首页> 外文期刊>Transactions of the American nuclear society >An Overview of Methodologies for Cybersecurity Vulnerability Assessments Conducted in Nuclear Power Plants
【24h】

An Overview of Methodologies for Cybersecurity Vulnerability Assessments Conducted in Nuclear Power Plants

机译:核电厂进行的网络安全漏洞评估方法概述

获取原文
获取原文并翻译 | 示例
           

摘要

After reviewing regulatory guidance from the NRC, VA practices in non-nuclear digital control systems, and the commentaries of other experts in the field, we conclude that established VA methodologies are inadequate as is for usage in the digital I&C systems of modernized NPPs. Current regulation establishes safety systems that are substantially hardened against outside attacks, by utilizing one-way communication and locked and alarmed physical access. However, these systems remain vulnerable to potential self-generated incidents, such as those occurring at the Browns Ferry NPP. Additionally, non-safety and data acquisition systems require further hardening as they are more exposed by defense-in-depth strategies, yet are still vital for operations. We propose that the methodologies established by the NRC can be most improved by more fully investigating the interconnectivity of all digital system components, reevaluating and redefining the risk associated with these components, and continually monitoring the security of the system throughout the entire lifetime of the NPP.
机译:在回顾了NRC的监管指南,无核数字控制系统中的VA做法以及该领域其他专家的评论后,我们得出结论,既定的VA方法与现代化NPP的数字I&C系统中使用的方法是不足够的。当前的法规建立了安全系统,该系统通过利用单向通信以及锁定和报警的物理访问来实质上增强了抵抗外部攻击的能力。但是,这些系统仍然容易受到潜在的自发事件的影响,例如发生在布朗斯渡轮核电厂的事件。此外,非安全和数据采集系统需要进一步加强,因为它们会被深度防御策略所暴露,但对于运营仍然至关重要。我们建议,可以通过更充分地研究所有数字系统组件的互连性,重新评估和重新定义与这些组件相关的风险以及在NPP整个生命周期中持续监视系统的安全性,来最大程度地改善NRC建立的方法。 。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号