Development of the framework for quantitative cyber risk assessment in nuclear facilities

被引:3
|
作者
Son, Kwang-Seop [1 ]
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
机构
[1] Korea Atom Energy Res Inst, Secur R&D Team, Daejeon, South Korea
关键词
TPA; Threat scenario; Attack vector; TAM; Security control method; Quanti fication of cyber risk; STPA-SAFESEC; SAFETY;
D O I
10.1016/j.net.2023.03.023
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Industrial control systems in nuclear facilities are facing increasing cyber threats due to the widespread use of information and communication equipment. To implement cyber security programs effectively through the RG 5.71, it is necessary to quantitatively assess cyber risks. However, this can be challenging due to limited historical data on threats and customized Critical Digital Assets (CDAs) in nuclear facilities. Previous works have focused on identifying data flows, the assets where the data is stored and processed, which means that the methods are heavily biased towards information security concerns. Additionally, in nuclear facilities, cyber threats need to be analyzed from a safety perspective. In this study, we use the system theoretic process analysis to identify system-level threat scenarios that could violate safety constraints. Instead of quantifying the likelihood of exploiting vulnerabilities, we quantify Security Control Measures (SCMs) against the identified threat scenarios. We classify the system and CDAs into four consequence-based classes, as presented in NEI 13-10, to analyze the adversary impact on CDAs. This allows for the ranking of identified threat scenarios according to the quantified SCMs. The proposed framework enables stakeholders to more effectively and accurately rank cyber risks, as well as establish security and response strategies.(c) 2023 Korean Nuclear Society, Published by Elsevier Korea LLC. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页码:2034 / 2046
页数:13
相关论文
共 50 条
  • [41] Systematic development of scenarios caused by cyber-attack-induced human errors in nuclear power plants
    Kim, Hee Eun
    Son, Han Seong
    Kim, Jonghyun
    Kang, Hyun Gook
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2017, 167 : 290 - 301
  • [42] Quantitative and Risk-Based Framework for Unmanned Aircraft Control System Assurance
    Hejase, Mohammad
    Kurt, Arda
    Aldemir, Tunc
    Ozguner, Umit
    Guarro, Sergio B.
    Yau, Michael K.
    Knudson, Matt D.
    JOURNAL OF AEROSPACE INFORMATION SYSTEMS, 2018, 15 (02): : 57 - 71
  • [43] A semi-quantitative methodology for risk assessment of university chemical laboratory
    Li, Xinhong
    Zhang, Luyao
    Zhang, Renren
    Yang, Ming
    Li, Hua
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2021, 72
  • [44] A quantitative microbial risk assessment model for Listeria monocytogenes in RTE sandwiches
    Tirloni, E.
    Stella, S.
    de Knegt, L. V.
    Gandolfi, G.
    Bernardi, C.
    Nauta, M. J.
    MICROBIAL RISK ANALYSIS, 2018, 9 : 11 - 21
  • [45] Evolution model and quantitative assessment of risk network in housing construction accidents
    Cheng, Lianhua
    Cao, Dongqiang
    ENGINEERING CONSTRUCTION AND ARCHITECTURAL MANAGEMENT, 2024, 31 (01) : 227 - 246
  • [46] Applying a semi-quantitative risk assessment on petroleum production unit
    Eltahan, Fatma M.
    Toderas, Monica
    Mansour, Moustapha S.
    El-Ashtoukhy, El Sayed Z.
    Abdou, Mohamed A.
    Shokry, F.
    SCIENTIFIC REPORTS, 2024, 14 (01)
  • [47] A dynamic risk assessment model based on multidimensional and quantitative inference theory
    Jing, Qi
    Yang, Guang
    Shi, Chao-ke
    Li, Yun-tao
    Luan, Guo-hua
    Li, Xin
    Liang, Tao
    PROCESS SAFETY AND ENVIRONMENTAL PROTECTION, 2024, 186 : 1567 - 1579
  • [48] Development of Risk Criteria for Permanent Changes in a Nuclear Power Plant
    Cepin, Marko
    ELEKTROTEHNISKI VESTNIK-ELECTROCHEMICAL REVIEW, 2006, 73 (2-3): : 149 - 154
  • [49] Combining Quantitative Risk Assessment of Human Health, Food Waste, and Energy Consumption: The Next Step in the Development of the Food Cold Chain?
    Duret, Steven
    Hong-Minh Hoang
    Derens-Bertheau, Evelyne
    Delahaye, Anthony
    Laguerre, Onrawee
    Guillier, Laurent
    RISK ANALYSIS, 2019, 39 (04) : 906 - 925