The transition from traditional to cyber-physical structures has increased the interconnectivity between cyber and physical elements of modern power systems, making them more susceptible to cyber-attacks. Past incidents, such as the Ukrainian power grid attack in 2015, which caused a widespread blackout affecting over 225,000 consumers, highlight the urgency of safeguarding critical infrastructure. More recent attacks, such as the 2023 Rhysida Ransomware incident on China Energy Engineering Corporation, although not causing blackouts, resulted in the exfiltration of substantial data later auctioned for 50 Bitcoin, demonstrating their disruptive potential. This study reviews over 120 recent research articles on cyber-physical power systems (CPPS), encompassing attack taxonomies, real-world case studies, and advanced control structures. The reviewed implementations span IEEE 14-bus, 30-bus, 39-bus, and 118-bus systems, as well as SCADA and AMI datasets, with reported results showing detection accuracies above 96
Vulnerability analysis is one of the important processes of cyber security risk assessment. With the gradual application of industrial Internet, intelligent technology, intelligent systems and equipment in the field of nuclear power, the methods of cyber attacks on nuclear power plants are gradually diversified, and the cyber security threats faced by industrial control systems are also increasing, and their cyber security vulnerabilities need to be continuously assessed. In this paper, combined with the current threat characteristics of nuclear power plant industrial control system operating environment, the cyber security vulnerability of the system is studied, and the typical vulnerability analysis items of nuclear power plant industrial control system are proposed to analyze the vulnerability characteristics of the system under different cyber security threat factors. At the same time, a vulnerability evaluation method based on functional safety impact analysis is formed, which takes the security level and consequence degree of the attacked system as the basic score, and the impact degree on the design of the defense-in-depth defense line as the weight for comprehensive scoring. Assess the vulnerability level to provide reference for the cybersecurity risk assessment and design improvement of the industrial control system of the nuclear power plant.
在现代信息系统中,数据库管理系统扮演着至关重要的角色.隔离级别测试对数据库管理系统而言具有重要意义,它确保并发操作的隔离性和数据的一致性,从而防止数据损坏和安全风险的发生,并为用户提供可靠的数据访问保障.模糊测试是一种广泛应用于软件和系统测试的方法,通过搜索测试空间并生成多样化的测试案例,探索系统的边界条件、异常情况和潜在问题,以发现可能的漏洞.本文介绍了针对数据库隔离级别进行模糊测试的工具SilverBlade,旨在提升生成测试案例的多样性,深入探索隔离级别测试空间.为了有效搜索庞大的测试空间,设计了结构化的测试输入结构,将测试空间拆分成并发事务组合和并发事务执行交互模式两个子空间进行搜索.为了更全面地测试隔离级别核心实现测试空间,还设计了基于深度和广度的自适应搜索方式,用于有效变异测试案例.实验结果表明,SilverBlade能够生成多样性的测试案例,并能够在流行的数据库管理系统PostgreSQL中更广泛地覆盖数据库隔离级别核心实现代码.与对比工具相比,SilverBlade在提高隔离级别关键区域的测试覆盖率方面表现更佳.
As the nerve center of a nuclear power plant, the industrial control system is used to ensure the safety and economy of power plant operation. With the integration of industrialization and informatization, as well as the development of industrial Internet and big data in the field of nuclear power, more and more intelligent control systems and equipment are applied in nuclear power plants, introducing the cyber security threats of traditional IT systems. Safety hazards will directly affect the operation of the power plant. The identification of cyber security threats is an important basis for vulnerability analysis and risk assessment, and it is also an important input for effective cyber security design. This paper analyzes the cyber security characteristics of nuclear power plant control systems and equipment, identifies and categorizes design basis threats, and proposes countermeasures for design basis threats (DBT) to provide a reference for the design of nuclear power plant industrial control system cyber security.
As the nerve center of nuclear power plant, the control system ensures the safety and economy of power plant operation, and its software test is very important. With the development of digital nuclear power and the wide application of embedded system software in the world, more and more embedded software has been applied to the control system and intelligent equipment of nuclear power plant. This paper analyzes the characteristics of embedded system software of control system in nuclear power plant and the difference between embedded system software and general application software from the perspective of test, and the impact on test. It puts forward a unit test method of embedded software, which realizes the separation of application software and underlying hardware by means of software structure analysis, program piling, syntax modification, hardware simulation, etc. in nuclear power plant based on ARM architecture. The successful application of V&V project unit test of plant control system software provides reference for unit test of embedded and similar hybrid programming software.
Software V&V technology provides reliability and safety guarantee for digital system and intelligent equipment which used in nuclear power plant. Although a systematic scheme of software V&V technologies has been formed for nuclear power plant, there are some technical nodes need to be discussed and considered. The software V&V standard has been updated. The higher requirements are put forward for the depth, scope, the appropriate techniques and methods of the software V&V. This paper will discuss the upgraded version of software V&V related standards, and give the key points that software V&V technology needs to pay attention. Then the pre-development software identification, new software V&V technical of the special instrument and control system, and the applicability assessment of the safety analysis software are also been discussed. The technical difficulties faced by software V&V in the above aspects will be put forward. At last the future development direction of software V&V technology is proposed.
In nuclear power plant (NPP), the digital control system introduced nuclear safety software, whose fault tolerance and reliability directly affect the safety of nuclear power plant facilities. Current manual, simulation and testing strategies all have limitations. An effective method to test the system with software plays an important role to ensure the safe operation of NPP. In this paper, a digital control system software test strategy based on real platform is proposed. Taking the RPS system as an example, this strategy analyzes the system function and software logic path characteristics, then identifies the system state by threshold boundary analyzing, and designs a test method based on the random combination of logical combination paths and parameter value intervals, and builds a real platform test environment. This paper has tested the typical functions of Pressurized water reactor (PWR) protection system. The test results show that the test strategy has significantly improved the coverage of paths and parameters. Compared with manual testing, test efficient has been improved obviously in this test platform. At present, this strategy solves the problem of the low efficiency in manual testing, low real-level in simulation testing, and the insufficient coverage in simple automated testing strategy. This strategy also provides good practice for the control system testing and lays the foundation for the reliability evaluation of the system and software.
The intellectualization and digitization of nuclear power plants have become the new direction of nuclear power development. The intellectualization of nuclear power plants cannot be achieved without the use of network control technology, the internet of things can be applied to multiple scenarios in nuclear power plants. With the application of internet of things technology in nuclear power plants, the security of nuclear power plants has been paid more and more attention because the destruction of nuclear power plants can cause great social panic and political influence. This paper focus on the security technology of the internet of things in nuclear power plant. The paper includes five parts. The safety analysis methods and security measures for the application of internet of things technology in nuclear power plants are emphasized. In this paper, the security measures of the internet of things have be divided into six aspects.
This paper describes how PaaS secures the containers that host application instances on Linux generally. It provides an overview of container isolation and container networking, describes how PaaS administrators customize container network traffic rules for their deployment, and describes how PaaS secures containers by running application instances in unprivileged containers and by hardening them.
The control system decides the safety and economy as a neural center, the information security plays a critical role in control system. With the fusion of industrialize and information, and with the development of digital nuclear power plant, the increasing number of general software technologies including network communication, operational system, etc., have been used, the security problem from traditional IT system has been introduce into industrial control system. By the view of information security, this paper analyzes characteristics of industrial control system that used in nuclear power plant, and establishes a hierarchy model from company management to software entity, then provides the defensive method for probably and potential intrusion on each level. Finally, this paper summarizes defense in depth system from software design and development to social engineering, and provides references for the optimization of information security in industrial control system.
Reactor protection system (RPS) plays critical role in digital control system (DCS), and ensures the safety for nuclear power plant (NPP). System test is a necessary step during system development, verification and validation (V&V), which ensure the safety and reliability for RPS. The debugging of test environment and equipment is an important step that ensures the effective and efficiency of test. The system, such as RPS that contains complicated logic and large number of interfaces, cost a lot of time and human resource for debugging. A structured debugging method has been proposed in this paper, this method establishes debugging architecture with a hierarchical model in according to signal transmission path, and it designs the debugging process from down to top. The result from engineering practice show that this method has improved the effective and efficiency of debugging provides the support and reference for system test environment establishment.
Cloud computing is a hot topic in the field of Information Technology, and it is the focus of attention in industry, academia and government. The capacity of the IP address space and the security of the IP protocol is one of the basic parameters of cloud computing that must be considered and valued. IPv4 protocol cannot meet the cloud computing to a large number of new network application requirements; IPv6 protocol is an inevitable choice for cloud computing development. In this article, in-depth analysis for IPv6 security issues in cloud computing environments is conducted, and IPv6 security test model in the cloud computing environment is proposed to help improve and enhance the security of cloud computing.
V&V (Verification and Validation) is an important way to assure the safety and reliability of software. Requirement management plays a critical role through the whole process of V&V. Based on the practice on Generation II + pressurized water reactor named CPR1000, this paper establishes requirement management scheme for digital RPS (Reactor Protection System) software V&V, the scheme is applied in typical DCS (Digital Control System) V&V project of nuclear power plant, and enhances the trace efficiency. The successful engineering practice provides efficient requirement management reference for succeed nuclear DCS devices development and test projects.
根据调研结果,并结合有关消防产品标准和设计规范的历史演变,客观地分析在不同时期火灾自动报警系统所选工作状态的原因,深入剖析不同的系统工作状态在管理、产品、标准、操作等方面的弊端,提出法规、技术和制度方面的改善建议.
随着IPv6的部署和5G标准化的推进,下一代网络已成为业界关注的热点.通过分析下一代网络(NextGeneration Network,NGN)的4层体系结构以及其关键技术,结合我国的网络特点,提出目前仍有必要更进一步进入下一代网络;同时给出了下一带网络发展过程中的实践部署经验,提出其需要突破的地方,并结合现有的技术给出下一代网络在安全方面存在的问题及其解决方案.
详细介绍了压煮溶出工艺计算机控制系统的设计,主要包括自控系统网络设计、硬件设计、控制功能,为企业连续稳定地生产提供保证.
The firmware is an indispensable basic system in computer systems. With the increase of BIOS chip capacity and module functions, the hidden security problems of BIOS are also more and more. But there is no BIOS production capacity in Chinese mainland currently. The whole information security system has not really established completely. In the circumstances of computer widespread using in the government, institutions, commercial, schools and so on, how to ensure and monitor the security of BIOS system has important significance to ensure overall control of information security in China. This paper proposes the design and implementation methods for BIOS security testing procedures and testing system through the analysis of BIOS security, and provides a new way of thinking for BIOS security.
In recent years, with the increase of the quantity and quality of computer rooms in colleges and universities, the number of courses and practice are also growing, the management of computer system in computer room is more and more complicated and difficult. A variety of computer management application softwares were used to enhance room management and maintenance of the computer system. Combining Shanghai Wan Xin reduction technology adopted by the scientific management of computer rooms, the difference between the system and others as well as the installation of the system model, cloning system protection in the university computer center, network and remote monitoring management of computer rooms, and the use of computers were discussed.