Compliance-Driven Cybersecurity Planning Based on Formalized Attack Patterns for Instrumentation and Control Systems of Nuclear Power Plants

被引:0
|
作者
Lee, Minsoo [1 ]
Kwon, Hyun [2 ]
Yoon, Hyunsoo [1 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Daejeon, South Korea
[2] Korea Mil Acad, Dept Artificial Intelligence & Data Sci, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
D O I
10.1155/2022/4714899
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The instrumentation and control (I&C) system of a nuclear power plant (NPP) employs a cybersecurity program regulated by the government. Through regulation, the government requires the implementation of security controls in order for a system to be developed and operated. Accordingly, the licensee of an NPP works to comply with this requirement, beginning in the development phase. The compliance-driven approach is efficient when the government supervises NPPs, but it is inefficient when a licensee constructs them. The security controls described in regulatory guidance do not consider system characteristics. In other words, the development organization spends a considerable amount of time excluding unnecessary control items and preparing the evidence to justify their exclusion. In addition, security systems can vary according to the developer's level of security knowledge, leading to differences in levels of security between systems. This paper proposes a method for a developer to select the appropriate security controls when preparing the security requirements during the early development phase; it is designed to ensure the system's security and reduce the cost of excluding unnecessary security controls. We have formalized the representation of attack patterns and security control patterns and identified the relationships between these patterns. We conducted a case study applying RG 5.71 in the Plant Protection System (PPS) to confirm the validity of the proposed method.
引用
收藏
页数:13
相关论文
共 37 条
  • [21] Regulatory and safety aspects concerning the implementation of modern instrumentation and control systems in German nuclear power plants
    Berg, HP
    Schaefer, T
    Seidel, F
    KERNTECHNIK, 1997, 62 (01) : 40 - 44
  • [22] Aging Treatment Implementation Strategy for Instrumentation and Control Equipment in Nuclear Power Plants Based on Preventive Replacement
    Chen, Yongwei
    Zhang, Zeyong
    Li, Dong
    NUCLEAR TECHNOLOGY, 2018, 204 (03) : 378 - 385
  • [23] Cyber threat assessment of machine learning driven autonomous control systems of nuclear power plants
    Yockey, Patience
    Erickson, Anna
    Spirito, Christopher
    PROGRESS IN NUCLEAR ENERGY, 2023, 166
  • [24] Understanding radiation effects in SRAM-based field programmable gate arrays for implementing instrumentation and control systems of nuclear power plants
    Nidhin, T. S.
    Bhattacharyya, Anindya
    Behera, R. P.
    Jayanthi, T.
    Velusamy, K.
    NUCLEAR ENGINEERING AND TECHNOLOGY, 2017, 49 (08) : 1589 - 1599
  • [25] Application Research and Practice of Simulation Analysis Method in Seismic Evaluation of Instrumentation and Control Systems in Nuclear Power Plants
    Li, Yan
    Zou, Hua-ming
    Zhou, Yang
    NEW ENERGY POWER GENERATION AUTOMATION AND INTELLIGENT TECHNOLOGY, SICPNPP 2024, VOL 1, 2024, 1249 : 525 - 537
  • [26] A Redundancy-Guided Approach for the Hazard Analysis of Digital Instrumentation and Control Systems in Advanced Nuclear Power Plants
    Shorthill, Tate
    Bao, Han
    Zhang, Hongbin
    Ban, Heng
    NUCLEAR TECHNOLOGY, 2022, 208 (05) : 892 - 911
  • [27] COMPUTER-BASED CONTROL-SYSTEMS OF NUCLEAR-POWER PLANTS
    KALASNIKOV, VK
    SUGAM, RA
    OLSEVSKIJ, JN
    KERNENERGIE, 1975, 18 (10): : 302 - 311
  • [28] Use of STPA as a diverse analysis method for optimization and design verification of digital instrumentation and control systems in nuclear power plants
    Rejzek, Martin
    Hilbes, Christian
    NUCLEAR ENGINEERING AND DESIGN, 2018, 331 : 125 - 135
  • [29] A Design of Intelligent Online Inspection Based on Digital Control Systems in Nuclear Power Plants
    Deng, Ze Fan
    Li, Gang
    Wang, Gui-lan
    Liu, Chun-ming
    Shi, Gui-lian
    NEW ENERGY POWER GENERATION AUTOMATION AND INTELLIGENT TECHNOLOGY, SICPNPP 2024, VOL 1, 2024, 1249 : 204 - 223
  • [30] Instrumentation and control systems applied to high-risk operating technologies:Paving the way to the Industry 4.0 at Nuclear Power Plants
    Gomes, Filipe Calado
    de Andrade, Alexandre Acacio
    Gasi, Fernando
    2021 14TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRY APPLICATIONS (INDUSCON), 2021, : 23 - 30