首页> 外文会议>International topical meeting on nuclear plant instrumentation, control, and human-machine interface technologies >METHODOLOGY ON CYBER SECURITY EVALUATION IN NUCLEAR FACILITIES CONSIDERING IC ARCHITECTURE
【24h】

METHODOLOGY ON CYBER SECURITY EVALUATION IN NUCLEAR FACILITIES CONSIDERING IC ARCHITECTURE

机译:考虑工控架构的核设施网络安全评估方法

获取原文

摘要

Cyber security has become a major issue in nuclear facilities recently due to obsolescence of existing analog system and increasing the use of digital system for instrumentation and control (I&C) system. There are several cases which are similar to cyber-attacks in nuclear facilities such as Davis-Besse NPP. Browns Ferry NPP. Hatch NPP, Natanz Nuclear Facility, and Monju NPP. Since the cyber-attack called "Stuxnet* occurred to a Natanz Nuclear Facility at 2010, the regulatory agencies have developed regulatory guidance for cyber security of nuclear facilities. In this paper, we will propose a methodology on cyber security evaluation in nuclear facilities considering I&C architecture. We will introduce the cyber security evaluation model for I&C system with Bayesian Belief Network (BBN). The cyber security evaluation model for nuclear facilities consists of I&C architecture, cyber threat such as malicious activity of attacker, and mitigation measure against malicious activity. In order to make benchmark model with I&C architecture, cyber threat, and mitigation measure, the likelihood and consequence concepts are used as prior information to the model. Bayesian update can be used to evaluate the cyber security for nuclear facility by calculating posterior information and comparing between prior information and posterior information with the model. Moreover, we will propose the methodology on application of the cyber security to existing PSA by using the cyber security evaluation model with BBN. It presents quantitative information for cyber security against cyber-attack and it is helpful to communicate between licensee and regulator on nuclear facilities.
机译:由于现有模拟系统的过时和对仪器仪表和控制系统(I&C)的数字系统使用的增加,网络安全已成为核设施中的主要问题。有几种情况类似于戴维斯-贝斯核电厂等核设施的网络攻击。布朗斯轮渡NPP。孵化核电厂,纳坦兹核设施和文殊核电厂。自2010年纳坦兹核设施发生网络攻击“ Stuxnet *”以来,监管机构已针对核设施的网络安全制定了监管指南。在本文中,我们将提出一种考虑I&C的核设施网络安全评估方法我们将使用贝叶斯信念网络(BBN)引入I&C系统的网络安全评估模型,核设施的网络安全评估模型包括I&C架构,攻击者的恶意活动等网络威胁以及针对恶意活动的缓解措施。为了建立具有I&C架构,网络威胁和缓解措施的基准模型,将可能性和后果概念用作模型的先验信息,通过计算后验信息并进行比较,贝叶斯更新可用于评估核设施的网络安全。在先验信息和后验信息之间建立模型。 e将通过使用带有BBN的网络安全评估模型,提出将网络安全应用于现有PSA的方法。它提供了针对网络攻击的网络安全的定量信息,有助于许可证持有者与核设施监管者之间的交流。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号