Cyber attack taxonomy for digital environment in nuclear power plants

With the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release o...

Full description

Bibliographic Details
Main Authors: Seungmin Kim, Gyunyoung Heo, Enrico Zio, Jinsoo Shin, Jae-gu Song
Format: Article
Language:English
Published: Elsevier 2020-05-01
Series:Nuclear Engineering and Technology
Online Access:http://www.sciencedirect.com/science/article/pii/S1738573319305443
id doaj-8b5db64888ce44618a7d9f76bff87f1f
record_format Article
spelling doaj-8b5db64888ce44618a7d9f76bff87f1f2020-11-25T02:15:56ZengElsevierNuclear Engineering and Technology1738-57332020-05-015259951001Cyber attack taxonomy for digital environment in nuclear power plantsSeungmin Kim0Gyunyoung Heo1Enrico Zio2Jinsoo Shin3Jae-gu Song4Kyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Korea Institute of Nuclear Nonproliferation and Control, Yuseong-daero, Yuseong-gu, Daejeon, 34057, South KoreaKyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Corresponding author.Kyung Hee Univ, Deogyeong-daero, Giheung-gu, Yongin-si, Gyeongi-do, 17104, South Korea; Chair on Systems Science and the Energetic Challenge, Foundation Electricité de France at Laboratoire Genie Industriel, CentraleSupélec, Universite’ Paris-Saclay, France; Energy Department, Politecnico di Milano, ItalyKorea Atomic Energy Research Institute, Daedeok-daero, Yuseong-gu, Daejeon, 34057, South KoreaKorea Atomic Energy Research Institute, Daedeok-daero, Yuseong-gu, Daejeon, 34057, South KoreaWith the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release of radioactive materials cyber-attacks.However, cyber security research on industrial control systems (ICSs) and supervisory control and data acquisition (SCADA) systems is relatively inadequate compared to information technology (IT) and further it is difficult to study cyber-attack taxonomy for NPPs considering the characteristics of ICSs. The advanced research of cyber-attack taxonomy does not reflect the architectural and inherent characteristics of NPPs and lacks a systematic countermeasure strategy.Therefore, it is necessary to more systematically check the consistency of operators and regulators related to cyber security, as in regulatory guide 5.71 (RG.5.71) and regulatory standard 015 (RS.015). For this reason, this paper attempts to suggest a template for cyber-attack taxonomy based on the characteristics of NPPs and exemplifies a specific cyber-attack case in the template. In addition, this paper proposes a systematic countermeasure strategy by matching the countermeasure with critical digital assets (CDAs). The cyber-attack cases investigated using the proposed cyber-attack taxonomy can be used as data for evaluation and validation of cyber security conformance for digital devices to be applied, and as effective prevention and mitigation for cyber-attacks of NPPs. Keywords: Cyber-attack taxonomy, Cyber security, Nuclear power plant, ICS, SCADAhttp://www.sciencedirect.com/science/article/pii/S1738573319305443
collection DOAJ
language English
format Article
sources DOAJ
author Seungmin Kim
Gyunyoung Heo
Enrico Zio
Jinsoo Shin
Jae-gu Song
spellingShingle Seungmin Kim
Gyunyoung Heo
Enrico Zio
Jinsoo Shin
Jae-gu Song
Cyber attack taxonomy for digital environment in nuclear power plants
Nuclear Engineering and Technology
author_facet Seungmin Kim
Gyunyoung Heo
Enrico Zio
Jinsoo Shin
Jae-gu Song
author_sort Seungmin Kim
title Cyber attack taxonomy for digital environment in nuclear power plants
title_short Cyber attack taxonomy for digital environment in nuclear power plants
title_full Cyber attack taxonomy for digital environment in nuclear power plants
title_fullStr Cyber attack taxonomy for digital environment in nuclear power plants
title_full_unstemmed Cyber attack taxonomy for digital environment in nuclear power plants
title_sort cyber attack taxonomy for digital environment in nuclear power plants
publisher Elsevier
series Nuclear Engineering and Technology
issn 1738-5733
publishDate 2020-05-01
description With the development of digital instrumentation and control (I&C) devices, cyber security at nuclear power plants (NPPs) has become a hot issue. The Stuxnet, which destroyed Iran's uranium enrichment facility in 2010, suggests that NPPs could even lead to an accident involving the release of radioactive materials cyber-attacks.However, cyber security research on industrial control systems (ICSs) and supervisory control and data acquisition (SCADA) systems is relatively inadequate compared to information technology (IT) and further it is difficult to study cyber-attack taxonomy for NPPs considering the characteristics of ICSs. The advanced research of cyber-attack taxonomy does not reflect the architectural and inherent characteristics of NPPs and lacks a systematic countermeasure strategy.Therefore, it is necessary to more systematically check the consistency of operators and regulators related to cyber security, as in regulatory guide 5.71 (RG.5.71) and regulatory standard 015 (RS.015). For this reason, this paper attempts to suggest a template for cyber-attack taxonomy based on the characteristics of NPPs and exemplifies a specific cyber-attack case in the template. In addition, this paper proposes a systematic countermeasure strategy by matching the countermeasure with critical digital assets (CDAs). The cyber-attack cases investigated using the proposed cyber-attack taxonomy can be used as data for evaluation and validation of cyber security conformance for digital devices to be applied, and as effective prevention and mitigation for cyber-attacks of NPPs. Keywords: Cyber-attack taxonomy, Cyber security, Nuclear power plant, ICS, SCADA
url http://www.sciencedirect.com/science/article/pii/S1738573319305443
work_keys_str_mv AT seungminkim cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants
AT gyunyoungheo cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants
AT enricozio cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants
AT jinsooshin cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants
AT jaegusong cyberattacktaxonomyfordigitalenvironmentinnuclearpowerplants
_version_ 1724893880375050240