Netinfo Security ›› 2025, Vol. 25 ›› Issue (10): 1493-1505.doi: 10.3969/j.issn.1671-1122.2025.10.002

Previous Articles     Next Articles

Review of Cyber Resilience Assessment Framework and Methods

ZHANG Dalong1,2, DING Shuguang2, HAN Zhilong1, FU Shouli1(), TANG Zhiqing1,2, SHI Lei1   

  1. 1. School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450001, China
    2. Songshan Laboratory, Zhengzhou 450000, China
  • Received:2025-05-30 Online:2025-10-10 Published:2025-11-07
  • Contact: FU Shouli E-mail:fusl@zzu.edu.cn

Abstract:

Cyber resilience emphasizes the system’s ability of perception, resistance, recovery, and adaptation when facing disasters or attacks. Constructing a resilient cyberspace can reduce security collapses and meanwhile mitigate the damage caused by security collapses and recover quickly from them, thereby enhancing the security resilience of cyberspace. The primary task in developing cyber resilience is to assess cyber resilience. This paper first briefly introduced the concept of cyber resilience and the need for resilience assessment. Subsequently, we reviewed the existing research from two aspects: cyber resilience assessment frameworks and assessment methods. For assessment frameworks, a classification method for existing frameworks from the perspective of process-oriented and result-oriented was proposed. For assessment methods, an introduction to existing methods from qualitative and quantitative perspective was provided. Moreover, this paper furthermore discussed the advantages and challenges associated with each type of framework and method. This analysis was important for guiding the application of existing frameworks and methods, as well as for researching new assessment frameworks and methods. Finally, we summarized and discuss the future directions of cyber resilience assessment.

Key words: cyber resilience assessment, process-oriented assessment, result-oriented assessment, area under the curve, network topology

CLC Number: