Integrated Risk Analysis of Function Safety and Cyber Security on I&C System of HTP-PM With STPA-SafeSec

Yukun Tian, Jianghai Li, Xiaojin Huang
{"title":"Integrated Risk Analysis of Function Safety and Cyber Security on I&C System of HTP-PM With STPA-SafeSec","authors":"Yukun Tian, Jianghai Li, Xiaojin Huang","doi":"10.1115/icone29-93395","DOIUrl":null,"url":null,"abstract":"\n Cyber security risk analysis can identify and assess factors that may damage to the system such as digital instrumentation and control system of nuclear power plants. Performing cyber security risk analysis is important for instrumentation and control system of nuclear power plants because it could assess overall impacts of risks and help to identify vulnerabilities to determine next steps to address security risks. With the integration of information system and physical system, cyber security of information system and functional safety of physical system interact with each other, resulting in a type of new comprehensive security problem and introducing serious security risks. Most of the existing cyber security risk analysis methods pay more attention to cyberattacks like attack tree analysis method, Petri net method, and Bayesian network method. STPA-SafeSec is a top-down security risk analysis method focusing on the system itself based on system theory, which starts from unacceptable losses of the system and pays attention to the causal factors that produce unsafe control. In this paper, STPA-SafeSec is applied to the primary circuit pressure control system of high temperature gas-cold reactors in order to perform the hazard analysis of integrated risk assessment for both functional safety and cyber security. The application details are given and a part of the hazardous scenarios tree is obtained for the formulation of mitigation strategies.","PeriodicalId":365848,"journal":{"name":"Volume 5: Nuclear Safety, Security, and Cyber Security","volume":"96 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-08-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Volume 5: Nuclear Safety, Security, and Cyber Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1115/icone29-93395","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Cyber security risk analysis can identify and assess factors that may damage to the system such as digital instrumentation and control system of nuclear power plants. Performing cyber security risk analysis is important for instrumentation and control system of nuclear power plants because it could assess overall impacts of risks and help to identify vulnerabilities to determine next steps to address security risks. With the integration of information system and physical system, cyber security of information system and functional safety of physical system interact with each other, resulting in a type of new comprehensive security problem and introducing serious security risks. Most of the existing cyber security risk analysis methods pay more attention to cyberattacks like attack tree analysis method, Petri net method, and Bayesian network method. STPA-SafeSec is a top-down security risk analysis method focusing on the system itself based on system theory, which starts from unacceptable losses of the system and pays attention to the causal factors that produce unsafe control. In this paper, STPA-SafeSec is applied to the primary circuit pressure control system of high temperature gas-cold reactors in order to perform the hazard analysis of integrated risk assessment for both functional safety and cyber security. The application details are given and a part of the hazardous scenarios tree is obtained for the formulation of mitigation strategies.
基于STPA-SafeSec的HTP-PM测控系统功能安全和网络安全综合风险分析
网络安全风险分析可以识别和评估可能对核电厂数字仪表和控制系统等系统造成损害的因素。执行网络安全风险分析对于核电站仪表和控制系统非常重要,因为它可以评估风险的整体影响,并有助于识别漏洞,以确定下一步应对安全风险的步骤。随着信息系统与物理系统的融合,信息系统的网络安全与物理系统的功能安全相互影响,形成了一类新的综合性安全问题,带来了严重的安全风险。现有的网络安全风险分析方法大多关注网络攻击,如攻击树分析法、Petri网法、贝叶斯网络法等。STPA-SafeSec是一种基于系统理论的自上而下的以系统本身为中心的安全风险分析方法,它从系统不可接受的损失出发,关注产生不安全控制的原因因素。本文将STPA-SafeSec应用于高温气冷堆一次回路压力控制系统,从功能安全和网络安全两方面进行综合风险评估危害分析。给出了应用细节,并获得了部分危险情景树,用于制定缓解战略。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信