A Study on the Vulnerability Assessment for Digital I&C System in Nuclear Power Plant

被引:0
作者
Kim, SungCheol [1 ]
Euom, IeckChae [1 ]
Ha, ChangHyun [1 ]
Lee, JooHyoung [1 ]
Noh, BongNam [2 ]
机构
[1] KEPCO KDN, Naju, South Korea
[2] Chonnam Natl Univ, Gwangju, South Korea
来源
INFORMATION SECURITY APPLICATIONS, WISA 2018 | 2019年 / 11402卷
关键词
Vulnerability assessment; CVSS; Nuclear Power Plant;
D O I
10.1007/978-3-030-17982-3_6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
NPP (Nuclear Power Plant) Operators have approached the problem of cyber security by simply keep up with the never-ending stream of new vulnerability alerts from suppliers and groups like ICS-CERT. Keeping Cyber Security Compliance, NPP Owner must patch vulnerabilities according to their CVSS Score. In fact, NPP Owner often has to deal with hundreds of vulnerabilities, which is not a trivial task to carry out. Unfortunately, the CVSS Score has been shown to be poor indicator for actual exploitation in NPP. This paper analyzes Vulnerability Assessment Methodology about Critical digital asset in NPP. And then give an effective methodology. It approaches the cyber security regulations of NPP from a technical vulnerability point of view, where any given Critical Digital Asset can be assessed for vulnerabilities.
引用
收藏
页码:68 / 80
页数:13
相关论文
共 8 条
  • [1] Ahn J, 2013, RES SOFTWARE VULNERA, P23
  • [2] Ahn J., 2015, QUANTITATIVE SCORING, P4
  • [3] [Anonymous], 2015, NIST Special Publication, V800
  • [4] Holt M., 2014, NUCL POWER PLANT SEC
  • [5] Jang D, 2017, STUDY IOT SOFTWARE N, P4
  • [6] Kostadinov V, 2011, VULNERABILITY ASSESS
  • [7] Shank J, 2016, CYBER ALERT NOTIFICA
  • [8] Song J.G, 2012, CYBER SECURITY RISK, P1