AN ANALYSIS OF TECHNICAL SECURITY CONTROL REQUIREMENTS FOR DIGITAL I&C SYSTEMS IN NUCLEAR POWER PLANTS

被引:23
|
作者
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
Park, Gee-Yong [1 ]
Kwon, Kee-Choon [1 ]
Lee, Dong-Young [1 ]
Lee, Cheol-Kwon [1 ]
机构
[1] Korea Atom Energy Res Inst, Taejon 305353, South Korea
关键词
Instrumentation and Control Systems; Nuclear Power Plant; Cyber Security; Technical Security Controls; Critical Digital Assets;
D O I
10.5516/NET.04.2012.091
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Instrumentation and control systems in nuclear power plants have been digitalized for the purpose of maintenance and precise operation. This digitalization, however, brings out issues related to cyber security. In the most recent past, international standard organizations, regulatory institutes, and research institutes have performed a number of studies addressing these systems cyber security.. In order to provide information helpful to the system designers in their application of cyber security for the systems, this paper presents methods and considerations to define attack vectors in a target system, to review and select the requirements in the Regulatory Guide 5.71, and to integrate the results to identify applicable technical security control requirements. In this study, attack vectors are analyzed through the vulnerability analyses and penetration tests with a simplified safety system, and the elements of critical digital assets acting as attack vectors are identified. Among the security control requirements listed in Appendices B and C to Regulatory Guide 5.71, those that should be implemented into the systems are selected and classified in groups of technical security control requirements using the results of the attack vector analysis. For the attack vector elements of critical digital assets, all the technical security control requirements are evaluated to determine whether they are applicable and effective, and considerations in this evaluation are also discussed. The technical security control requirements in three important categories of access control, monitoring and logging, and encryption are derived and grouped according to the elements of attack vectors as results for the sample safety system.
引用
收藏
页码:637 / 652
页数:16
相关论文
共 50 条
  • [1] Safety and security aspects in design of digital safety I&C in nuclear power plants
    Ding, Y.
    Waedt, K.
    KERNTECHNIK, 2016, 81 (02) : 185 - 187
  • [2] Next Generation Technologies in the Digital I&C Systems for Nuclear Power Plants
    Maekawa, Tatsuyuki
    Hayashi, Toshifumi
    ADVANCES IN LIGHT WATER REACTOR TECHNOLOGIES, 2011, : 223 - 250
  • [3] A CYBER SECURITY RISK ASSESSMENT FOR THE DESIGN OF I&C SYSTEMS IN NUCLEAR POWER PLANTS
    Song, Jae-Gu
    Lee, Jung-Woon
    Lee, Cheol-Kwon
    Kwon, Kee-Choon
    Lee, Dong-Young
    NUCLEAR ENGINEERING AND TECHNOLOGY, 2012, 44 (08) : 919 - 928
  • [4] Replacing turbine I&C systems in nuclear power plants
    Landis, R
    ATW-INTERNATIONAL JOURNAL FOR NUCLEAR POWER, 2005, 50 (02): : 102 - +
  • [5] INTEGRATING CYBER SECURITY INTO NUCLEAR DIGITAL I&C SAFETY SYSTEMS
    Zhang, Deanna Jing
    PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING 2010, VOL 1, 2011, : 897 - 901
  • [6] A NOVEL INTUITIVE DYNAMIC MODELLING METHOD FOR DIGITAL I&C SYSTEMS IN NUCLEAR POWER PLANTS
    Shin, Seung Ki
    Goh, Gyoung Tae
    Seong, Poong Hyun
    ANNALS OF DAAAM FOR 2008 & PROCEEDINGS OF THE 19TH INTERNATIONAL DAAAM SYMPOSIUM: INTELLIGENT MANUFACTURING & AUTOMATION: FOCUS ON NEXT GENERATION OF INTELLIGENT SYSTEMS AND SOLUTIONS, 2008, : 1247 - 1248
  • [7] Cyberphysical Security and Dependability Analysis of Digital Control Systems in Nuclear Power Plants
    Cho, Chi-Shiang
    Chung, Wei-Ho
    Kuo, Sy-Yen
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2016, 46 (03): : 356 - 369
  • [8] An Integrated Risk Assessment Process of Safety-Related Digital I&C Systems in Nuclear Power Plants
    Zhang, Hongbin
    Bao, Han
    Shorthill, Tate
    Quinn, Edward
    NUCLEAR TECHNOLOGY, 2023, 209 (03) : 377 - 389
  • [9] A communication network with high safety, maintainability, and user convenience for digital I&C systems of nuclear power plants
    Lee, JM
    Park, TR
    Kim, HS
    Young, S
    Shin, SY
    Choi, JY
    Kwon, WH
    Lee, SW
    Song, SI
    ETFA 2001: 8TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOL 1, PROCEEDINGS, 2001, : 353 - 358
  • [10] A QUANTITATIVE APPROACH FOR RELIABILITY EVALUATION OF SAFETY I&C SYSTEMS IN NUCLEAR POWER PLANTS
    Liu Dongxu
    Xu Dongling
    Zhang Shuhui
    Hu Xiaoying
    PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING, 2017, VOL 1, 2017,