Compliance-Driven Cybersecurity Planning Based on Formalized Attack Patterns for Instrumentation and Control Systems of Nuclear Power Plants

被引:0
|
作者
Lee, Minsoo [1 ]
Kwon, Hyun [2 ]
Yoon, Hyunsoo [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Daejeon, South Korea
[2] Korea Mil Acad, Dept Artificial Intelligence & Data Sci, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
D O I
10.1155/2022/4714899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The instrumentation and control (I&C) system of a nuclear power plant (NPP) employs a cybersecurity program regulated by the government. Through regulation, the government requires the implementation of security controls in order for a system to be developed and operated. Accordingly, the licensee of an NPP works to comply with this requirement, beginning in the development phase. The compliance-driven approach is efficient when the government supervises NPPs, but it is inefficient when a licensee constructs them. The security controls described in regulatory guidance do not consider system characteristics. In other words, the development organization spends a considerable amount of time excluding unnecessary control items and preparing the evidence to justify their exclusion. In addition, security systems can vary according to the developer's level of security knowledge, leading to differences in levels of security between systems. This paper proposes a method for a developer to select the appropriate security controls when preparing the security requirements during the early development phase; it is designed to ensure the system's security and reduce the cost of excluding unnecessary security controls. We have formalized the representation of attack patterns and security control patterns and identified the relationships between these patterns. We conducted a case study applying RG 5.71 in the Plant Protection System (PPS) to confirm the validity of the proposed method.
引用
收藏
页数:13
相关论文
共 35 条
  • [1] A Cybersecurity Risk Assessment Method and its Application for Instrumentation and Control Systems in Nuclear Power Plants
    Tian, Y.
    Li, J.
    Huang, X.
    IFAC PAPERSONLINE, 2022, 55 (09): : 238 - 243
  • [2] Digitizing instrumentation and control systems in nuclear power plants
    Aleite, W
    ATW-INTERNATIONALE ZEITSCHRIFT FUR KERNENERGIE, 1997, 42 (02): : 82 - 85
  • [3] CONTROL AND INSTRUMENTATION SYSTEMS IN NUCLEAR-POWER-PLANTS
    ALEITE, W
    HOFMANN, H
    JUNG, M
    ATOMWIRTSCHAFT-ATOMTECHNIK, 1987, 32 (03): : 122 - 128
  • [4] Cybersecurity Vulnerability Scanner for Digital Nuclear Power Plant Instrumentation and Control Systems
    Kim, Jae-Hong
    Choi, Yang-Seo
    Na, Jung-Chan
    PROCEEDINGS OF 2018 THE 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ARTIFICIAL INTELLIGENCE (CSAI 2018) / 2018 THE 10TH INTERNATIONAL CONFERENCE ON INFORMATION AND MULTIMEDIA TECHNOLOGY (ICIMT 2018), 2018, : 463 - 467
  • [5] Modernizing and maintaining instrumentation and control systems in nuclear power plants
    Naser, J
    Torok, R
    Shankar, R
    NUCLEAR TECHNOLOGY, 2003, 141 (01) : 3 - 9
  • [6] Reliability Measurement of Control and Instrumentation Systems of Nuclear Power Plants
    Singh, Pooja
    Singh, Lalit Kumar
    IEEE TRANSACTIONS ON RELIABILITY, 2023, 72 (02) : 727 - 736
  • [7] Diversity assessment of nuclear power plants instrumentation and control systems
    Kharchenko, V
    Yastrebenetsky, M
    Sklyar, V
    PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL 1- 6, 2004, : 1351 - 1356
  • [8] INSTRUMENTATION, CONTROL, AND ELECTRICAL SYSTEMS FOR NUCLEAR POWER PLANTS.
    Yamanaka, Yoshinobu
    Morimoto, Yoshinori
    Mitsubishi Electric Advance, 1987, 39 : 2 - 4
  • [9] Design Verification of Instrumentation and Control Systems of Nuclear Power Plants
    Singh, Lalit Kumar
    Vinod, Gopika
    Tripathi, A. K.
    IEEE TRANSACTIONS ON NUCLEAR SCIENCE, 2014, 61 (02) : 921 - 930
  • [10] INSTRUMENTATION AND CONTROL-SYSTEMS IN NUCLEAR-POWER-PLANTS
    ALEITE, W
    ATOMWIRTSCHAFT-ATOMTECHNIK, 1992, 37 (10): : 462 - 471