Development of a cyber security risk model using Bayesian networks

被引:62
|
作者
Shin, Jinsoo [1 ]
Son, Hanseong [2 ]
Ur, Rahman Khalil [1 ]
Heo, Gyunyoung [1 ]
机构
[1] Kyung Hee Univ, Yongin 446701, Gyeonggi Do, South Korea
[2] Joongbu Univ, Geumsan Gun 312702, Chungnam, South Korea
关键词
Cyber security; Activity-quality; Architecture analysis; Bayesian network; Reactor protection system; Research reactor; FRAMEWORK;
D O I
10.1016/j.ress.2014.10.006
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Cyber security is an emerging safety issue in the nuclear industry, especially in the instrumentation and control (I&C) field. To address the cyber security issue systematically, a model that can be used for cyber security evaluation is required. In this work, a cyber security risk model based on a Bayesian network is suggested for evaluating cyber security for nuclear facilities in an integrated manner. The suggested model enables the evaluation of both the procedural and technical aspects of cyber security, which are related to compliance with regulatory guides and system architectures, respectively. The activity-quality analysis model was developed to evaluate how well people and/or organizations comply with the regulatory guidance associated with cyber security. The architecture analysis model was created to evaluate vulnerabilities and mitigation measures with respect to their effect on cyber security. The two models are integrated into a single model, which is called the cyber security risk model, so that cyber security can be evaluated from procedural and technical viewpoints at the same time. The model was applied to evaluate the cyber security risk of the reactor protection system (RPS) of a research reactor and to demonstrate its usefulness and feasibility. (C) 2014 Elsevier Ltd. All rights reserved.
引用
收藏
页码:208 / 217
页数:10
相关论文
共 50 条
  • [1] Using Bayesian Networks for Cyber Security Analysis
    Xie, Peng
    Li, Jason H.
    Ou, Xinming
    Liu, Peng
    Levy, Renato
    [J]. 2010 IEEE-IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS DSN, 2010, : 211 - 220
  • [2] Quantitative Assessment of Cyber Security Risk using Bayesian Network-based model
    Mo, Sheung Yin Kevin
    Beling, Peter A.
    Crowther, Kenneth G.
    [J]. 2009 IEEE SYSTEMS AND INFORMATION ENGINEERING DESIGN SYMPOSIUM (SIEDS), 2009, : 183 - 187
  • [3] Biologically Inspired Risk Assessment in Cyber Security using Neural Networks
    Mihai-Gabriel, Ionita
    Patriciu, Victor-Valeriu
    [J]. 2014 10TH INTERNATIONAL CONFERENCE ON COMMUNICATIONS (COMM), 2014,
  • [4] Network Security Risk Mitigation Using Bayesian Decision Networks
    Khosravi-Farmad, Masoud
    Rezaee, Razieh
    Harati, Ahad
    Bafghi, Abbas Ghaemi
    [J]. 2014 4TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2014, : 267 - 272
  • [5] Application of Bayesian Network to Data-Driven Cyber-Security Risk Assessment in SCADA Networks
    Huang, Kaixing
    Zhou, Chunjie
    Tian, Yu-Chu
    Tu, Weixun
    Peng, Yuan
    [J]. 2017 27TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2017, : 96 - 101
  • [6] A Data-Driven Model for Software Development Risk Analysis Using Bayesian Networks
    Feng, Nan
    Li, Minqiang
    Xie, Jing
    Fang, Deying
    [J]. 2008 IEEE SYMPOSIUM ON ADVANCED MANAGEMENT OF INFORMATION FOR GLOBALIZED ENTERPRISES, PROCEEDINGS, 2008, : 41 - +
  • [7] Cyber security risk assessment for SCADA and DCS networks
    Ralston, P. A. S.
    Graham, J. H.
    Hieb, J. L.
    [J]. ISA TRANSACTIONS, 2007, 46 (04) : 583 - 594
  • [8] Cyber Security Risk management with attack detection frameworks using multi connect variational auto-encoder with probabilistic Bayesian networks
    Mouti, Samar
    Shukla, Surendra Kumar
    Althubiti, S. A.
    Ahmed, Mohammed Altaf
    Alenezi, Fayadh
    Arumugam, Mahendran
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2022, 103
  • [9] Beyond the Castle Model of cyber-risk and cyber-security
    Leuprecht, Christian
    Skillicorn, David B.
    Tait, Victoria E.
    [J]. GOVERNMENT INFORMATION QUARTERLY, 2016, 33 (02) : 250 - 257
  • [10] Risk assessment of smart grids under cyber-physical attacks using Bayesian networks
    AlMajali A.
    Wadhawan Y.
    Saadeh M.S.
    Shalalfeh L.
    Neuman C.
    [J]. International Journal of Electronic Security and Digital Forensics, 2020, 12 (04): : 424 - 436