首页> 外文会议>Conference on Nuclear Plant Instrumentation, Control and Human-Machine Interface Technologies >IAEA Coordinated Research Project on Enhancing Incident Response at Nuclear Facilities
【24h】

IAEA Coordinated Research Project on Enhancing Incident Response at Nuclear Facilities

机译:国际原子能机构协调研究项目加强核设施事故响应

获取原文

摘要

In June 2016, the IAEA commenced a new coordinated research project (CRP) J02008 titledEnhancing Computer Security Incident Response at Nuclear Facilities. The objective of this CRPis to conduct activities which support improved computer security capabilities at nuclear facilitiesto support the prevention and detection of, and response to, computer security incidents that havethe potential to either directly or indirectly adversely affect nuclear safety and nuclear security.This CRP provides the opportunity to participate in four activities to enhance computer securityincident analysis and response: (1) Operator support for computer security incident recognitionand response; (2) Analysis and technology support for computer security incident response; (3)Computer security Information Exchange; and (4) Cyber Crime Investigation.To achieve these aims, 17 institutes from 13 countries began to conduct research and developmenton design and construction of research environments that reflect and perform like nuclear facilitiesand/or their I&C systems.The oversight and coordination of the project led to the definition of three roles: (1)Facility/System Builders; (2) Threat Modellers; and (3) Capability Providing Organizations.Facility/System Builders are organizations that are intending to build mock-ups of nuclear systemsas part of their research. The current completed efforts are the first release of a model/simulatorthat can simulate the impact of cyber attacks on a hypothetical facility. The model/simulator canalso be used with compatible hardware in the loop systems.Threat Modellers are organizations that are developing Design Basis Threat (DBT), Scenarios, andThreat Tactics, Techniques and Procedures (TTP). The objective of these organizations is to buildupon existing threat models and information exchange to establish a possible threat modelapplicable to nuclear security.Capability Providing Organizations are organizations that can provide specific capabilities toothers in the CRP that stem from their background expertise and/or the research they will beconducting in the CRP, e.g., on vulnerability assessment, security controls assessment, policies.These organizations will be using IEC cyber security standards as a common basis on which topostulate, design, and implement computer security measures with respect to incident response.This paper will provide a summary of the research approaches and the results of the CRP J02008,and preview the final results expected by the end of 2019.
机译:2016年6月,国际原子能机构开始了一个新的协调研究项目(CRP)J02008标题在核设施加强计算机安全事件响应。这个CRP的目标是开展支持核设施改善计算机安全功能的活动支持预防和检测,并响应计算机安全事件潜力直接或间接地影响核安全和核安全。该CRP提供了参加四项活动的机会,以提高计算机安全事件分析和响应:(1)操作员支持计算机安全事件识别和反应; (2)对计算机安全事件响应的分析和技术支持; (3)计算机安全信息交换; (4)网络犯罪调查。为实现这些目标,来自13个国家的17个研究所开始进行研发论核设施等研究环境的设计与施工和/或他们的I&C系统。该项目的监督和协调导致了三个角色的定义:(1)设施/系统建设者; (2)威胁莫德勒; (3)提供组织的能力。设施/系统建设者是打算构建核系统模型的组织作为他们研究的一部分。目前已完成的努力是模型/模拟器的第一个版本这可以模拟网络攻击对假设设施的影响。型号/模拟器可以还可以在循环系统中使用兼容硬件。威胁莫德勒是开发设计基础威胁(DBT),情景和和的组织威胁策略,技术和程序(TTP)。这些组织的目标是建立在现有威胁模型和信息交换时建立可能的威胁模型适用于核安全。提供组织的能力是可以提供特定功能的组织CRP中的其他人源于他们的背景专业知识和/或他们将是的在CRP中进行,例如,关于漏洞评估,安全控制评估,政策。这些组织将使用IEC网络安全标准作为其常见的基础关于事件响应的假设,设计和实施计算机安全措施。本文将提供研究方法的摘要和CRP J02008的结果,并预览2019年底预期的最终结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号