Compliance-driven cybersecurity based on formalized attack pattern for NPPs원자력 발전소 제어 시스템을 위한 정형화된 공격 패턴 기반의 사이버보안 규제 대응 방안

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 213
  • Download : 0
DC FieldValueLanguage
dc.contributor.advisorYoon, Hyunsoo-
dc.contributor.advisor윤현수-
dc.contributor.authorLee, Minsoo-
dc.date.accessioned2021-05-11T19:42:20Z-
dc.date.available2021-05-11T19:42:20Z-
dc.date.issued2020-
dc.identifier.urihttp://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=901601&flag=dissertationen_US
dc.identifier.urihttp://hdl.handle.net/10203/283504-
dc.description학위논문(박사) - 한국과학기술원 : 전산학부, 2020.2,[iv, 53 p. :]-
dc.description.abstractThe I&C system of Nuclear Power Plants(NPPs) employ a cybersecurity program what government leads. The government requires that apply the security controls of regulation to develop and operate the system. Accordingly, the licensee of NPPs tries to comply with this requirement from the development phase. Michael Muckin called this method a compliance-driven approach in his paper[1]. This approach is efficient when the government supervises NPPs, but it is not efficient when the licensee produces NPPs. The security controls include all the NPP-related controls without consideration of system characteristics. In other words, the development organization spends much time to exclude unnecessary controls and to write the evidence. Also, the security of the system can weaken according to the security knowledge level of the developer, and this can lead to differences in security levels between systems. This dissertation proposes a method for selecting the security control that can be applied in the early development phase to ensure the security of the system and to reduce the cost of excluding unnecessary security control. We formalize an attack pattern and the security controls pattern and use a relationship between patterns. We conduct a case study on applying R.G. 5.71 in the PPS(Plant Protection System) to confirm the validation of our method.-
dc.languageeng-
dc.publisher한국과학기술원-
dc.subjectAttack Pattern▼aNPPs▼aR.G. 5.71▼aSecurity Control▼aCompliance-driven security-
dc.subject공격 패턴▼a원전 제어 시스템▼aR.G. 5.71▼a보안통제▼a규제기반 사이버보안-
dc.titleCompliance-driven cybersecurity based on formalized attack pattern for NPPs-
dc.title.alternative원자력 발전소 제어 시스템을 위한 정형화된 공격 패턴 기반의 사이버보안 규제 대응 방안-
dc.typeThesis(Ph.D)-
dc.identifier.CNRN325007-
dc.description.department한국과학기술원 :전산학부,-
dc.contributor.alternativeauthor이민수-
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0