Standard Standard

Cyber security in the nuclear industry: A closer look at digital control systems, networks and human factors. / Ayodeji, Abiodun; Mohamed, Mokhtar; Li, Li et al.
In: Progress in Nuclear Energy, Vol. 161, 104738, 01.07.2023.

Research output: Contribution to journalArticlepeer-review

HarvardHarvard

APA

CBE

MLA

VancouverVancouver

Ayodeji A, Mohamed M, Li L, Di Buono A, Pierce I, Ahmed H. Cyber security in the nuclear industry: A closer look at digital control systems, networks and human factors. Progress in Nuclear Energy. 2023 Jul 1;161:104738. Epub 2023 May 20. doi: https://doi.org/10.1016/j.pnucene.2023.104738

Author

Ayodeji, Abiodun ; Mohamed, Mokhtar ; Li, Li et al. / Cyber security in the nuclear industry: A closer look at digital control systems, networks and human factors. In: Progress in Nuclear Energy. 2023 ; Vol. 161.

RIS

TY - JOUR

T1 - Cyber security in the nuclear industry: A closer look at digital control systems, networks and human factors

AU - Ayodeji, Abiodun

AU - Mohamed, Mokhtar

AU - Li, Li

AU - Di Buono, Antonio

AU - Pierce, Iestyn

AU - Ahmed, Hafiz

PY - 2023/7/1

Y1 - 2023/7/1

N2 - The development life cycle of conventional nuclear power plants (NPPs) needs to be optimized if the energy produced by advanced reactors and small modular reactors is to be competitive. One of the proposed optimisation initiatives is the digitalization of nuclear facility control and instrumentation. Digitalization of nuclear control and instrumentation will improve plants' performance and cost competitiveness. However, it could also introduce cyber security challenges. To create a strong cyber-defence for critical digital assets in nuclear facilities, an extensive analysis of threats and vulnerabilities in systems, networks, and devices is necessary. This article examines recent research that analyses the digital assets at nuclear power facilities for threats and vulnerabilities. This work synthesizes and categorises potential attack propagation paths in digitalized nuclear facilities based on five different surfaces: direct network path, programmable logic controllers, sensor/actuator signals, and indirect propagation paths such as attacks that exploit human factors and the supply chain. The work's main contribution is it provides a state-of-the-art understanding of the relationship between attack propagation paths, associated vulnerabilities, and current security controls. Based on the literature review, a framework for developing an attack-resilient control system for NPPs is suggested, which would be helpful for a security-informed design of reactor control systems. The discussion on nuclear cyber risks, vulnerabilities, attack routes, and defence methods offers a cutting-edge understanding of the security challenges in digitalized nuclear facilities. The suggested framework is an essential foundation for future research direction, towards a secured and resilient digitisation of nuclear power plant control systems.

AB - The development life cycle of conventional nuclear power plants (NPPs) needs to be optimized if the energy produced by advanced reactors and small modular reactors is to be competitive. One of the proposed optimisation initiatives is the digitalization of nuclear facility control and instrumentation. Digitalization of nuclear control and instrumentation will improve plants' performance and cost competitiveness. However, it could also introduce cyber security challenges. To create a strong cyber-defence for critical digital assets in nuclear facilities, an extensive analysis of threats and vulnerabilities in systems, networks, and devices is necessary. This article examines recent research that analyses the digital assets at nuclear power facilities for threats and vulnerabilities. This work synthesizes and categorises potential attack propagation paths in digitalized nuclear facilities based on five different surfaces: direct network path, programmable logic controllers, sensor/actuator signals, and indirect propagation paths such as attacks that exploit human factors and the supply chain. The work's main contribution is it provides a state-of-the-art understanding of the relationship between attack propagation paths, associated vulnerabilities, and current security controls. Based on the literature review, a framework for developing an attack-resilient control system for NPPs is suggested, which would be helpful for a security-informed design of reactor control systems. The discussion on nuclear cyber risks, vulnerabilities, attack routes, and defence methods offers a cutting-edge understanding of the security challenges in digitalized nuclear facilities. The suggested framework is an essential foundation for future research direction, towards a secured and resilient digitisation of nuclear power plant control systems.

U2 - https://doi.org/10.1016/j.pnucene.2023.104738

DO - https://doi.org/10.1016/j.pnucene.2023.104738

M3 - Article

VL - 161

JO - Progress in Nuclear Energy

JF - Progress in Nuclear Energy

SN - 0149-1970

M1 - 104738

ER -