Compliance-driven cybersecurity based on formalized attack pattern for NPPs원자력 발전소 제어 시스템을 위한 정형화된 공격 패턴 기반의 사이버보안 규제 대응 방안

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 197
  • Download : 0
The I&C system of Nuclear Power Plants(NPPs) employ a cybersecurity program what government leads. The government requires that apply the security controls of regulation to develop and operate the system. Accordingly, the licensee of NPPs tries to comply with this requirement from the development phase. Michael Muckin called this method a compliance-driven approach in his paper[1]. This approach is efficient when the government supervises NPPs, but it is not efficient when the licensee produces NPPs. The security controls include all the NPP-related controls without consideration of system characteristics. In other words, the development organization spends much time to exclude unnecessary controls and to write the evidence. Also, the security of the system can weaken according to the security knowledge level of the developer, and this can lead to differences in security levels between systems. This dissertation proposes a method for selecting the security control that can be applied in the early development phase to ensure the security of the system and to reduce the cost of excluding unnecessary security control. We formalize an attack pattern and the security controls pattern and use a relationship between patterns. We conduct a case study on applying R.G. 5.71 in the PPS(Plant Protection System) to confirm the validation of our method.
Advisors
Yoon, Hyunsooresearcher윤현수researcher
Description
한국과학기술원 :전산학부,
Publisher
한국과학기술원
Issue Date
2020
Identifier
325007
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전산학부, 2020.2,[iv, 53 p. :]

Keywords

Attack Pattern▼aNPPs▼aR.G. 5.71▼aSecurity Control▼aCompliance-driven security; 공격 패턴▼a원전 제어 시스템▼aR.G. 5.71▼a보안통제▼a규제기반 사이버보안

URI
http://hdl.handle.net/10203/283504
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=901601&flag=dissertation
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0