Compliance-Driven Cybersecurity Planning Based on Formalized Attack Patterns for Instrumentation and Control Systems of Nuclear Power Plants

被引:0
|
作者
Lee, Minsoo [1 ]
Kwon, Hyun [2 ]
Yoon, Hyunsoo [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Daejeon, South Korea
[2] Korea Mil Acad, Dept Artificial Intelligence & Data Sci, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
D O I
10.1155/2022/4714899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The instrumentation and control (I&C) system of a nuclear power plant (NPP) employs a cybersecurity program regulated by the government. Through regulation, the government requires the implementation of security controls in order for a system to be developed and operated. Accordingly, the licensee of an NPP works to comply with this requirement, beginning in the development phase. The compliance-driven approach is efficient when the government supervises NPPs, but it is inefficient when a licensee constructs them. The security controls described in regulatory guidance do not consider system characteristics. In other words, the development organization spends a considerable amount of time excluding unnecessary control items and preparing the evidence to justify their exclusion. In addition, security systems can vary according to the developer's level of security knowledge, leading to differences in levels of security between systems. This paper proposes a method for a developer to select the appropriate security controls when preparing the security requirements during the early development phase; it is designed to ensure the system's security and reduce the cost of excluding unnecessary security controls. We have formalized the representation of attack patterns and security control patterns and identified the relationships between these patterns. We conducted a case study applying RG 5.71 in the Plant Protection System (PPS) to confirm the validity of the proposed method.
引用
收藏
页数:13
相关论文
共 35 条
  • [31] Reliability analysis of microcomputer circuit modules and computer based control systems important to safety of nuclear power plants
    Khobare, S.K.
    Shrikhande, S.V.
    Chandra, Umesh
    Govindarajan, G.
    Reliability Engineering and System Safety, 1998, 59 (02): : 253 - 258
  • [32] Reliability analysis of microcomputer circuit modules and computer based control systems important to safety of nuclear power plants
    Khobare, SK
    Shrikhande, SV
    Chandra, U
    Govindarajan, G
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 1998, 59 (02) : 253 - 258
  • [33] Quantitative evaluation of common cause failures in high safety-significant safety-related digital instrumentation and control systems in nuclear power plants
    Bao, Han
    Zhang, Hongbin
    Shorthill, Tate
    Chen, Edward
    Lawrence, Svetlana
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2023, 230
  • [34] APPROACH FOR THE EVALUATION OF THE IMPACT OF POTENTIAL SOFTWARE FAILURES IN SOFTWARE-BASED INSTRUMENTATION AND CONTROL (I&C) EQUIPMENT IN NUCLEAR POWER PLANTS
    Mbonjo, Herve
    Jopen, Manuela
    Ulrich, Birte
    Sommer, Dagmar
    PROCEEDINGS OF THE 24TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING, 2016, VOL 1, 2016,
  • [35] Ultimate design and testing TPTS-based control systems with using full-scaled physical models of nuclear power plants
    Zhukov, I. M.
    Tolokonsky, A. O.
    2ND INTERNATIONAL TELECOMMUNICATION CONFERENCE ADVANCED MICRO- AND NANOELECTRONIC SYSTEMS AND TECHNOLOGIES, 2019, 498