Search NASA⌕ Search

Engineering topics

Clements, Samuel L.

Publications and source records attributed to Clements, Samuel L..

Evaluating software defined networking solutions to reduce the digital attack surface of nuclear security systems

Most nuclear security systems used today were not designed for today’s threat environment. Systems that were intended to be stand alone are now interconnected. Devices that have a single purpose are built on multi-purpose platforms and communication protocols that, while effective, have no ability to authenticate authorized versus unauthorized commands. These attributes provide an attacker significant ability to affect the system, pivot throughout the interconnected networks, and remain undetected if he/she is able to compromise a single node. Software defined networking (SDN) has been used for years by information technology (IT) cloud service providers to quickly provision or remove servers or other systems to meet changing demand. The same concept has recently been applied to operational technology (OT) systems to enable very fast failover on critical systems that have stringent and deterministic (<5ms) transmit/receive times. By carefully engineering the communication flows through a network using preplanned routes and specific pathways it is possible to achieve deterministic and extremely reliable message delivery even when components fail. This engineering approach to network design has added security benefits including securing the networking control plane, eliminating network scanning and mapping, inhibiting ARP spoofing and host masquerading, eliminating unauthorized network pivoting and enabling greater situational awareness on the network. SDN in OT environments is new but early testing in electrical power and other critical infrastructure has shown it to be a very powerful tool for building reliable networks and reducing the digital attack surface of the network. The authors tested a software defined network switch on a simple physical protection system with components commonly found in nuclear security systems and found improved mitigations to denial of service attacks, lateral movement and network reconnaissance. The paper details the tests and their results.

Cyber security, Nuclear security, software defined↗

APPLICATION OF MATURITY MODELS FOR EVALUATING CYBERSECURITY PROGRAMS AT NUCLEAR AND RADIOLOGICAL FACILITIES

Maturity models can be used to provide government agencies, industry associations, and organizations operating nuclear facilities with the ability to quickly evaluate the maturity of their cybersecurity programs and identify areas to prioritize for improvement. The Cybersecurity Capability Maturity Model (C2M2) was developed by the U.S. Department of Energy to allow organizations in the energy sector to evaluate the programmatic capabilities of their cybersecurity programs in a consistent manner, communicate programmatic maturity information, prioritize cybersecurity investments in targeted areas of concern, and track how the maturity of their cybersecurity program evolves over time. The C2M2 is designed for use by any critical infrastructure organization regardless of ownership, structure, or size. The C2M2 can be easily fine-tuned to access the maturity of nuclear cybersecurity programs and their application at individual facilities. Built on a foundation of existing cybersecurity standards, frameworks, programs, and initiatives, the model features 10 security domains. Performance in each security domain is characterized using a structured set of cybersecurity practices that represent activities an organization can perform to improve cybersecurity in their domain. Each practice can be quickly evaluated as being either fully, largely, partially, or not implemented. Once practices are evaluated for each security domain, the model defines four maturity indicator levels that apply independently to each domain in the model. To earn a maturity level in a given domain, an organization must adequately perform all the practices for that maturity level and its predecessor level(s). A small assessment team can conduct a C2M2 assessment in a single day. A screening version of the C2M2 allows an initial look at the maturity of nuclear cybersecurity programs that could be completed in under an hour.

Cyber security, Nuclear security, maturity model↗