86
1 Information Weapon: Concepts, Means, Methods …
– Unauthorized tampering with operation of the computer systems (such as informational, control and monitoring, and backup) communication and telecommunication systems, etc.
The nature of the threatening factors based on improper activities of a person
(agent, subverter) having very specific target for successful implementation of that
there is effected unauthorized acquisition of crucial data defines the problem of
protecting the information pertaining to the most relevant and most vulnerable
facilities and processes of NPP:
– Location of crucial facility of NPP;
– Assets of crucial facilities of NPP, their compositions, billing systems, control
modes, and checked parameters;
– Acutely relevant technological processes, methods and means of monitoring, and
diagnostics of crucial facilities implemented by computer systems;
– Systems of physical protection and life insuring of crucial facilities of nuclear
power plant
– Key personnel of NPP, etc.
Crucial information stored at tangible media and\or processed in computer
systems of nuclear power plant should be clearly identified and its protection should
be arranged in compliance with the established level of its relevance for NPP’s
security and legislation currently in force.
It can be specifically exemplified. Thus operational modes of NPP reactor unit
are determined by major processes:
– Energy generation;
– Start of reactor unit;
– Hot shutoff
– Cold shutoff
– Refueling.
Such rather sophisticated operational modes are controlled by various computer
systems in various production environments. The most stressful ones in terms of
safety assuring are the periods when the equipment is being replaced, software,
hardware, and systems are being modified and tested.
Thus, for instance, the dynamics of reactor units maintenance periods shall enable
the violators to alter the architecture and to create vulnerability (hardware Trojans)
in computer systems. Computer systems which are checked and as a rule are strictly
supervised in operational mode may get vulnerable during temporal shutoff.
There exist the threat of inputting the software Trojan (virus) at connecting
test computers or test equipment. For example, in order to provide assistance at
computer system testing there may be changed the configuration of security system
(for example, some protection mechanisms may be shutoff).
The typical case of vulnerability inputting (not only software, but hardware vulnerabilities) at maintenance is the technique frequently applied by providers\ subcontractors in their practical work to install a special purpose modem into computer
1 Information Weapon: Concepts, Means, Methods …
– Unauthorized tampering with operation of the computer systems (such as informational, control and monitoring, and backup) communication and telecommunication systems, etc.
The nature of the threatening factors based on improper activities of a person
(agent, subverter) having very specific target for successful implementation of that
there is effected unauthorized acquisition of crucial data defines the problem of
protecting the information pertaining to the most relevant and most vulnerable
facilities and processes of NPP:
– Location of crucial facility of NPP;
– Assets of crucial facilities of NPP, their compositions, billing systems, control
modes, and checked parameters;
– Acutely relevant technological processes, methods and means of monitoring, and
diagnostics of crucial facilities implemented by computer systems;
– Systems of physical protection and life insuring of crucial facilities of nuclear
power plant
– Key personnel of NPP, etc.
Crucial information stored at tangible media and\or processed in computer
systems of nuclear power plant should be clearly identified and its protection should
be arranged in compliance with the established level of its relevance for NPP’s
security and legislation currently in force.
It can be specifically exemplified. Thus operational modes of NPP reactor unit
are determined by major processes:
– Energy generation;
– Start of reactor unit;
– Hot shutoff
– Cold shutoff
– Refueling.
Such rather sophisticated operational modes are controlled by various computer
systems in various production environments. The most stressful ones in terms of
safety assuring are the periods when the equipment is being replaced, software,
hardware, and systems are being modified and tested.
Thus, for instance, the dynamics of reactor units maintenance periods shall enable
the violators to alter the architecture and to create vulnerability (hardware Trojans)
in computer systems. Computer systems which are checked and as a rule are strictly
supervised in operational mode may get vulnerable during temporal shutoff.
There exist the threat of inputting the software Trojan (virus) at connecting
test computers or test equipment. For example, in order to provide assistance at
computer system testing there may be changed the configuration of security system
(for example, some protection mechanisms may be shutoff).
The typical case of vulnerability inputting (not only software, but hardware vulnerabilities) at maintenance is the technique frequently applied by providers\ subcontractors in their practical work to install a special purpose modem into computer
