Development of the framework for quantitative cyber risk assessment in nuclear facilities

被引:3
|
作者
Son, Kwang-Seop [1 ]
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
机构
[1] Korea Atom Energy Res Inst, Secur R&D Team, Daejeon, South Korea
关键词
TPA; Threat scenario; Attack vector; TAM; Security control method; Quanti fication of cyber risk; STPA-SAFESEC; SAFETY;
D O I
10.1016/j.net.2023.03.023
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Industrial control systems in nuclear facilities are facing increasing cyber threats due to the widespread use of information and communication equipment. To implement cyber security programs effectively through the RG 5.71, it is necessary to quantitatively assess cyber risks. However, this can be challenging due to limited historical data on threats and customized Critical Digital Assets (CDAs) in nuclear facilities. Previous works have focused on identifying data flows, the assets where the data is stored and processed, which means that the methods are heavily biased towards information security concerns. Additionally, in nuclear facilities, cyber threats need to be analyzed from a safety perspective. In this study, we use the system theoretic process analysis to identify system-level threat scenarios that could violate safety constraints. Instead of quantifying the likelihood of exploiting vulnerabilities, we quantify Security Control Measures (SCMs) against the identified threat scenarios. We classify the system and CDAs into four consequence-based classes, as presented in NEI 13-10, to analyze the adversary impact on CDAs. This allows for the ranking of identified threat scenarios according to the quantified SCMs. The proposed framework enables stakeholders to more effectively and accurately rank cyber risks, as well as establish security and response strategies.(c) 2023 Korean Nuclear Society, Published by Elsevier Korea LLC. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:2034 / 2046
页数:13
相关论文
共 50 条
  • [1] Towards Developing a Scalable Cyber Risk Assessment and Mitigation Framework
    Malik, Adeel A.
    Tosh, Deepak K.
    18TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE, SYSCON 2024, 2024,
  • [2] Risk Assessment Methods for Cybersecurity in Nuclear Facilities: Compliance to Regulatory Requirements
    Setianingsih, Lilis Susanti
    Pulungan, Reza
    Putra, Agfianto Eko
    Wibowo, Moh Edi
    Syarip
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (09) : 714 - 722
  • [3] Development of interaction model on the risk assessment method for nuclear facilities using a system model with a multi-layer structure
    Mori, Kenji
    Muta, Hitoshi
    Ohtori, Yasuki
    JOURNAL OF NUCLEAR SCIENCE AND TECHNOLOGY, 2021, 58 (05) : 542 - 566
  • [4] Development of risk assessment for nuclear power: insights from history
    Perkins J.H.
    Journal of Environmental Studies and Sciences, 2014, 4 (4) : 273 - 287
  • [5] DEVELOPMENT OF FRAMEWORK FOR ASSESSMENT OF COMBINED EFFECTS OF RISK FACTORS IN WOODWORKING
    Hnilica, Richard
    PROCEEDINGS OF THE 4TH INTERNATIONAL SCIENCE CONFERENCE WOODWORKING TECHNIQUES, 2011, : 117 - 123
  • [6] Development of a Novel Quantitative Risk Assessment Tool for UK Road Tunnels
    Haddad, Razieh Khaksari
    Harun, Zambri
    FIRE-SWITZERLAND, 2023, 6 (02):
  • [7] Quantitative approach for cardiac risk assessment and interpretation in tuberculosis drug development
    Polak, Sebastian
    Romero, Klaus
    Berg, Alexander
    Patel, Nikunjkumar
    Jamei, Masoud
    Hermann, David
    Hanna, Debra
    JOURNAL OF PHARMACOKINETICS AND PHARMACODYNAMICS, 2018, 45 (03) : 457 - 467
  • [8] Survey of cyber risk analysis techniques for use in the nuclear industry
    Eggers, Shannon
    Le Blanc, Katya
    PROGRESS IN NUCLEAR ENERGY, 2021, 140
  • [9] Preliminary Risk and Mitigation Assessment in Cyber-Physical Systems
    Foldvari, Andras
    Brancati, Francesco
    Pataricza, Andras
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 267 - 274
  • [10] CyberRiskDELPHI: TOWARDS OBJECTIVE CYBER RISK ASSESSMENT FOR COMPLEX SYSTEMS
    Papakonstantinou, Nikolaos
    Van Bossuyt, Douglas L.
    Hale, Britta
    Arlitt, Ryan
    Salonen, Jarno
    Suomalainen, Jani
    PROCEEDINGS OF ASME 2023 INTERNATIONAL DESIGN ENGINEERING TECHNICAL CONFERENCES AND COMPUTERS AND INFORMATION IN ENGINEERING CONFERENCE, IDETC-CIE2023, VOL 2, 2023,