Title
Development of a cyber security risk model using Bayesian networks.
Abstract
Cyber security is an emerging safety issue in the nuclear industry, especially in the instrumentation and control (I&C) field. To address the cyber security issue systematically, a model that can be used for cyber security evaluation is required. In this work, a cyber security risk model based on a Bayesian network is suggested for evaluating cyber security for nuclear facilities in an integrated manner. The suggested model enables the evaluation of both the procedural and technical aspects of cyber security, which are related to compliance with regulatory guides and system architectures, respectively. The activity-quality analysis model was developed to evaluate how well people and/or organizations comply with the regulatory guidance associated with cyber security. The architecture analysis model was created to evaluate vulnerabilities and mitigation measures with respect to their effect on cyber security. The two models are integrated into a single model, which is called the cyber security risk model, so that cyber security can be evaluated from procedural and technical viewpoints at the same time. The model was applied to evaluate the cyber security risk of the reactor protection system (RPS) of a research reactor and to demonstrate its usefulness and feasibility.
Year
DOI
Venue
2015
10.1016/j.ress.2014.10.006
Reliability Engineering & System Safety
Keywords
DocType
Volume
Cyber security,Activity-quality,Architecture analysis,Bayesian network,Reactor protection system,Research reactor
Journal
134
ISSN
Citations 
PageRank 
0951-8320
9
0.50
References 
Authors
9
4
Name
Order
Citations
PageRank
Jinsoo Shin190.50
Hanseong Son2515.54
Rahman Khalil ur390.50
Gyunyoung Heo490.50