Development of the framework for quantitative cyber risk assessment in nuclear facilities

被引:3
|
作者
Son, Kwang-Seop [1 ]
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
机构
[1] Korea Atom Energy Res Inst, Secur R&D Team, Daejeon, South Korea
关键词
TPA; Threat scenario; Attack vector; TAM; Security control method; Quanti fication of cyber risk; STPA-SAFESEC; SAFETY;
D O I
10.1016/j.net.2023.03.023
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Industrial control systems in nuclear facilities are facing increasing cyber threats due to the widespread use of information and communication equipment. To implement cyber security programs effectively through the RG 5.71, it is necessary to quantitatively assess cyber risks. However, this can be challenging due to limited historical data on threats and customized Critical Digital Assets (CDAs) in nuclear facilities. Previous works have focused on identifying data flows, the assets where the data is stored and processed, which means that the methods are heavily biased towards information security concerns. Additionally, in nuclear facilities, cyber threats need to be analyzed from a safety perspective. In this study, we use the system theoretic process analysis to identify system-level threat scenarios that could violate safety constraints. Instead of quantifying the likelihood of exploiting vulnerabilities, we quantify Security Control Measures (SCMs) against the identified threat scenarios. We classify the system and CDAs into four consequence-based classes, as presented in NEI 13-10, to analyze the adversary impact on CDAs. This allows for the ranking of identified threat scenarios according to the quantified SCMs. The proposed framework enables stakeholders to more effectively and accurately rank cyber risks, as well as establish security and response strategies.(c) 2023 Korean Nuclear Society, Published by Elsevier Korea LLC. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:2034 / 2046
页数:13
相关论文
共 50 条
  • [21] Dependency-based security risk assessment for cyber-physical systems
    Akbarzadeh, Aida
    Katsikas, Sokratis K.
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (03) : 563 - 578
  • [22] Quantitative risk assessment of an urban hydrogen refueling station
    Gye, Hye-Ri
    Seo, Seung-Kwon
    Bach, Quang-Vu
    Ha, Daeguen
    Lee, Chul-Jin
    INTERNATIONAL JOURNAL OF HYDROGEN ENERGY, 2019, 44 (02) : 1288 - 1298
  • [23] A Methodological Framework for the Risk Assessment of Drone Intrusions in Airports
    Pascarella, Domenico
    Gigante, Gabriella
    Vozella, Angela
    Bieber, Pierre
    Dubot, Thomas
    Martinavarro, Edgar
    Barraco, Giovanni
    Li Calzi, Greta
    AEROSPACE, 2022, 9 (12)
  • [24] Quantitative risk assessment of the Italian gas distribution network
    Vianello, Chiara
    Maschio, Giuseppe
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2014, 32 : 5 - 17
  • [25] Semi-quantitative Risk Assessment Framework for Tractor Rollover Prevention Systems Based on the Functional Resonance Analysis Method (FRAM)
    Rossi, Pierluigi
    Cecchini, Massimo
    Monarca, Danilo
    Assettati, Leonardo
    Macor, Carlo
    Alemanno, Riccardo
    SAFETY, HEALTH AND WELFARE IN AGRICULTURE AND AGRO-FOOD SYSTEMS, SHWA 2023, 2024, 521 : 205 - 213
  • [26] Risk assessment of the vulnerability of sexual victimisation of children by analysing the security of touristic facilities
    Fabris, Sanja Delac
    Rosic-Jakupovic, Alica
    POLICIJA I SIGURNOST-POLICE AND SECURITY, 2023, 32 (01): : 83 - 102
  • [27] Review on Optimization of Nuclear Power Development: A Cyber-Physical-Social System in Energy Perspective
    Yang, Xinxin
    Cai, Bin
    Xue, Yusheng
    JOURNAL OF MODERN POWER SYSTEMS AND CLEAN ENERGY, 2022, 10 (03) : 547 - 561
  • [28] Dynamic Risk Assessment Enabling Automated Interventions for Medical Cyber-Physical Systems
    Leite, Fabio L., Jr.
    Schneider, Daniel
    Adler, Rasmus
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019, 2019, 11698 : 216 - 231
  • [29] Legal framework considerations in the development of risk acceptance criteria
    Hartford, D. N. D.
    STRUCTURAL SAFETY, 2009, 31 (02) : 118 - 123
  • [30] Quantitative risk assessment of new ship designs in damage conditions
    Gerigk, M. K.
    SAFETY AND RELIABILITY: METHODOLOGY AND APPLICATIONS, 2015, : 1539 - 1546