignment with Network Expansion
Parsafard, M., Rashidi, E., X. Li, and Medal, H.
Publication Year: 2016-01-01 00:00:00
Peer-reviewed Conference Papers
-
A Visual Evaluation Study of Graph Sampling Techniques.
Zhang, Fangyan; Zhang, Song; Chung Wong, Pak; Medal, Hugh; Bian, Linkan; Swan II, J. Edward; Jankun-Kelly, T.J. Proceedings of the 7th annual IS&T International Symposium on Electronic Imaging 2017, no. 1 (2017): 110-117. Atlanta, GA.
Publication Year: 2017-01-01 00:00:00 [Link to Article] -
Analyzing the Vulnerability of a Single-Hop Wireless Network Grid
Schweitzer, D., Jafari, R., and Medal, H. Proceedings of the Industrial and Systems Engineering Research Conference. Anaheim, CA, United States.
Publication Year: 2016-12-01 00:00:00 -
Information diffusion in social networks with individual time constraints
Rashidi, E. and Medal, H. Proceedings of the Industrial and Systems Engineering Research Conference. Anaheim, CA, United States.
Publication Year: 2016-11-01 00:00:00 -
A Stochastic Programming Approach to Satellite Wildfire Observations
Hoskins, A. and Medal, H. Proceedings of the Industrial and Systems Engineering Research Conference. Anaheim, CA, United States.
Publication Year: 2016-10-01 00:00:00 -
Minimizing Expected Maximum Risk from Cyber-Attacks with Probabilistic Attack Success
Bhuiyan, T. H., Nandi, A. K., Medal, H., and M. Halappanavar Accepted for publication in IEEE International Conference on Technologies for Homeland Security. Waltham, Massachusetts, USA
Publication Year: 2016-09-01 00:00:00 -
Students’ Experiences with an Open-ended Client Project in a Graduate Course
Heier-Stamm, J, R Burch, and Medal, H. Proceedings of the 112nd ASEE Annual Conference and Exposition. Seattle, Washington, USA.
Publication Year: 2015-07-15 18:40:59 -
A Bi-Level Programming Model for the Wireless Network Jamming Placement Problem.
Satish Vadlamani, Hugh Medal, Burak Ekşioğlu, Pan Li Proceedings of the 2014 Industrial and Systems Engineering Research Conference
Publication Year: 2014-12-01 00:00:00 [PDF] -
A Network Design Model under Connectivity Constraints with Heterogeneous Services
Li, X., Medal, H., and Wang, J. Proceedings of the 2014 Transportation Research Board Conference. Washington, D.C.
Publication Year: 2014-11-01 00:00:00 -
Link removal models for minimizing the spread of infections in a network.
Nandi, A. K. and Medal, H. In: Proceedings of the 8th INFORMS Workshop on Data Mining and Health Informatics (DM-HI 2013). Ed. by O Seref, N Serban, and D Zeng. INFORMS.
Publication Year: 2013-06-17 18:50:15 -
A Software Tool for Intermittent Demand Analysis
Medal, H., M. D. Rossetti, Varghese, V.M., and E. A. Pohl 2009 Industrial Engineering Research Conference. Ed. by J. C. Smith and J. Geunes. Miami, Florida, pp.1658–1663 (CD)
Publication Year: 2009-01-01 00:00:00 -
Pickup and Delivery of Poultry in Rural Networks.
Medal, H., S. J. Gade, D.and Mason, R. D. Meller, and E. A. Pohl 2008 Industrial Engineering Research Conference. Ed. by J. Fowler and S. Mason. Vancouver, Canada, pp.1897–1902
Publication Year: 2008-01-01 00:00:00
Book Chapters
-
Security in Wireless Networks: An Operations Research Oriented Tutorial
Satish Vadlamani, Hugh Medal, Burak Ekşioğlu, Pan Li NATO Science for Peace and Security, Volume 37, Pages 272–288
Publication Year: 2014-01-01 00:00:00 [PDF] [Link to Article]
Dissertation
-
Locating and Protecting Facilities Subject to Random Disruptions and Attacks
Hugh Medal PhD thesis. Fayetteville, Arkansas: University of Arkansas.
Publication Year: 2012-01-01 00:00:00 [PDF]



