Abstract
Command and control (C2) networks are critical components of modern military systems, enabling information sharing and communications between systems. These systems operate in complex environments characterized by uncertain and evolving threats, creating a need for agile C2 networks. This paper presents a Cyber Complex Adaptive Systems approach for assessing the agility of adaptive C2 networks. Agent-based modeling is used to simulate the performance of a C2 network connecting unmanned aerial vehicles for a collaborative surveillance mission. Due to the importance of information sharing in C2, information entropy-based awareness is used to quantitatively evaluate C2 performance. Complex network methods are used to define initial network topologies and threats. Network adaptation through random rewiring is shown to recover lost C2 capabilities following network attacks, and in some cases improve performance relative to initial topologies. Inverse average path length and largest connected component fraction are shown to be important factors for maintaining C2 awareness, with inverse average path length being the better indicator of awareness.
Keywords
1. Introduction
Military systems are becoming increasingly connected and dependent upon networks for information sharing and system collaboration. This transformation from platform-centric to network-centric systems has been driven by the concepts of network-centric warfare (NCW) and network enabled capability (NEC).1–3 NCW and NEC focus on creating a connected military force able to achieve information superiority over adversaries. While there are many benefits of network-centric systems, there are also many risks associated with relying on networks. These risks are especially apparent in the cyber-domain of military operations. System designers must consider cyber-related threats and consequences of implementing NCW and NEC principles, particularly those related to Command and Control (C2) networks. However, C2 networks are complex systems difficult to model and evaluate. Current approaches for C2 research are limited in their ability to consider these complexities.
Across military missions, C2 is vital to mission success. Ultimately, the goal of C2 is to develop a common operational picture and shared intent among all forces to foster agility, adaptability, and situational awareness. To accomplish this goal, it is necessary to gain superiority across all domains, both physical and cyber, in order to effectively shape outcomes during military operations. Thus it becomes vitally important to gain an understanding of the architecture and behavior of the systems and networks that are used to establish and maintain C2 as they carry out functions to monitor, assess, and communicate information about the dynamically changing battlespace conditions to warfighters.
C2 networks need to be effective in a variety of situations, providing communications in ideal, as well as highly contested environments. The potential for unpredictable threats requires C2 networks that are not only effective, but perhaps more importantly, agile. Alberts defines C2 agility as the “capability to successfully cope with changes in circumstances” and identifies important aspects of agility to include responsiveness, versatility, flexibility, resilience, and adaptability. 4 Research on C2 agility has focused on redefining5,6 C2 and identifying novel ways to structure C2 networks in an effort to improve C2 performance and robustness. Much of the work on C2 structures suggests that decentralizing C2 and moving towards Edge C2 structures can improve C2 agility. Several studies use an Organization Management and Theory approach to show benefits of decentralized C2 approaches compared with classic, hierarchical ones.7–9 Other researchers use agent-based models (ABMs)4,10 and experiments with an online test bed 11 to study network-centric C2 approaches. Complex network methods, 12 social network analysis,13–15 and network entropy 16 have also been applied to C2, demonstrating the use of network methods to characterize and evaluate C2.
These studies show the potential for decentralized C2 structures to improve C2 agility and provide novel methods for characterizing C2 networks. However, they are limited in two primary ways. First, these studies focus on static networks, i.e. networks whose topology does not change. This focus ignores potential dynamics of network topologies, and consequently ignores how those dynamics may affect processes occurring on networks. As an example, a communications network may adapt its topology in response to its state (e.g. the congestion of information flow, or its vulnerability to network attacks), which in turn would affect the state of the network (e.g. improving information flow, or network robustness). These dynamics create a feedback between a network’s topology and its state. These types of networks are referred to as adaptive or coevolutionary networks, and have been a recent focus of many complex network researchers.17,18 Adaptive networks have the potential to improve C2 agility, and not considering adaptation in C2 may limit the ability of future military systems to handle the growing presence of cyber threats. We expand on current C2 agility research by investigating adaptive C2 networks.
Another limitation of current C2 research is the use of overall mission measures of performance to evaluate and compare potential C2 approaches. While the Department of Defense (DoD) defines C2 as “The exercise of authority and direction by a properly designated commander over assigned and attached forces in the accomplishment of the mission”, 19 the use of mission success as the sole criteria for evaluating the effectiveness of C2 has been called into question. 20 The quality of C2, especially in the network-centric age of modern warfare, must be assessed by measuring how well C2 functionality is executed. Since C2 is fundamentally used to develop information superiority for the warfighter, this means overcoming the “inability to quantify battlespace awareness, its mapping, or the capabilities to gather awareness”. 21 We complement current C2 research by providing a quantitative metric of battlespace awareness founded on the principles of information entropy that enables system designers to assess the performance of a C2 network, focusing on its ability to share information and provide awareness of the battlespace. 22
There are many complexities that must be considered when studying C2 networks. As military systems, or system-of-systems, are often composed of a mix of system types, researchers must consider system heterogeneity when modeling C2 networks. The dynamic, uncertain environments within which these systems operate also creates complex interactions between systems and their surroundings. These interactions often result in nonlinear behaviors that are difficult to predict. Focusing on the cyber domain within which C2 networks operate also requires new methods and metrics to evaluate performance. Our desire to consider adaptive networks further complicates the process of modeling and evaluating C2 performance. With the aforementioned limitations in current C2 research, there is a need for novel methods to model and evaluate adaptive C2 networks.
We present a Cyber Complex Adaptive Systems (CyCAS) approach for assessing the agility of adaptive C2 networks. This approach enables consideration of network adaptation and system heterogeneity, and provides methods for modeling complex interactions that may occur within a C2 network. Metrics for quantitatively evaluating C2 performance are also presented, based on work in the complex systems community.
Our paper is organized as follows. In Section 2, we motivate our approach of viewing C2 networks as CyCAS, and describe methods used to model and evaluate the agility of adaptive C2 networks. Section 3 describes the application problem used to demonstrate our method. Section 4 presents results comparing the performance of adaptive C2 networks under cases of interest. Section 5 provides conclusions from our work and future directions for this research.
2. A CyCAS perspective to C2
As natural and engineered systems have grown in scale and connectivity, new methods and frameworks have been developed to study these complex systems. Much of the research on complex systems has attempted to model the evolution of their structure and explain their behaviors from a global, or holistic, view of the system. Examples of complex systems include ant colonies, the brain, social networks, and the World Wide Web (WWW). While there is no universally accepted definition of a complex system, commonly identified characteristics are emergent behavior and self-organization.23,24 Complex systems are typically composed of independently acting agents that interact with each other and their environment. These interactions result in unexpected, emergent behaviors or features that characterize the system at a global level. A common emergent feature of complex systems is a non-regular, non-random structure that has evolved without any true centralized controller. The scale-free network topology of the WWW is an example of such a structure evolving despite the system having no central figure guide its evolution. 25 Self-organization occurs when system components organize themselves autonomously, such that a global structure emerges over time.
Complex Adaptive Systems (CAS) are complex systems with the ability to adapt to or learn from their environment.26,27 The adaptive capacity of CAS gives them a natural resilience to potential disturbances. 28 Since we aim to improve the agility of C2 networks, the inherent resilience of CAS is of great interest. CAS that focus on cyber systems and threats can be defined as CyCAS. CyCAS typically describe network-centric systems that are heavily dependent on communication links and show properties of CAS. Table 1 summarizes commonly identified characteristics of CAS and CyCAS.26,28,29
We choose to view C2 networks as CyCAS because of the many similarities between these types of systems. C2 networks are composed of heterogeneous systems, whose interactions with each other and their surroundings can result in emergent behaviors. In addition, we focus on adaptive C2 networks designed to provide reliable communications between systems. Emergence, adaptation, and communication links are defining characteristics of CyCAS. CAS and CyCAS are also well represented as networks, with nodes representing agents and links representing interactions or relationships between agents. 30 Given our focus on networks within C2, this further supports a CyCAS approach to C2. Taking a CyCAS approach also allows us to use knowledge gained from studying natural self-organizing systems, and apply those concepts to complex engineered systems such as C2 networks. 24
2.1. Agent-based modeling of adaptive C2 networks
Modeling C2 networks is a difficult task due to the number of component systems present in a C2 network and the interactions that occur between those systems. Viewing C2 as CyCAS allows us to use modeling methods for complex systems to study adaptive C2 networks.
Many studies of complex systems use differential equations to represent feedback effects between agents. A common application of these models is the study of dynamics on complex social systems, such as epidemic spreading in a network with the SIR model. Differential equation-based models aggregate agents into a small number of categories to study macroscopic interactions between groups of agents. These models can capture nonlinear behaviors and feedback within a system, but are limited in their ability to consider agent heterogeneity and system adaptation, as system structure and agent behaviors are assumed to be constant over time.31,32 One example of this is system dynamics (SD) models which were developed in the 1950s. An SD model is best described mathematically as a system of differential equations.33,34
Another modeling approach for complex systems is discrete event simulation (DES). DES models represent sequences of events, and thus are modeled in terms of individual entities that undergo sequentially occurring processes that change the state of the system. Rather than simulating the system operation in a continuous manner, the state of the system changes at discrete points in time allowing the simulation to “jump” from one event to the next. DES entities are usually passive in nature. DES requires a highly centralized approach in which much of the behavior is programmed globally. This top-down approach makes it difficult to fully consider heterogeneous and detailed behaviors of individual entities that often characterize complex systems and networks.34,35
Agent-based modeling is an alternative method for studying complex systems that captures system behaviors by modeling interactions between autonomous agents. An ABM is composed of a set of agents with defined attributes and behaviors, and an environment within which agents interact with each other. Agent attributes are used to represent characteristics of the agents being modeled, such as agent capabilities (e.g. the sensing range of a system in a military surveillance model) or descriptive properties of an agent (e.g. the pollution from a car in a transportation model). Varying agent attributes allows one to consider heterogeneity in the population. Agent behaviors are defined by rules representing how the modeler believes an agent should react when it encounters various situations. These rules can range from simplistic, “if–then” behaviors to very detailed and complex descriptions of how agents make decisions. For example, a simple model may have agents perform a specific action when they are within a certain distance of others, while a detailed model may use artificial intelligence to optimize the decision-making process of agents.
Agents move and interact with each other within a defined environment. The environment provides boundaries on where agents can move and information regarding their positions relative to each other. Environments can be as simple as a grid of cells defining possible agent locations or as complex as maps defined using geographic information system data. Detailed environments can be used to incorporate agent interactions with impeding structures, such as buildings, or terrain features, such as mountains. Information about the environment and an agent’s position within it is often used by agents to guide their actions.
Relationships between agents are also defined within an ABM. These relationships are typically defined as connections in a network. Connections between agents can describe many types of relationships, such as communication links for systems, friendships in a social network, or contacts for information diffusion or the spread of epidemics. The network topology of connections between agents limits their interactions and can have a large impact on the overall system behaviors seen in the model. This topology can be defined statically, where connections do not change over time, or dynamically, where agents adapt who they are connected with in response to the state of the system. Figure 1 shows components of an ABM and how they interact with each other on different levels of the model. Macal and North provide further descriptions of agents, their common characteristics, and considerations in creating an ABM in their tutorial of agent-based modeling. 36

ABMs are defined by agents, their attributes and behaviors, and the environment, as well agent–agent and agent–environment interactions.
ABMs are used in many applications, including the social sciences, epidemiology, biological systems, and military systems. Examples of ABMs in the social sciences are modeling crowd behaviors, flow and traffic management, organizational behaviors, and financial markets. 37 ABMs are used in epidemiology to study the spread of contagious diseases in populations, where people are represented as agents and connected together by various network topologies. 32 Self-organization of molecules has also been modeled with agent-based modeling, where optimal molecular structures are determined by defining a set of agent rules and allowing agents to arrange themselves. 38 Examples of agent-based modeling for military systems are the modeling of land combat,39,40 campaigns during previous battles, 41 and terrorist networks. 42
Although ABMs can be used for a wide range of applications, they are most useful for modeling systems that naturally decompose into a set of agents, display emergent behavior, and self-organize. ABMs are able to capture many of the emergent behaviors found in complex systems, even when simple behavioral rules are applied to agents. Emergent behaviors often result from a system being more than the sum of its parts. Since ABMs model the system at the local level rather than system level, they are able to represent the parts of the system and capture global effects that emerge from interactions between those parts. ABMs can also represent heterogeneity among agents and nonlinear behaviors, two other factors that contribute to emergence. Self-organization can be modeled within an ABM due to the connectivity among agents. As agents communicate with each other and sense their surroundings, they can use that information to alter their relationships or positions and self-organize. Bonabeau describes agent-based modeling and its benefits 37 and summarizes the following as situations in which to use ABMs:
when agent interactions are complex, nonlinear, discontinuous, or discrete;
when agent positions are not fixed;
when the agent population is heterogeneous;
when the topology of connections between agents is complex;
when agents can adapt and learn.
Agent-based modeling is a powerful technique for modeling complex systems, but has limitations that must be considered. Validation is an important step in the development of a model. Due to the complex interactions and emergent behaviors present in many ABMs, validating an ABM can be difficult. Validation of ABMs is often limited to the use of subject matter experts for validating general trends in the model or programmed agent behaviors. Another issue with agent-based modeling is the assumption of bounded rationality for agents. This assumption may lead to misleading results for systems driven by human behaviors, but can be alleviated by providing context when drawing conclusions from results.
Characteristics of ABMs make them well-suited for modeling CyCAS. ABMs are particularly appropriate for these systems due their ability to represent adaptive, connected, and heterogeneous agents and capture emergent behaviors that result from complex interactions. Similarities between ABMs and C2 are also present when C2 is viewed from the perspective of CyCAS. We therefore use agent-based modeling to simulate the performance of adaptive C2 networks.
2.2. Complex network methods for analyzing adaptive C2 networks
A C2 network is composed of nodes and links. We define nodes to represent systems or agents within a C2 system. For example, nodes can represent military vehicles connected by a C2 network. Links between nodes represent information or communication paths between systems. To evaluate adaptive C2 networks, we need to define an initial network topology, potential threats to the network, and a method of adaptation to respond to those threats. Since CAS often have a complex network structure, 28 we turn to the field of complex networks for tools to analyze adaptive C2 networks.
Most complex systems can be represented as a network.28,43 As the recognition of complex systems has grown in recent years, so has interest in understanding and modeling their underlying complex networks. Much of this research has taken a statistical approach, creating a field of research seeking to understand the science of networks. Network science differs from previous network research by focusing on statistical properties of large-scale, real networks and aiming to model and predict the evolution of those network topologies. 44
One of the most prominent discoveries in network science has been the identification of scale-free topologies in real-world networks such as the WWW, electrical power grids, citation networks of scientific publications, 25 metabolic networks, 45 and many others.44,46 Scale-free networks have a power-law degree distribution, meaning that the probability, P(k), that a node is connected to k other nodes scales as P(k) ~ k−γ. This degree distribution results in the presence of several hubs in a scale-free network. These hubs efficiently connect nodes within a network, limiting distances between nodes and the number of links needed to provide connectivity. Finding this topology in different real networks is especially interesting to CAS and CyCAS researchers, since these networks, which are all fundamentally different in function and purpose, naturally evolved to have the same structure over time. As self-organization is a defining feature of CAS, systems with a scale-free topology can be regarded as CAS. 28
Scale-free networks also have an inherent robustness to node failures. Several studies have shown that scale-free networks are able to maintain connectivity in the presence of repeated node failures.47–49 These results focus on changes in network structural properties, such as the size of the largest connected component (LCC) and network diameter, as nodes are removed from the network. While results show scale-free networks to be robust to random removals (i.e. random failures), they also show scale-free networks to be susceptible to targeted node removals (i.e. targeted attacks). Node targeting is typically done using node initial degree, recalculated degree after each removal, or a measure of node centrality (e.g. betweenness centrality).
We use scale-free networks as initial C2 network topologies because of their prevalence in real complex systems, in addition to their self-organization, efficiency, and robustness. Studies by Grant et al.
50
and Jarvis
51
support the use of scale-free networks for C2 by showing that many existing C2 networks have a scale-free structure. We use the Barabási–Albert (BA) preferential attachment model to create scale-free network topologies.
25
BA preferential attachment models the evolution of a network by starting with a small number, m0, of initially connected nodes and adding one node to the network at each time step. Each added node links with m existing nodes when it is added, where the probability, P(kj), that a node with degree kj is linked with is proportional to the degree of that node, i.e.
We also use randomly connected networks for initial network topologies. Most studies of scale-free network robustness compare scale-free networks to random networks with exponential degree distributions, such as Erdős–Rényi (ER) networks. Exponential networks have a random structure where most node degrees are similar to each other, limiting the occurrence of network hubs. ER networks can be generated by randomly connecting nodes based on a connection probability p. 52 However, ER networks can have disconnections (i.e. nodes that are not connected to each other) in the network topology. Since we are interested in military C2 networks, we assume that disconnections in the initial network topology are unlikely. To prevent disconnections, we create pseudo-random connected networks with N nodes and L links. 53 Networks begin with a single node. One node is added to the network at each step, with that node being randomly connected to an existing node in the network. There are N − 1 links in the network once all nodes have been added. The remaining L − (N − 1) links are randomly added to the network. These networks are “pseudo-random” because nodes added at the beginning of the process will be given more opportunities to gain connections than those added at the end. This bias results in networks that are not truly random in connectivity. Figure 2 shows example topologies for scale-free and pseudo-random networks with 20 nodes and 37 links.

Scale-free (a) and pseudo-random (b) networks with N = 20 and L = 37. Networks are visualized using a Force Atlas layout, with node size scaled by degree. Scale-free networks have network hubs with high connectivity; pseudo-random networks are more homogeneous in node degree.
We use random and targeted node removals to model threats to C2 networks, since this method enables consideration of a variety of relevant network threats. A node removal can represent a targeted cyber attack on an important node, random failure, or physical damage to a node. We assume node attacks and failures result in total loss of functionality, removing a node and its links from the network when it is attacked. We use random removals and targeting by recalculated node degree. Targeting by recalculated degree removes nodes with the highest degree at each attack, updating the degree of all nodes once the network structure is changed.
Network adaptation is modeled by allowing nodes to randomly rewire links following a node removal event. Only links disconnected by the most recent node removal are allowed to be rewired (see Figure 3). A time delay between when a node is removed and when the network adapts is implemented to represent the time it may take to decide how to adapt and rewire existing links. Rewiring nodes choose new neighbors randomly; if a node is already connected to all other nodes, that node does not rewire its link. Network researchers have considered similar defensive or adaptive mechanisms to improve network resilience, however most of these studies either pre-emptively rewired links54,55 or randomly re-added disconnected links anywhere in the network. 56

Network adaptation following targeted attacks using recalculated degree. The initial network is shown in (a) with the first targeted node being shaded in. The adapted network is shown in (b) with rewiring nodes shaded in and their rewired links represented by thick, darkened lines. The second targeted node is shown in (c), with the second adapted network shown in (d).
Complex networks are often analyzed using structural properties to characterize their connectivity and distances between nodes. We use LCC size to describe network connectivity. A connected component is a subset of nodes in a network such that there exists a path between every node pair in the subset, but no links between nodes in the subset and those outside of it. The LCC is the largest connected component in a network, with the size of the LCC being the number of nodes in the LCC. LCC fraction is normalized by network size, N. The size of the LCC is important for C2 networks since military systems rely on network connectivity to distribute information and gain awareness of the battlefield. Inverse average path length is used to characterize the efficiency of a network, representing how quickly nodes can get information to other locations in the network. Inverse average path length, 〈d〉′, is calculated using
where 〈d〉 is the average path length and dij is the geodesic distance (i.e. path length) between nodes i and j. Inverse average path length is used instead of average path length because of the potential for network disconnections, which would give infinite path lengths using the traditional metric. LCC fraction and inverse average path length allow one to track structural changes to a C2 network over time, as it adapts to node removals. They can also be used to represent network capabilities, though this assumes that these properties correlate to actual system capabilities.
2.3. Quantitatively evaluating C2 performance
Evaluating C2 performance requires a metric that captures the ability of a network to provide information superiority over an adversary. Isolating C2 performance from overall mission success is important because mission success is affected by many other aspects of a mission not directly related to C2 (e.g. weapon effectiveness, vehicle speed). A C2-specific metric enables quantitative comparisons of C2 network alternatives. The Naval Doctrine Publication for Command and Control provides insight into what this metric should measure, claiming that “The key to achieving command and control will always come down to finding a way to cope with the effects of uncertainty and time”. 57
Since we view C2 as a CyCAS, we also desire a C2 metric capable of capturing key features of complex systems, such as nonlinear relationships between inputs and outputs and emergent behavior. While these features should be represented as comprehensively as possible, we want to avoid imposing a prohibitively expensive computational burden.
We select Shannon’s information entropy to quantify C2 performance because it provides a simple calculation of uncertainty (for a given probability distribution), 58 while still being able to reflect common features of complex systems. Uncertainty reduction is related to C2 performance since information sharing within a C2 network should reduce the uncertainty a military force has regarding its mission over time. As systems in a C2 network gain awareness of their surroundings, this can be captured by probability distributions representing their beliefs in the current states (e.g. location) of targets of interest. Sharing information over a C2 network allows an entire military force to gain the awareness needed to successfully accomplish desired tasks.
Entropy is a fundamental property encountered in the field of thermodynamics. Entropy is used as a measure of the disorder or unpredictability in a system. The Second Law of Thermodynamics governs the change in entropy for systems undergoing thermodynamic processes. Shannon developed the concept of information entropy, in which entropy is applied to the uncertainty associated with a random variable, making it possible to quantify the expected value of the information contained in a message being passed between two systems. High levels of uncertainty in a message correspond to large amounts of measured entropy, meaning that the message possesses low information content.
A simple coin toss is an example that can help to illustrate the calculation of Shannon’s information entropy. The outcome of a coin flip represents a Bernoulli random variable, X, with two possible outcomes, heads or tails. The entropy of this random variable, H(X), represents the uncertainty in the outcome of a coin flip. For a discrete random variable, information entropy can be calculated using
where n is the number of possible outcomes (n = 2 for a two-sided coin). The entropy of the coin flip changes as the probability of an outcome changes (i.e. as the bias of the coin changes). Figure 4 plots entropy against the probability that a coin toss results in heads (it can alternatively represent tails since there are only two outcomes) and shows that entropy is maximized for an unbiased coin. The logarithmic base determines the units of information entropy. If a logarithmic base of b = 2 is chosen, then the value of H(X) is expressed in bits. The outcome of a coin toss can be represented by one bit, where x = 0 can represent a result of heads and x = 1 a result of tails. Unit selection is arbitrary as long as consistency is maintained for compared results. 59 Information entropy for a continuous random variable can be calculated using

Variation in information entropy as the probability of a coin flip outcome (e.g. an outcome of heads) changes.
Domercant et al. 22 detail an approach for applying information entropy to evaluate C2 performance during a mission simulation. Their approach enables quantification of the amount of uncertainty, or conversely awareness, that a C2 network possesses while trying to develop a common operational picture. This paper further develops the use of information entropy for comparative analysis of C2 performance. A description of the approach is presented as follows.
Discretize the battlespace into relevant features such as the ID, location, and team of friendly and enemy forces, environmental and hazardous features, and resources such as data and information. These features are referred to as state properties of the battlespace. Each state property is defined by a set of possible conditions or values. For example, the team state property may consist of three possible conditions, blue, red, or white.
Model each state property as a random variable, X, with a discrete probability distribution. State probability distributions are derived from the performance of system functions (e.g. sensing, classification) corresponding to related mission tasks.
Use information entropy to determine the amount of maximum uncertainty, U, based on the maximum number of possible conditions or outcomes:
Use information entropy to determine the amount of uncertainty, H(X), represented by a probability distribution. See equation (2).
Transform H(X) into a measure of awareness, A, using
Complete awareness of the battlespace means having absolute certainty of the condition of each state property or battlespace feature.
Calculate total awareness for a group of n agents (e.g. n blue team agents) considering m state properties (e.g. agent ID, location, team) as the mean awareness of all state properties over all active agents within that group (i.e. all agents that have not been removed from the simulation):
Incorporate the awareness calculations into a warfare simulation.
Analyze awareness versus time results to determine the effectiveness of various C2 networks.
Table 2 shows example awareness calculations for the team state property of an unidentified agent, with three cases shown. The first case represents maximum uncertainty, as the unidentified agent is estimated to be a friendly agent (blue), enemy agent (red), or neutral agent (white) with equal probability. Case 3 represents the opposite situation, where the agent’s team is identified with complete certainty, leading to an awareness value of one. Case 2 represents an intermediate situation, where the agent’s team is believed to be red, but with some uncertainty. This type of probability distribution results in an intermediate value of awareness.
Example entropy calculations for quantifying awareness of an agent’s team (using a log base of 2).
Since state probability distributions used for entropy-based awareness arise from interactions between agents, key features of complex systems can be captured by information entropy. For example, awareness is constructed such that it can measure the influence of information sharing at both individual and aggregate levels. This allows analysts to observe emergent behaviors that may arise during simulations. In addition, this metric can reflect nonlinear agent behaviors that often occur in warfare. For example, C2 awareness can be defined to account for and measure the following: 22
effects of misleading, false, or incorrectly processed data and information;
impact of holding false beliefs regarding the status of other agents within the battlespace;
effects of different levels of trust for particular sources of information.
A Bayesian approach can be used to update one state probability distribution with another (e.g. when an agent attempts to update its awareness with received information), with consideration of different levels of trust for shared awareness. This approach is based on Bayes’ theorem
and consists of four steps.
We describe the approach used with respect to two discrete state probability distributions representing a single state property, X (e.g. an agent’s team). The initial state distribution is represented by f0(x) = P(X = x) for x ∈ S, where S is the set of all n possible conditions for that state property (e.g. blue, red, or white teams, with n = 3). The new state distribution (used to update the initial one) is represented by f1(x) = P(X = x). The updated state distribution is some combination of the initial and new distributions, and is represented by f2(x) = P(X = x). The following describes steps used to update f0(x) with f1(x), resulting in f2(x).
Determine the bias (relative to complete uncertainty), b0(x), for each possible state condition, x, using the initial distribution f0(x). Similarly, determine the bias, b1(x), for each state condition of the new distribution f1(x):
Determine whether the new state distribution confirms or conflicts with the initial distribution. The new state distribution confirms the initial distribution if
Calculate a bias percentage, ρ(x), for each state condition, x, using the new state distribution, f1(x):
Calculate a bias multiplier, M(x), for each state condition in the new state distribution using
if the new distribution confirms the initial, or
if the new distribution conflicts with the initial.
Calculate bias multipliers, Madj(x), adjusted for the trust, T, given to the new state distribution, where T ∈ [0,1]. Complete distrust in the new distribution is represented by T = 0, in which case f2(x) = f0(x). Complete trust in the new distribution is represented by T = 1, in which case f2(x) is a combination of f0(x) and f1(x):
Apply adjusted bias multipliers to the initial state distribution and normalize to ensure that the updated distribution, f2(x), sums to one:
Here, f0(x) represents prior probabilities in this Bayesian approach.
Table 3 shows the impact of trust on the Bayesian calculations for shared awareness. In this example an initial state distribution, f0(x), is updated with new information, f1(x), that confirms the initial state distribution. The resulting updated state distribution, f2(x), is shown for various levels of trust in the new information. Since this is a confirming case, as trust in the new information is increased, so is the belief that the agent of interest is on the red team. Validation and real-world experimentation of this approach for state distribution updates is an area of future research.
Example state distribution updates for an agent’s team state property.
Entropy-based awareness results are analyzed using plots of awareness versus time. An example awareness plot is shown in Figure 5. These plots provide a visual means of expressing C2 performance for a given mission simulation. The higher the level of awareness, the better a C2 network is at processing and communicating relevant battlespace information. High levels of awareness are a necessary but not sufficient condition for mission success. C2 awareness plots give analysts a means to evaluate the impact of changes to C2 networks on C2 functions, independent from mission success.

Example awareness plot for a C2 network with 20 nodes, 37 links, and no adaptation. A node is randomly removed every 200 time steps (removal times are shown by vertical dashed lines).
This approach for evaluating C2 effectiveness enables comprehensive evaluations of potential C2 designs at the architectural, or system level. For complex systems such as C2 networks, there are a wide array of architectural parameters that affect both C2 effectiveness and mission success. The described entropy-based awareness metric can be used to assess potential combinations of these architectural parameters. For example, a detailed design of experiments can be constructed to analyze the effects of varying architectural attributes, such as system capabilities, network attributes that define the information sharing architecture, and the manner in which agents interact while sharing information. An analysis of variance can then be performed to explore and explain observations on how changes in the C2 architecture impact awareness and overall mission effectiveness. Changes in awareness at both the agent and network level can be correlated with or contrasted against gains or losses in overall mission effectiveness.
3. Unmanned aerial vehicle surveillance application problem
We apply the presented method to a notional military scenario where unmanned aerial vehicles (UAVs) are tasked with maintaining surveillance over enemy and neutral agents in a defined battlefield. 60 The UAVs (blue team) are connected by a C2 network, enabling information sharing throughout a mission. Enemy agents (red team) are also connected by their own C2 network, accounting for the fact that modern adversaries are often technologically advanced and well-connected. Neutral agents (white team) are not connected to anyone, modeling the presence of people or systems not associated with the blue or red team. This scenario could represent a military force trying to track the actions of terrorists in a populated civilian area. The ability to share information is crucial to success in such a mission, due to large geographic distances that may need to be covered and the movements of people in the area.
3.1. Model description
We use NetLogo to create an ABM of the selected application problem. NetLogo is a simulation environment commonly used to teach and create ABMs. 61 A large library of NetLogo models exists, ranging from simple predator–prey models to detailed traffic grid models. These models provide guidelines for creating ABMs.
Three types of agents are defined for the model: blue UAV agents, red enemy agents, and white neutral agents. Agents are defined by a set of attributes and actions. Table 4 shows important agent attributes that affect the simulation and differ between agent types. Blue agents perform search actions throughout a simulation, where they move in a snake-like search pattern within a square grid in the battlefield. They choose search grids using a maximin algorithm that maximizes the minimum distance to other blue agents. The purpose of searching through a grid is to sense other agents. Blue and red agents have the ability to sense agents within their sensing radius. Agents within the inner sensing radius are sensed with probability based on the maximum sensing probability of the sensing agent. Agents outside of the inner radius but within the outer sensing radius are sensed with a probability that linearly decreases with distance, following the generic sensor performance model of Perry et al. 62 Once an agent is sensed, the sensing agent classifies the believed operational level (operational or not operational), team (blue, red, or white), and location (based on discretized grids in the battlefield) of the sensed agent. The probability that an agent correctly classifies the state of another agent is also calculated using the generic sensor performance model. The three states of an agent are used to calculate the awareness agents have of each other. Agents are also able to send messages throughout their C2 network. These messages contain information regarding the states of sensed agents and current areas that agents are searching. Instead of searching through the battlefield, red agents attempt to evade detection by moving away from blue agents that they are aware of.
Summary of important agent attributes.
Agents move around a battlefield defined by a square environment of 3600 patches. A patch is a type of agent in NetLogo used to define an area over which agents can move. Patches are stationary, but can have attributes like typical agents. The battlefield is separated into 36 search grids, where each grid is a square area containing 100 patches (i.e. grids are 10 by 10 areas of patches). These grids are used to define blue agent search areas and specify agent locations for awareness calculations.
Connections between agents are defined by the C2 network of a team. Initial network topologies are either scale-free or pseudo-random. Each network consists of 20 nodes or agents. Networks begin with 19 or 37 links, corresponding to scale-free networks created with m0 = 2 and m = 1 (19 links) or m = 2 (37 links). These connections determine who agents can communicate with (i.e. who they send messages to). For example, when an agent senses and classifies the location of a nearby agent, it sends a message to its neighbors (i.e. agents it is connected with) containing the location of the sensed agent. Agents receiving that message use that information to update their own awareness, then forward that message to their own neighbors. Agents keep track of messages they have sent and received to prevent receiving duplicate messages. Figure 6 shows a screenshot of the ABM.

Screenshot of the NetLogo UAV model showing agents with their information links and square search grids in the battlefield (defined by darker shaded patches). Triangular agents are blue agents, “X”-shaped agents are red agents, and circular agents are white agents.
3.2. Implementation of awareness
Information entropy-based awareness is implemented using the three sensed states of agents: their operational level, team, and location. The operational state of an agent has two possible states, fully operational or completely inoperable. The team of an agent has three possible states, blue, red, or white. The location of an agent has 36 possible states, each corresponding to a grid in the battlefield. Entropy calculations use a logarithmic base of two. Team awareness is calculated for blue and red teams, using equation (6). State space distributions are updated with full trust (i.e. T = 1).
Awareness diffusion is also modeled to account for increased uncertainty in the state of an agent as time passes with no updated information regarding that agent. Awareness is diffused by slowly “pushing” state probability distributions towards a uniform distribution as time passes without updated information regarding that state property. For example, say agent i has just sensed the location of agent j and has complete certainty (i.e. awareness of one) that agent j is in grid x. Since agent j can move around the battlefield, if agent i hasn’t sensed or received any information regarding the location of agent j again after several time steps, the awareness agent i has of the location of agent j should decrease. Incorporating awareness diffusion increases the importance of timely information sharing, since extended time periods without information updates result in an awareness of zero for a given state property.
3.3. Measuring mission success
Overall mission success is also measured to determine the relationship between C2 effectiveness (i.e. awareness) and mission success. Since the objective of the modeled mission is to maintain surveillance of agents within the battlefield, a measure of search efficiency is used for mission success. Search efficiency is defined by
where Nblue, duplicate is the number of blue agents searching a grid already being searched by another blue agent, and Nblue is the number of active blue agents. For example, if three blue agents are searching grid x and two blue agents are searching grid y, Nblue, duplicate = (3 − 1) +(2 − 1). This metric captures the ability of the blue agents to maximize their surveillance by avoiding duplicate grid searches.
4. Results
Simulated results compare the performance of C2 networks with scale-free and pseudo-random initial topologies, subjected to random and targeted threats, and including or not including network adaptation. Since the ABM used is stochastic, results are averaged over 50 replications for each case. A case is defined by a specific set of inputs to the model. A replication is a single simulation run with specified inputs. Simulations are run to 1200 time steps, with one node being removed from the blue C2 network every 200 time steps (i.e. one blue agent is removed from the simulation every 200 time steps). For cases in which network adaptation is allowed, a 100 time step delay is required before agents rewire disconnected links. For discussion purposes, we divide a simulation into epochs, where an epoch represents a time period between node removals (e.g. epoch one contains time steps 0–199, epoch two contains time steps 200–399). Awareness results are shown for the mean blue team awareness, calculated with equation (6) for blue team agents.
Figure 7a shows that node removal strategy strongly affects the awareness blue agents are able to maintain for the simulated cases. Targeted removals greatly reduce the awareness of all networks, particularly following the first removal. Random removals also reduce awareness, but in a more gradual manner with less severity. Results for inverse average path length and LCC fraction (Figure 7b and c) suggest that targeting connected nodes has more impact on awareness than removing random nodes because of greater increases in path lengths and reductions in network connectivity.

Awareness (a), inverse average path length (b), and LCC fraction (c) for cases with 20 nodes, 19 links, and no adaptation. Initial network topologies are scale-free (SF) and pseudo-random (Rand.). Node removals are random (R) and degree recalculated (DR). Node removal and network adaptation times are indicated by dashed vertical lines. Cases with adaptation are shown in (d)–(f).
Initial network structure also affects the impact of node removals on C2 networks. Scale-free networks show more robustness to random attacks, but more susceptibility to targeting than pseudo-random networks. Scale-free networks are robust to random attacks because they have few nodes with high connectivity. Therefore, the probability of randomly removing a highly connected node is relatively low. However, the presence of these highly connected node hubs makes targeting by node degree very damaging to network connectivity. These results agree with previous studies on the robustness of scale-free networks compared with ER random networks.47,49,63 However, we note that our pseudo-random networks show more similarity to scale-free networks under targeted attacks than results from Albert, Jeong, and Barabási comparing ER and scale-free networks. 47 This difference is likely due to pseudo-random networks being biased towards having more highly connected nodes than ER networks, in addition to the small size of our networks.
We find scale-free networks to have better awareness than pseudo-random networks during the first epoch, where no nodes have been removed. This result is due to the efficiency of scale-free networks and the presence of node hubs that can quickly distribute information within a network. Figure 7b supports this explanation, as cases with a scale-free initial network topology show higher inverse average path lengths than those with pseudo-random topologies. Higher inverse average path length indicates shorter path lengths, on average, between nodes. Shorter path lengths mean information sent over a network is quickly received by the desired node. Timely information sharing is important because of the diffusion incorporated into awareness calculations. Results also suggest that inverse average path length may be a better indicator of C2 awareness than LCC fraction for the cases considered, since path length results capture the trend of increased awareness in the first epoch for cases with scale-free networks, while LCC fraction is the same for all cases. However, LCC fraction and inverse average path length both capture general awareness trends as nodes are removed over time.
Figure 7d shows that network adaptation, using random rewiring, enables C2 networks to recover lost awareness capabilities due to node removals and reduces the impact of future attacks. Adaptation actually improves the awareness of these networks relative to their initial state, despite having fewer active nodes searching the battlefield. This type of improvement suggests the potential for network adaptation, even based on a method as simple as random rewiring, to provide anti-fragility to C2 networks. 64 To gain insights into why C2 performance improves as networks adapt, we look at corresponding network metrics. Figure 7e and f show that inverse average path length and LLC fraction drop when nodes are removed, but increase once the network adapts. These network properties improve with adaptation because network density increases when nodes rewire, providing more paths for information to travel on. Increasing density also reduces the potential for future node removals to disconnect the network and isolate nodes from others, as well as disconnect short paths between nodes that enable fast information exchange. Focusing on performance in the first epoch, we again see that inverse average path length captures the trend of improved performance for scale-free networks compared to pseudo-random networks, while LCC fraction is maximized for both networks.
Figure 8 shows that search efficiency gradually increases as nodes are removed. This counter-intuitive result is likely due to the decreasing probability of agents choosing the same grid as the number of blue agents decreases. That is, as blue agents are removed, the number of agents choosing search grids decreases while the number of available grids stays the same. Therefore, it is simply less likely that agents will choose the same grid to search. However, search efficiency is also shown to depend on network topology and node removal strategy. As with awareness, search efficiency is better for cases subjected to random node removals. In addition, the search efficiency of scale-free networks is more sensitive to targeted removals than for pseudo-random networks. Search efficiency also improves as networks adapt by rewiring links. These similarities between search efficiency and awareness are expected since both metrics depend heavily on the ability to successfully share information. If agents have high awareness, they are able to make informed decisions of where to search, decreasing the likelihood of duplicate searches and wasted effort. These results suggest that maintaining high levels of awareness is important for achieving mission success, when measured by search efficiency.

Search efficiency for cases with scale-free and pseudo-random initial network topologies, 20 nodes, 19 links, no adaptation (a), and adaptation (b).
Figure 9 shows that for cases with 37 initial links (previous results were for networks with 19 links) and random node removals, adding adaptation to scale-free networks shows little benefit in awareness. Adaptation is not beneficial for these cases because the increased network density reduces the likelihood that a randomly removed node will strongly impact network connectivity, negating the need for adaptation. Therefore, decreases in C2 performance from random removals are solely due to less agents being available for sensing, rather than structural changes in the network. However, targeted removals still affect the network structure of scale-free and pseudo-random networks, greatly reducing C2 awareness. These results suggest that increasing network density may be sufficient to provide C2 agility against random failures, but network adaptation should be considered when highly connected nodes are susceptible to attacks.

Awareness for cases with scale-free and pseudo-random initial network topologies, 20 nodes, 37 links, no adaptation (a), and adaptation (b).
Previous results have focused on awareness and network metrics averaged over all replications. Analyzing data from stochastic simulations should also consider variability in performance. Figure 10 shows quartile plots for the performance of scale-free networks subjected to random and targeted attacks. Plotting the first, second (i.e. median), and third quartiles allows one to make comparisons regarding the range in performance one can expect for different cases. For cases with no adaptation, random node removal shows larger variability in awareness compared with targeted removals. Larger variation is expected for random threats since all nodes have equal probability of being removed, regardless of their importance to the network. However, networks with adaptation show similar variation in awareness regardless of the removal strategy. Similar results are seen for inverse average path length and LCC fraction.

Quartile plots of awareness for cases with scale-free initial network topologies, 20 nodes, 19 links, no adaptation (a), and adaptation (b). Lightly shaded lines show first and third quartile results from 50 replication runs for each case. Darker lines show second quartile results.
5. Discussion
This paper presents a CyCAS approach for evaluating the agility of adaptive C2 networks. Previous work on C2 agility has focused on static networks, with limited quantification of how well C2 networks perform information sharing functions. We extend the C2 literature by implementing network adaptation as a method to achieve agility and measuring C2 performance based on awareness and uncertainty reduction. Viewing C2 from the perspective of CyCAS, we are able to use methods commonly applied to complex systems to model and evaluate adaptive C2 networks.
Agent-based modeling is used to simulate C2 performance for networked UAVs on a surveillance mission. Complex network methods are used to define network topologies and model threats to those networks. Information entropy enables the definition of a quantitative metric for C2 performance, focusing on the awareness agents are able to maintain throughout a simulation. Inverse average path length and LCC fraction complement the awareness metric, providing additional insights into C2 performance and the evolution of network structures as networks adapt to threats with random rewiring.
This CyCAS method for analyzing C2 agility allows researchers to make quantitative comparisons between potential network designs and adaptation strategies. Results show the potential for network adaptation to improve C2 agility in the presence of random and targeted node removals. Network adaptation typically enables systems to recover lost awareness capabilities due to node removals, and in some cases improves performance relative to the initial network. However, we also find that adaptation provides little benefit to dense networks for the cases considered, since the link redundancy in those networks reduces the effects of node removals, negating the need for adaptation. We also find that initial network topology can have a large impact on the performance and robustness of a network. Our results agree with previous work on complex network robustness, although we extend the literature by considering simulated network capabilities (i.e. C2 awareness) in addition to network structural properties.
Supplementing C2 awareness with traditional network metrics gives a deeper understanding of C2 performance, providing insights into desirable network properties with respect to awareness. Network properties allow researchers to track the adaptation of networks and understand how these structural changes affect network performance. For example, we find that connectivity and network path lengths are important to the awareness provided by a C2 network. However, our results suggest that inverse average path length may be a better indicator of awareness than LCC fraction for the simulated mission, due to slight differences in observed trends. The importance of short path lengths in military networks is supported by Dekker. 65
Potential extensions to this work include formal validation of the ABM and further development of network adaptation strategies. Our implementation of adaptation was limited to random rewiring. Additional research into network adaptation should consider more intelligent and complex methods for determining how nodes rewire links over time. Incorporating learning into the adaptation method could further improve network agility and provide insights into how we can achieve anti-fragility in C2 networks. We also intend to improve the fidelity of the network model by incorporating various communications packages and modeling the effects of range on network capabilities. This work can be further extended by incorporating the dimensions of C2 agility identified by Alberts and Hayes 66 that are not addressed in this work. We focus on robustness to threat types, resilience to node removals, responsiveness through consideration of network path lengths, and adaptation through random rewiring. Other important aspects of agility include flexibility and innovation.
Footnotes
Funding
This research received no specific grant from any funding agency in the public, commercial, or not-for-profit sectors.
