84
1 Information Weapon: Concepts, Means, Methods …
Generally cybersecurity of a nuclear power plant means protection of technological process against unauthorized entry. In fact the most hazardous case for nuclear
power plant if control of the technological process is undertaken by somebody or
something without authorization. It may be virus or a person (using software and
hardware Trojans).
Cybersecurity of nuclear power plant is assured at numerous levels—at each level
where there is data or digital control is found.
At the first data level, there are the sensors mounted at the equipment and also
the programmable microcontrollers these sensors are connected to. Microcontrollers
receive the data from the sensors, analyze it as per dedicated algorithms, and produce
control impacts at actuators of the equipment. At this level, there are installed various
tools for protection of the technological process.
At the second level, the data gathered by microcontrollers through special-purpose
locks (the so-called lock contour) is up-loaded to local network of high unit level
system. At the information board of high unit level system all the events that happen
to the equipment can be viewed by operators. The operators do not control the
technological process directly from computers.
Direct control is carried out not by a person but by controllers where there is
installed small-scale software products. All the commands issued by operators are
subjected to verification. If the command is approved, it will be transmitted to control
system. If the command is banned, it will be disabled. This is one of the measures to
assure cybersecurity of the technological process. This controller may be contaminated with “Trojan” either at the stage of its production (if it is produced abroad) or
in the process of routine works (repair, preventive maintenance).
The third data level at nuclear power plant is the level of “non-on-line” control.
Staff members of the plant using their computers may supervise the technological
processes, both in real time and those stored in archives, but they are not able to
control in any way to control them. Automated process control system of a nuclear
power plant has no access to INTERNET: the system has no any connection with
global network. Nuclear power plant transmits the respective data outside (to crisis
center, in particular) only by dedicated secured communication channels. Only standard networks which are used for accountant’s documents’ traffic have access to
INTERNET. But these networks exist separately and is not physically connected
with automated process control system. However as per the experience of the abovementioned covert operations “Olympic Games,” in this case the actuating virus may
be smoothly introduced by means of just flash memory stick fetched in by violator.
At each of the data levels, there exist their own managerial and technical procedures for protection against cyberthreats. For example, automated process control
system is controlled by administrators. They are not subordinated to each other and
have no idea about passwords, and one monitors what the other one is doing. Only
secured computers are in use, where all the components (hardware and software
installed) should be certified and on a regular basis checked by the experts of the
data security department.
There is login ban for external storage media in effect: at nuclear power plants it is
prohibited to attach an unknown flash-card to the computer running in the automated
1 Information Weapon: Concepts, Means, Methods …
Generally cybersecurity of a nuclear power plant means protection of technological process against unauthorized entry. In fact the most hazardous case for nuclear
power plant if control of the technological process is undertaken by somebody or
something without authorization. It may be virus or a person (using software and
hardware Trojans).
Cybersecurity of nuclear power plant is assured at numerous levels—at each level
where there is data or digital control is found.
At the first data level, there are the sensors mounted at the equipment and also
the programmable microcontrollers these sensors are connected to. Microcontrollers
receive the data from the sensors, analyze it as per dedicated algorithms, and produce
control impacts at actuators of the equipment. At this level, there are installed various
tools for protection of the technological process.
At the second level, the data gathered by microcontrollers through special-purpose
locks (the so-called lock contour) is up-loaded to local network of high unit level
system. At the information board of high unit level system all the events that happen
to the equipment can be viewed by operators. The operators do not control the
technological process directly from computers.
Direct control is carried out not by a person but by controllers where there is
installed small-scale software products. All the commands issued by operators are
subjected to verification. If the command is approved, it will be transmitted to control
system. If the command is banned, it will be disabled. This is one of the measures to
assure cybersecurity of the technological process. This controller may be contaminated with “Trojan” either at the stage of its production (if it is produced abroad) or
in the process of routine works (repair, preventive maintenance).
The third data level at nuclear power plant is the level of “non-on-line” control.
Staff members of the plant using their computers may supervise the technological
processes, both in real time and those stored in archives, but they are not able to
control in any way to control them. Automated process control system of a nuclear
power plant has no access to INTERNET: the system has no any connection with
global network. Nuclear power plant transmits the respective data outside (to crisis
center, in particular) only by dedicated secured communication channels. Only standard networks which are used for accountant’s documents’ traffic have access to
INTERNET. But these networks exist separately and is not physically connected
with automated process control system. However as per the experience of the abovementioned covert operations “Olympic Games,” in this case the actuating virus may
be smoothly introduced by means of just flash memory stick fetched in by violator.
At each of the data levels, there exist their own managerial and technical procedures for protection against cyberthreats. For example, automated process control
system is controlled by administrators. They are not subordinated to each other and
have no idea about passwords, and one monitors what the other one is doing. Only
secured computers are in use, where all the components (hardware and software
installed) should be certified and on a regular basis checked by the experts of the
data security department.
There is login ban for external storage media in effect: at nuclear power plants it is
prohibited to attach an unknown flash-card to the computer running in the automated
