Kwang-Seop Son , Jae-Gu Song , Inhye Hahm , Jung-Woon Lee
{"title":"量化网络风险:评估网络威胁对核电站安全影响的模型","authors":"Kwang-Seop Son , Jae-Gu Song , Inhye Hahm , Jung-Woon Lee","doi":"10.1016/j.net.2025.103675","DOIUrl":null,"url":null,"abstract":"<div><div>The quantitative cyber risk assessment approach presented in this paper is specifically tailored to meet the operational and safety needs of Nuclear Power Plants (NPPs). Addressing the limitations of conventional qualitative methods, the proposed approach evaluates cyber risks through the integration of two key elements: the Risk Increase Ratio (RIR) derived from Probabilistic Safety Assessment (PSA) and the Score of Security Controls (SSC) for Critical Digital Assets (CDA). By employing these metrics, the study quantifies the safety impacts of cyber threats by considering their impact on the Core Damage Frequency (CDF). The framework incorporates three distinct models—<span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>L</mi></msub></mrow></math></span>, <span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>M</mi></msub></mrow></math></span>, and <span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>Z</mi></msub></mrow></math></span>—each reflecting different data distribution and normalization methods. Although the absolute risk values varied among the models, their consistent relative risk rankings highlight the robustness of the methodology. A case study was conducted on digital safety systems, demonstrating the applicability of the proposed model to real NPP scenarios. To support practical implementation, the study emphasizes the need for collaboration among operators, designers, and cybersecurity experts to adapt SSC and RIR mappings to the risk values considering site-specific operational and design environments. This structured, risk-informed methodology advances the field of cyber risk assessment by ensuring consistency, granularity, and applicability, ultimately enhancing the resilience of critical infrastructure such as NPPs.</div></div>","PeriodicalId":19272,"journal":{"name":"Nuclear Engineering and Technology","volume":"57 10","pages":"Article 103675"},"PeriodicalIF":2.6000,"publicationDate":"2025-04-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Quantifying cyber risk: A model for evaluating safety impacts of cyber threats on NPPs\",\"authors\":\"Kwang-Seop Son , Jae-Gu Song , Inhye Hahm , Jung-Woon Lee\",\"doi\":\"10.1016/j.net.2025.103675\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>The quantitative cyber risk assessment approach presented in this paper is specifically tailored to meet the operational and safety needs of Nuclear Power Plants (NPPs). Addressing the limitations of conventional qualitative methods, the proposed approach evaluates cyber risks through the integration of two key elements: the Risk Increase Ratio (RIR) derived from Probabilistic Safety Assessment (PSA) and the Score of Security Controls (SSC) for Critical Digital Assets (CDA). By employing these metrics, the study quantifies the safety impacts of cyber threats by considering their impact on the Core Damage Frequency (CDF). The framework incorporates three distinct models—<span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>L</mi></msub></mrow></math></span>, <span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>M</mi></msub></mrow></math></span>, and <span><math><mrow><msub><mrow><mi>C</mi><mi>R</mi></mrow><mi>Z</mi></msub></mrow></math></span>—each reflecting different data distribution and normalization methods. Although the absolute risk values varied among the models, their consistent relative risk rankings highlight the robustness of the methodology. A case study was conducted on digital safety systems, demonstrating the applicability of the proposed model to real NPP scenarios. To support practical implementation, the study emphasizes the need for collaboration among operators, designers, and cybersecurity experts to adapt SSC and RIR mappings to the risk values considering site-specific operational and design environments. This structured, risk-informed methodology advances the field of cyber risk assessment by ensuring consistency, granularity, and applicability, ultimately enhancing the resilience of critical infrastructure such as NPPs.</div></div>\",\"PeriodicalId\":19272,\"journal\":{\"name\":\"Nuclear Engineering and Technology\",\"volume\":\"57 10\",\"pages\":\"Article 103675\"},\"PeriodicalIF\":2.6000,\"publicationDate\":\"2025-04-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Nuclear Engineering and Technology\",\"FirstCategoryId\":\"5\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S1738573325002438\",\"RegionNum\":3,\"RegionCategory\":\"工程技术\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"NUCLEAR SCIENCE & TECHNOLOGY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Nuclear Engineering and Technology","FirstCategoryId":"5","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S1738573325002438","RegionNum":3,"RegionCategory":"工程技术","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"NUCLEAR SCIENCE & TECHNOLOGY","Score":null,"Total":0}
Quantifying cyber risk: A model for evaluating safety impacts of cyber threats on NPPs
The quantitative cyber risk assessment approach presented in this paper is specifically tailored to meet the operational and safety needs of Nuclear Power Plants (NPPs). Addressing the limitations of conventional qualitative methods, the proposed approach evaluates cyber risks through the integration of two key elements: the Risk Increase Ratio (RIR) derived from Probabilistic Safety Assessment (PSA) and the Score of Security Controls (SSC) for Critical Digital Assets (CDA). By employing these metrics, the study quantifies the safety impacts of cyber threats by considering their impact on the Core Damage Frequency (CDF). The framework incorporates three distinct models—, , and —each reflecting different data distribution and normalization methods. Although the absolute risk values varied among the models, their consistent relative risk rankings highlight the robustness of the methodology. A case study was conducted on digital safety systems, demonstrating the applicability of the proposed model to real NPP scenarios. To support practical implementation, the study emphasizes the need for collaboration among operators, designers, and cybersecurity experts to adapt SSC and RIR mappings to the risk values considering site-specific operational and design environments. This structured, risk-informed methodology advances the field of cyber risk assessment by ensuring consistency, granularity, and applicability, ultimately enhancing the resilience of critical infrastructure such as NPPs.
期刊介绍:
Nuclear Engineering and Technology (NET), an international journal of the Korean Nuclear Society (KNS), publishes peer-reviewed papers on original research, ideas and developments in all areas of the field of nuclear science and technology. NET bimonthly publishes original articles, reviews, and technical notes. The journal is listed in the Science Citation Index Expanded (SCIE) of Thomson Reuters.
NET covers all fields for peaceful utilization of nuclear energy and radiation as follows:
1) Reactor Physics
2) Thermal Hydraulics
3) Nuclear Safety
4) Nuclear I&C
5) Nuclear Physics, Fusion, and Laser Technology
6) Nuclear Fuel Cycle and Radioactive Waste Management
7) Nuclear Fuel and Reactor Materials
8) Radiation Application
9) Radiation Protection
10) Nuclear Structural Analysis and Plant Management & Maintenance
11) Nuclear Policy, Economics, and Human Resource Development