This paper addresses the problem of distributed resilient state estimation and control for linear time-invariant systems in the presence of malicious false data injection sensor attacks and bounded noise. We consider a system operator (defender) capable of deploying cybersecurity measures to counteract malicious sensor compromises. Although such measures enhance resilience against adversarial attacks, they may incur substantial costs; hence, it is crucial to strategically select countermeasures that balance resilience gains and cost efficiency. We first demonstrate that the system's resilience against attacks is maximized through the appropriate implementation of security measures, implying that no attacker can execute undetectable sensor attacks. Building on this analysis, we formulate an optimization problem for optimal security measures under cost constraints, which is NP-hard. We then propose an exact algorithm and derive a polynomial-time approximation algorithm that achieves a constant-factor performance guarantee. Furthermore, we develop a distributed resilient state estimation and control scheme informed by the optimal security measure and establish conditions that guarantee bounded estimation and control errors. Finally, we validate the efficacy of our approach through numerical simulations of a vehicle platooning scenario.
QC 20260713