Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Evaluating Methods of Software Bill of Materials Generation to Enhance Nuclear Power Plant Cybersecurity

Journal Article · · Nuclear Technology

Instrumentation and control (I&C) systems in nuclear power plants (NPPs) are potential targets of cyberattacks and can prove deleterious for the safety of the NPPs. A Software Bill of Materials (SBOM) provides a detailed list of the various components and their dependencies in software, which helps in vulnerability and risk assessment for cyber hygiene and situational awareness. For an NPP, the process of generating an accurate SBOM report can be complex due to the legacy systems and firmware binaries involved. While most current SBOM tools are focused more on modern internet technology software, this research provides insights and guidelines for an NPP to generate an accurate and efficient SBOM. Here, the paper proposes a new methodology to help NPPs categorize software and use appropriate tools to generate SBOMs for their digital I&C systems.

Research Organization:
Idaho National Laboratory (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
USDOE Office of Nuclear Energy (NE)
Grant/Contract Number:
AC07-05ID14517
OSTI ID:
2587599
Report Number(s):
INL/JOU--23-75742-Rev000
Journal Information:
Nuclear Technology, Journal Name: Nuclear Technology Journal Issue: 6 Vol. 211; ISSN 0029-5450; ISSN 1943-7471
Publisher:
Informa UK LimitedCopyright Statement
Country of Publication:
United States
Language:
English

References (4)

Cyber security issues imposed on nuclear power plants journal March 2014
Robust localized cyber-attack detection for key equipment in nuclear power plants journal October 2020
Building resilient medical technology supply chains with a software bill of materials journal February 2021
Software Bills of Materials Are Required. Are We There Yet? journal March 2023

Similar Records

Software Bill of Materials in the Nuclear Industry
Conference · Wed Jun 21 00:00:00 EDT 2023 · OSTI ID:2279155

Towards Software Bill of Materials in the Nuclear Industry
Technical Report · Thu Sep 01 00:00:00 EDT 2022 · OSTI ID:1901825

SCA Tools - SCRM Value Add or Lossy Noise Machines
Conference · Wed Oct 30 00:00:00 EDT 2024 · OSTI ID:2479528