Cyber attack taxonomy for digital environment in nuclear power plants
With the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release o...
Main Authors: | , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
Elsevier
2020-05-01
|
Series: | Nuclear Engineering and Technology |
Online Access: | http://www.sciencedirect.com/science/article/pii/S1738573319305443 |
id |
doaj-8b5db64888ce44618a7d9f76bff87f1f |
---|---|
record_format |
Article |
spelling |
doaj-8b5db64888ce44618a7d9f76bff87f1f2020-11-25T02:15:56ZengElsevierNuclear Engineering and Technology1738-57332020-05-015259951001Cyber attack taxonomy for digital environment in nuclear power plantsSeungmin Kim0Gyunyoung Heo1Enrico Zio2Jinsoo Shin3Jae-gu Song4Kyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Korea Institute of Nuclear Nonproliferation and Control, Yuseong-daero, Yuseong-gu, Daejeon, 34057, South KoreaKyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Corresponding author.Kyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Chair on Systems Science and the Energetic Challenge, Foundation Electricité de France at Laboratoire Genie Industriel, CentraleSupélec, Universite’ Paris-Saclay, France; Energy Department, Politecnico di Milano, ItalyKorea Atomic Energy Research Institute, Daedeok-daero, Yuseong-gu, Daejeon, 34057, South KoreaKorea Atomic Energy Research Institute, Daedeok-daero, Yuseong-gu, Daejeon, 34057, South KoreaWith the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release of radioactive materials cyber-attacks.However, cyber security research on industrial control systems (ICSs) and supervisory control and data acquisition (SCADA) systems is relatively inadequate compared to information technology (IT) and further it is difficult to study cyber-attack taxonomy for NPPs considering the characteristics of ICSs. The advanced research of cyber-attack taxonomy does not reflect the architectural and inherent characteristics of NPPs and lacks a systematic countermeasure strategy.Therefore, it is necessary to more systematically check the consistency of operators and regulators related to cyber security, as in regulatory guide 5.71 (RG.5.71) and regulatory standard 015 (RS.015). For this reason, this paper attempts to suggest a template for cyber-attack taxonomy based on the characteristics of NPPs and exemplifies a specific cyber-attack case in the template. In addition, this paper proposes a systematic countermeasure strategy by matching the countermeasure with critical digital assets (CDAs). The cyber-attack cases investigated using the proposed cyber-attack taxonomy can be used as data for evaluation and validation of cyber security conformance for digital devices to be applied, and as effective prevention and mitigation for cyber-attacks of NPPs. Keywords: Cyber-attack taxonomy, Cyber security, Nuclear power plant, ICS, SCADAhttp://www.sciencedirect.com/science/article/pii/S1738573319305443 |
collection |
DOAJ |
language |
English |
format |
Article |
sources |
DOAJ |
author |
Seungmin Kim Gyunyoung Heo Enrico Zio Jinsoo Shin Jae-gu Song |
spellingShingle |
Seungmin Kim Gyunyoung Heo Enrico Zio Jinsoo Shin Jae-gu Song Cyber attack taxonomy for digital environment in nuclear power plants Nuclear Engineering and Technology |
author_facet |
Seungmin Kim Gyunyoung Heo Enrico Zio Jinsoo Shin Jae-gu Song |
author_sort |
Seungmin Kim |
title |
Cyber attack taxonomy for digital environment in nuclear power plants |
title_short |
Cyber attack taxonomy for digital environment in nuclear power plants |
title_full |
Cyber attack taxonomy for digital environment in nuclear power plants |
title_fullStr |
Cyber attack taxonomy for digital environment in nuclear power plants |
title_full_unstemmed |
Cyber attack taxonomy for digital environment in nuclear power plants |
title_sort |
cyber attack taxonomy for digital environment in nuclear power plants |
publisher |
Elsevier |
series |
Nuclear Engineering and Technology |
issn |
1738-5733 |
publishDate |
2020-05-01 |
description |
With the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release of radioactive materials cyber-attacks.However, cyber security research on industrial control systems (ICSs) and supervisory control and data acquisition (SCADA) systems is relatively inadequate compared to information technology (IT) and further it is difficult to study cyber-attack taxonomy for NPPs considering the characteristics of ICSs. The advanced research of cyber-attack taxonomy does not reflect the architectural and inherent characteristics of NPPs and lacks a systematic countermeasure strategy.Therefore, it is necessary to more systematically check the consistency of operators and regulators related to cyber security, as in regulatory guide 5.71 (RG.5.71) and regulatory standard 015 (RS.015). For this reason, this paper attempts to suggest a template for cyber-attack taxonomy based on the characteristics of NPPs and exemplifies a specific cyber-attack case in the template. In addition, this paper proposes a systematic countermeasure strategy by matching the countermeasure with critical digital assets (CDAs). The cyber-attack cases investigated using the proposed cyber-attack taxonomy can be used as data for evaluation and validation of cyber security conformance for digital devices to be applied, and as effective prevention and mitigation for cyber-attacks of NPPs. Keywords: Cyber-attack taxonomy, Cyber security, Nuclear power plant, ICS, SCADA |
url |
http://www.sciencedirect.com/science/article/pii/S1738573319305443 |
work_keys_str_mv |
AT seungminkim cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants AT gyunyoungheo cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants AT enricozio cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants AT jinsooshin cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants AT jaegusong cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants |
_version_ |
1724893880375050240 |