首页> 外文会议>International conference on nuclear engineering >CYBER SECURITY ASSESSMENT OF COMPONENT OFF-THE-SHELF BASED NPP lC SYSTEM USING IMECA TECHNIQUE
【24h】

CYBER SECURITY ASSESSMENT OF COMPONENT OFF-THE-SHELF BASED NPP lC SYSTEM USING IMECA TECHNIQUE

机译:基于IMECA技术的基于组件的现成NPP L&C系统的网络安全评估

获取原文

摘要

Nowadays cyber security assurance is one of the key challenges of safety critical software based NPP I&C (Nuclear Power Plants Instrumentation and Control) systems requirements profiling, development and operation. Any I&C system consists of a set of standard software (SW), hardware (HW) and FPGA components. These components can be selected and combined in different ways to address the particular control and safety assurance related tasks. Some of them are proprietary software (PS) and commercial off-the-shelf (COTS) components developed previously. Application of such components reduces the level of safety and cyber security, because they can contain vulnerabilities that were created intentionally. In this case, targeted attacks can lead to a system failure. National Vulnerability Database (NVD) and other open databases contain information about vulnerabilities which can be attacked by insiders or other intruders and decrease cyber security of NPP I&C systems. In this paper, we propose a safety assessment technique of NPP I&C systems, which consists of the following procedures: 1. Analysis of I&C architecture to assess influence of OTS component failures on dependability (reliability and safety) of the system. For that purpose, FMEDA or similar techniques can be applied. As a result, three-dimension criticality matrixes (CM) (with metrics of detection, probability and severity) are developed for different components (SWFCM and HW/FPGAFCM). 2. The IMECA-based assessment of OTS components and their configuration. In this case, CMs (SWICM and HW/FPGAICM) describe the degree of failure component influence on cyber security. 3. Joining of criticality matrixes (SWFCM and HW/FPGAFCM, SWICM and HW/FPGAICM), impact analysis of components depending on degree of influence on cyber security and safety as a whole. 4. Developing of Security Assurance Case and selecting of countermeasures according to safety (cyber security)/costs criteria. The developed tool supports creation of criticality matrixes for each analyzed component of the system and I&C as a whole. Joining of criticality matrixes allows creating common matrix for system cyber security and functional safety. The tool supports decision making to optimize choice of countermeasures according to criterion of safety and security/cost criterion.
机译:如今,网络安全保证已成为基于安全关键软件的NPP I&C(核电厂仪表与控制)系统需求分析,开发和运营的主要挑战之一。任何I&C系统都由一组标准软件(SW),硬件(HW)和FPGA组件组成。可以以不同的方式选择和组合这些组件,以解决与特定控制和安全保证相关的任务。其中一些是以前开发的专有软件(PS)和商用现货(COTS)组件。此类组件的应用降低了安全性和网络安全性,因为它们可能包含故意创建的漏洞。在这种情况下,有针对性的攻击可能导致系统故障。国家漏洞数据库(NVD)和其他开放数据库包含有关漏洞的信息,这些漏洞可能会被内部人员或其他入侵者攻击,从而降低NPP I&C系统的网络安全性。在本文中,我们提出了NPP I&C系统的安全评估技术,该技术包括以下过程:1.分析I&C体系结构,以评估OTS组件故障对系统可靠性(可靠性和安全性)的影响。为此,可以应用FMEDA或类似技术。结果,针对不同的组件(SWFCM和HW / FPGAFCM)开发了三维关键度矩阵(CM)(具有检测指标,概率和严重性)。 2.基于IMECA的OTS组件及其配置评估。在这种情况下,CM(SWICM和HW / FPGAICM)描述了故障组件对网络安全的影响程度。 3.连接关键性矩阵(SWFCM和HW / FPGAFCM,SWICM和HW / FPGAICM),根据对网络安全和整体安全的影响程度对组件进行影响分析。 4.根据安全(网络安全)/成本标准制定安全保证案例并选择对策。开发的工具支持为系统和I&C的每个分析组件创建关键性矩阵。连接关键性矩阵可以创建用于系统网络安全和功能安全的通用矩阵。该工具支持决策制定,以根据安全和安保/成本准则来优化对策选择。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号