Study on Cyber Security Risk Assessment of Digital Instrumentation &Control System of Nuclear Power Plant

Dongbo Liu, Yujuan Chen, Ji Shi, D. Chen
{"title":"Study on Cyber Security Risk Assessment of Digital Instrumentation &Control System of Nuclear Power Plant","authors":"Dongbo Liu, Yujuan Chen, Ji Shi, D. Chen","doi":"10.1109/POWERCON.2018.8601978","DOIUrl":null,"url":null,"abstract":"The digital instrumentation and control (I&C) systems have been widely used in operating and new nuclear power plants (NPPs). The application of digital computers, communication systems and network technologies in digital I&C system of NPP has brought many benefits, including high performance and convenient maintainability. However, the digital I&C system of NPP has many cyber security risks that may lead to serious hazards. Cyber security risk assessment for digital I&C system of NPP has become more crucial. This study presents the general configuration and functions of digital I&C system of NPP. The digital asset classification, data flow and the security level of the counter measures are given based on the cyber security defense-in-depth model. The factors of asset, threat and vulnerability of digital I&C system are identified in detail. The cyber security risks of digital I&C system of NPP are analyzed for the process system interface level, automatic control and protection level, control and supervisory level, and plant information management level. The cyber security protection scheme of digital I&C system of NPP is designed to cope with the potential cyber security risks. The risk assessment contents of the every stage of cyber security full life cycle are presented. The cyber security risk assessment flow and risk assessment method for digital I&C system of NPP are proposed.","PeriodicalId":260947,"journal":{"name":"2018 International Conference on Power System Technology (POWERCON)","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Power System Technology (POWERCON)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/POWERCON.2018.8601978","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

The digital instrumentation and control (I&C) systems have been widely used in operating and new nuclear power plants (NPPs). The application of digital computers, communication systems and network technologies in digital I&C system of NPP has brought many benefits, including high performance and convenient maintainability. However, the digital I&C system of NPP has many cyber security risks that may lead to serious hazards. Cyber security risk assessment for digital I&C system of NPP has become more crucial. This study presents the general configuration and functions of digital I&C system of NPP. The digital asset classification, data flow and the security level of the counter measures are given based on the cyber security defense-in-depth model. The factors of asset, threat and vulnerability of digital I&C system are identified in detail. The cyber security risks of digital I&C system of NPP are analyzed for the process system interface level, automatic control and protection level, control and supervisory level, and plant information management level. The cyber security protection scheme of digital I&C system of NPP is designed to cope with the potential cyber security risks. The risk assessment contents of the every stage of cyber security full life cycle are presented. The cyber security risk assessment flow and risk assessment method for digital I&C system of NPP are proposed.
核电厂数字仪表控制系统网络安全风险评估研究
数字仪表与控制系统在运行中的核电站和新建核电站中得到了广泛应用。数字计算机、通信系统和网络技术在核电厂数字化测控系统中的应用,带来了高性能、易于维护等诸多优点。然而,核电厂数字化灾控系统存在诸多网络安全风险,可能导致严重危害。核电厂数字化测控系统的网络安全风险评估显得尤为重要。介绍了核电厂数字化测控系统的总体结构和功能。基于网络安全纵深防御模型,给出了数字资产的分类、数据流和防范措施的安全级别。详细分析了数字测控系统的资产因素、威胁因素和脆弱性因素。从过程系统接口层、自动控制与保护层、控制与监督层、工厂信息管理层四个层面分析了核电厂数字化I&C系统的网络安全风险。针对潜在的网络安全风险,设计了核电厂数字化测控系统的网络安全防护方案。给出了网络安全全生命周期各阶段的风险评估内容。提出了核电厂数字化测控系统的网络安全风险评估流程和风险评估方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信