Assessment of Cyber Security Challenges in Nuclear Power Plants Security Incidents, Threats, and Initiatives

نویسنده

  • Rahat Masood
چکیده

Nuclear power plants play an important role in electricity production for many countries. They supply power to industries, centers, government facilities, and residential areas. Yet, upon review, several cases reveal that even a small-scale attack on a nuclear power plant could lead to catastrophic consequences for a country’s citizens, economy, infrastructure, and security. In recent years, there has been increased attention to the area of nuclear cybersecurity due to attacks or incidents designed to disrupt NPP operations. In spite of this rise of nuclear-related cyber attacks, the security for NPPs has not been holistically addressed. Literature review reveals the lack of a comprehensive information security framework to secure nuclear power plants from internal and external threats. This research highlights the significance of performing security assessments within NPPs as it relates to cyber defense. The contribution of this paper is twofold. First, it presents a detailed review of cyber challenges and security incidents that have occurred within NPPs, followed by a discussion on the initiatives taken by governments and regulatory bodies in mitigating such security challenges. Contextual background information on Critical Infrastructure Protection, nuclear power plants and information security risk management has been supplied to aid reader understanding. Additionally, this research posits that any kind of cyber incident on nuclear infrastructure may lead to catastrophic results, from which recovery may be impossible. Therefore, there is a significant need to perform detailed threat and vulnerability assessments that address either stand-alone attacks or coordinated attacks against the use of computer systems on NPPs. Following this discussion, a threat modelling is presented using an established methodology, which identifies possible threats to, vulnerabilities in, and adversaries of a generic Instrumentation and Control (I&C) system of a NPP by considering its characteristics and architecture. The analysis reveals that NPPs are not fully armed against cyber attacks and identifies a significant need to conduct security assessments such as the Information Security Risk Assessment, which would provide comprehensive and reliable risk analysis functionality to NPPs.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Pbnc 2012 Challenges of Cyber Security for Nuclear Power Plants

Nuclear Power Plants (NPPs) become one of the most important infrastructures in providing efficient and non-interrupted electricity in a country using radioactive elements due to global warming and shortage of fossil resources. To provide the higher reliability and better performance with additional diagnostic capabilities in operating NPPs, digital Instrumentation and Control (I&C) systems hav...

متن کامل

Cyber Security of FPGA-Based NPP I&C Systems: Challenges and Solutions

This paper presents an overview of the state-of-the-art of Field Programmable Gate Arrays(FPGA)-based Nuclear Power Plants (NPPs) Instrumentation and Control (I&C) systems cyber security assurance problem, starting from analysis of regulatory documents that cover various aspects of NPP I&C systems development and operation, FPGA technology implementation, as well as cyber security assessment an...

متن کامل

Cyber Security of Safety-critical Infrastructures: a Case Study for Nuclear Facilities

Computers have become crucial to the operations of government and business. Critical infrastructure protection policy has evolved since the mid-1990’s. Since 11 September 2001, the critical link between cyberspace and physical space has been increasingly recognized. Presently, critical infrastructure sectors face various cyber threats. In particular, the electrical power infrastructure is the m...

متن کامل

A Cyber Security Risk Assessment for the Design of I&c Systems in Nuclear Power Plants

The instrumentation and control (I&C) systems in nuclear power plants (NPPs) collect signals from sensors measuring plant parameters, integrate and evaluate sensor information, monitor plant performance, and generate signals to control plant devices for a safe operation of NPPs. Although the application of digital technology in industrial control systems (ICS) started a few decades ago, I&C sys...

متن کامل

Documenting Cyber Security Incidents

Organizations often record cyber security incidents to track employee workload, satisfy auditors, fulfil reporting requirements, or to analyze cyber risk. While security incident databases are often neglected, they contain invaluable information that can be leveraged to assess the threats, vulnerabilities, and impacts of cyber attacks, providing a detailed view of cyber risk in an organization....

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2016