Development of the framework for quantitative cyber risk assessment in nuclear facilities

被引:3
|
作者
Son, Kwang-Seop [1 ]
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
机构
[1] Korea Atom Energy Res Inst, Secur R&D Team, Daejeon, South Korea
关键词
TPA; Threat scenario; Attack vector; TAM; Security control method; Quanti fication of cyber risk; STPA-SAFESEC; SAFETY;
D O I
10.1016/j.net.2023.03.023
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Industrial control systems in nuclear facilities are facing increasing cyber threats due to the widespread use of information and communication equipment. To implement cyber security programs effectively through the RG 5.71, it is necessary to quantitatively assess cyber risks. However, this can be challenging due to limited historical data on threats and customized Critical Digital Assets (CDAs) in nuclear facilities. Previous works have focused on identifying data flows, the assets where the data is stored and processed, which means that the methods are heavily biased towards information security concerns. Additionally, in nuclear facilities, cyber threats need to be analyzed from a safety perspective. In this study, we use the system theoretic process analysis to identify system-level threat scenarios that could violate safety constraints. Instead of quantifying the likelihood of exploiting vulnerabilities, we quantify Security Control Measures (SCMs) against the identified threat scenarios. We classify the system and CDAs into four consequence-based classes, as presented in NEI 13-10, to analyze the adversary impact on CDAs. This allows for the ranking of identified threat scenarios according to the quantified SCMs. The proposed framework enables stakeholders to more effectively and accurately rank cyber risks, as well as establish security and response strategies.(c) 2023 Korean Nuclear Society, Published by Elsevier Korea LLC. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:2034 / 2046
页数:13
相关论文
共 50 条
  • [1] A quantitative bow-tie cyber risk classification and assessment framework
    Sheehan, Barry
    Murphy, Finbarr
    Kia, Arash N.
    Kiely, Ronan
    JOURNAL OF RISK RESEARCH, 2021, 24 (12) : 1619 - 1638
  • [2] Study on Cyber Security Assessment for Wireless Network at Nuclear Facilities
    Kim, Sangwoo
    Lim, Hyunjong
    Lim, Soo-Min
    Shin, Ick-hyun
    2018 6TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSIC AND SECURITY (ISDFS), 2018, : 102 - 106
  • [3] A Thermodynamic Assessment of the Cyber Security Risk in Healthcare Facilities
    Fernandes, Filipe
    Alves, Victor
    Machado, Joana
    Miranda, Filipe
    Vicente, Dinis
    Ribeiro, Jorge
    Vicente, Henrique
    Neves, Jose
    TRENDS AND INNOVATIONS IN INFORMATION SYSTEMS AND TECHNOLOGIES, VOL 3, 2020, 1161 : 452 - 465
  • [4] A FRAMEWORK FOR CYBER SECURITY RISK ASSESSMENT OF SHIPS
    Svilicic, Boris
    Celic, Jasmin
    Kamahara, Junzo
    Bolmsten, Johan
    19TH ANNUAL GENERAL ASSEMBLY (AGA) OF THE INTERNATIONAL ASSOCIATION OF MARITIME UNIVERSITIES (IAMU), 2018, : 21 - 28
  • [5] Framework for risk assessment in cyber situational awareness
    Xi Rongrong
    Yun Xiaochun
    Hao Zhiyu
    IET INFORMATION SECURITY, 2019, 13 (02) : 149 - 156
  • [6] Probabilistic Risk Assessment Framework Development for Nuclear Power Plant
    Liu, Tao
    Tong, Jiejuan
    Zhao, Jun
    IEEM: 2008 INTERNATIONAL CONFERENCE ON INDUSTRIAL ENGINEERING AND ENGINEERING MANAGEMENT, VOLS 1-3, 2008, : 1330 - 1334
  • [7] Development of a defensive cyber damage assessment framework
    Fortson, Larry
    Grimaila, Michael
    ICIW 2007: PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2007, : 69 - 76
  • [8] Standardized Cyber Security Risk Assessment for Unmanned Offshore Facilities
    Teglasy, Balint Z.
    Katsika, Sokratis
    Lundteigen, Mary Ann
    3RD INTERNATIONAL WORKSHOP ON ENGINEERING AND CYBERSECURITY OF CRITICAL SYSTEMS (ENCYCRIS 2022), 2022, : 33 - 40
  • [9] Quantitative assessment of wildfire risk in oil facilities
    Khakzad, Nima
    Dadashzadeh, Mohammad
    Reniers, Genserik
    JOURNAL OF ENVIRONMENTAL MANAGEMENT, 2018, 223 : 433 - 443
  • [10] ManPro: Framework for the Generation and Assessment of Documentation for Nuclear Facilities
    Olaverri-Monreal, Cristina
    Dlugosch, Carsten
    Bengler, Klaus
    ADVANCES IN INFORMATION SYSTEMS AND TECHNOLOGIES, 2013, 206 : 849 - 859