AN ANALYSIS OF TECHNICAL SECURITY CONTROL REQUIREMENTS FOR DIGITAL I&C SYSTEMS IN NUCLEAR POWER PLANTS

被引:23
作者
Song, Jae-Gu [1 ]
Lee, Jung-Woon [1 ]
Park, Gee-Yong [1 ]
Kwon, Kee-Choon [1 ]
Lee, Dong-Young [1 ]
Lee, Cheol-Kwon [1 ]
机构
[1] Korea Atom Energy Res Inst, Taejon 305353, South Korea
关键词
Instrumentation and Control Systems; Nuclear Power Plant; Cyber Security; Technical Security Controls; Critical Digital Assets;
D O I
10.5516/NET.04.2012.091
中图分类号
TL [原子能技术]; O571 [原子核物理学];
学科分类号
0827 ; 082701 ;
摘要
Instrumentation and control systems in nuclear power plants have been digitalized for the purpose of maintenance and precise operation. This digitalization, however, brings out issues related to cyber security. In the most recent past, international standard organizations, regulatory institutes, and research institutes have performed a number of studies addressing these systems cyber security.. In order to provide information helpful to the system designers in their application of cyber security for the systems, this paper presents methods and considerations to define attack vectors in a target system, to review and select the requirements in the Regulatory Guide 5.71, and to integrate the results to identify applicable technical security control requirements. In this study, attack vectors are analyzed through the vulnerability analyses and penetration tests with a simplified safety system, and the elements of critical digital assets acting as attack vectors are identified. Among the security control requirements listed in Appendices B and C to Regulatory Guide 5.71, those that should be implemented into the systems are selected and classified in groups of technical security control requirements using the results of the attack vector analysis. For the attack vector elements of critical digital assets, all the technical security control requirements are evaluated to determine whether they are applicable and effective, and considerations in this evaluation are also discussed. The technical security control requirements in three important categories of access control, monitoring and logging, and encryption are derived and grouped according to the elements of attack vectors as results for the sample safety system.
引用
收藏
页码:637 / 652
页数:16
相关论文
共 47 条
  • [1] A CYBER SECURITY RISK ASSESSMENT FOR THE DESIGN OF I&C SYSTEMS IN NUCLEAR POWER PLANTS
    Song, Jae-Gu
    Lee, Jung-Woon
    Lee, Cheol-Kwon
    Kwon, Kee-Choon
    Lee, Dong-Young
    NUCLEAR ENGINEERING AND TECHNOLOGY, 2012, 44 (08) : 919 - 928
  • [2] Safety Objective Oriented Design of Digital Safety I&C - Defence in Depth in Nuclear Power Plants
    Ding, Yongjian
    ATP EDITION, 2014, (05): : 54 - 61
  • [3] The Independence of Safety Digital I&C System in Nuclear Power Plant
    Jia, Xiang
    Wang, Zhong-Qiu
    Zhang, Yun-Bo
    Guo, Yin-Hui
    NUCLEAR POWER PLANTS: INNOVATIVE TECHNOLOGIES FOR INSTRUMENTATION AND CONTROL SYSTEMS, 2017, 400 : 201 - 207
  • [4] A computational method for probabilistic safety assessment of I&C systems and human operators in nuclear power plants
    Kim, MC
    Seong, PH
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2006, 91 (05) : 580 - 593
  • [5] A Study on the Vulnerability Assessment for Digital I&C System in Nuclear Power Plant
    Kim, SungCheol
    Euom, IeckChae
    Ha, ChangHyun
    Lee, JooHyoung
    Noh, BongNam
    INFORMATION SECURITY APPLICATIONS, WISA 2018, 2019, 11402 : 68 - 80
  • [6] DATA FLOW BASED CYBER SECURITY DEFENSE-IN-DEPTH MODEL OF I&C SYSTEM FOR NUCLEAR POWER PLANTS
    Hu, Bing
    Zhang, Longqiang
    Guo, Zhiwu
    Li, Youran
    Sun, Wei
    Zhou, Liang
    Tian, Yong
    PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING, 2017, VOL 4, 2017,
  • [7] EMI Analysis and Location of I&C Equipment in Nuclear Power Plant
    Huang S.
    He X.
    Han D.
    Liu X.
    Li B.
    Hedongli Gongcheng/Nuclear Power Engineering, 2023, 44 (01): : 171 - 176
  • [8] Cyber Security Risk Evaluation of a Nuclear I&C Using BN and ET
    Shin, Jinsoo
    Son, Hanseong
    Heo, Gyunyoung
    NUCLEAR ENGINEERING AND TECHNOLOGY, 2017, 49 (03) : 517 - 524
  • [9] DESIGN OF THE COMMUNICATION INDEPENDENCE FOR ACPR1000 NUCLEAR POWER PLANT DIGITAL SAFETY I&C SYSTEM
    Sun Na
    Shi Gui-lian
    Xie Yi-qin
    Li Gang
    Jiang Guo-jin
    PROCEEDINGS OF THE 25TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING, 2017, VOL 1, 2017,
  • [10] RESEARCH ON ELECTRIC AND I&C EQUIPMENT SAFETY FUNCTION CLASSIFICATION OF NUCLEAR POWER PLANT
    Wang Yuqi
    Sun Qian
    PROCEEDINGS OF 2021 28TH INTERNATIONAL CONFERENCE ON NUCLEAR ENGINEERING (ICONE28), VOL 1, 2021,