Development of the framework for quantitative cyber risk assessment in nuclear facilities

被引:3
|
作者
Son, Kwang-Seop [1 ]
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
机构
[1] Korea Atom Energy Res Inst, Secur R&D Team, Daejeon, South Korea
关键词
TPA; Threat scenario; Attack vector; TAM; Security control method; Quanti fication of cyber risk; STPA-SAFESEC; SAFETY;
D O I
10.1016/j.net.2023.03.023
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Industrial control systems in nuclear facilities are facing increasing cyber threats due to the widespread use of information and communication equipment. To implement cyber security programs effectively through the RG 5.71, it is necessary to quantitatively assess cyber risks. However, this can be challenging due to limited historical data on threats and customized Critical Digital Assets (CDAs) in nuclear facilities. Previous works have focused on identifying data flows, the assets where the data is stored and processed, which means that the methods are heavily biased towards information security concerns. Additionally, in nuclear facilities, cyber threats need to be analyzed from a safety perspective. In this study, we use the system theoretic process analysis to identify system-level threat scenarios that could violate safety constraints. Instead of quantifying the likelihood of exploiting vulnerabilities, we quantify Security Control Measures (SCMs) against the identified threat scenarios. We classify the system and CDAs into four consequence-based classes, as presented in NEI 13-10, to analyze the adversary impact on CDAs. This allows for the ranking of identified threat scenarios according to the quantified SCMs. The proposed framework enables stakeholders to more effectively and accurately rank cyber risks, as well as establish security and response strategies.(c) 2023 Korean Nuclear Society, Published by Elsevier Korea LLC. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:2034 / 2046
页数:13
相关论文
共 50 条
  • [31] Development of safety assessment code for decommissioning of nuclear facilities (DECDOSE)
    Japan Atomic Energy Agency, Tokai-mura, Ibaraki, Japan
    Int Conf Nucl Eng Proc ICONE, (25-32):
  • [32] Development of a framework for metals risk assessment
    Sappington, K
    Fairbrother, A
    Wentsel, R
    Wood, W
    JOURNAL OF ENVIRONMENTAL MONITORING, 2003, 5 (06): : 123N - 132N
  • [33] Cyber-Security Risk Assessment Framework for Blockchains in Smart Mobility
    Al Mallah, Ranwa
    Lopez, David
    Farooq, Bilal
    IEEE OPEN JOURNAL OF INTELLIGENT TRANSPORTATION SYSTEMS, 2021, 2 : 294 - 311
  • [34] Implementation of cyber security for safety systems of nuclear facilities
    Park, JaeKwan
    Suh, YongSuk
    Park, Cheol
    PROGRESS IN NUCLEAR ENERGY, 2016, 88 : 88 - 94
  • [35] Cyber Security Risk Assessment Framework for Cloud Customer and Service Provider
    Kumari, N. Sujata
    Vurukonda, Naresh
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (12) : 683 - 697
  • [36] Model Based Risk Assessment and Risk Mitigation Framework for Cyber-Physical Systems
    Gowdanakatte, Shwetha
    Ray, Indrakshi
    Abdelgawad, Mahmoud
    2023 5TH IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS, TPS-ISA, 2023, : 203 - 212
  • [37] Cyber risk assessment
    Nicholson, Todd
    CONTROL ENGINEERING, 2007, 54 (11) : C11 - C12
  • [38] Special section on the Seismic Analysis and Risk Assessment of Nuclear Facilities Foreword
    Bolisetti, Chandrakanth
    NUCLEAR TECHNOLOGY, 2021, 207 (11)
  • [39] A Framework for Development of Risk-Informed Autonomous Adaptive Cyber Controllers
    Veeramany, Arun
    Hutton, William J.
    Sridhar, Siddharth
    Gourisetti, Sri Nikhil Gupta
    Coles, Garill A.
    Skare, Paul M.
    JOURNAL OF COMPUTING AND INFORMATION SCIENCE IN ENGINEERING, 2019, 19 (04)
  • [40] Risk Assessment of Spent Nuclear Fuel Facilities Considering Climate Change
    Tolo, Silvia
    Patelli, Edoardo
    Beer, Michael
    ASCE-ASME JOURNAL OF RISK AND UNCERTAINTY IN ENGINEERING SYSTEMS PART A-CIVIL ENGINEERING, 2017, 3 (02):