Threat Model: The Networked Reactor
A structured enumeration of who might attack a Kronos plant, what they want, and how they could try - the basis every control in this section is measured against.
Adversaries and objectives
A threat model names the adversary before naming the defense. For a networked fusion plant Kronos considers: nation-state actors seeking to damage critical energy or defense infrastructure (Aegis is a fixed defense installation); criminal actors seeking disruption or extortion leverage; malicious or coerced insiders; and opportunistic attackers riding IT compromises. Objectives range from causing an unsafe plasma state, to disrupting availability, to stealing design or byproduct-material data, to corrupting the digital twin's models.
Attack surfaces
- The external L7 API and enterprise IT - see IT/OT separation.
- The OT control network and its edge FPGAs - see secure boot.
- The supply chain for hardware, firmware, and ML models - see supply-chain security.
- Diagnostics and actuation paths - see diagnostic spoofing and actuator manipulation.
- People with legitimate access - see insider-threat model.
Consequence ranking
Rows: unsafe physical state, byproduct-material data integrity, availability disruption, and model/twin corruption. Columns: high consequence, high exposure. Safety of the physical state is the top priority regardless of likelihood, which is why safety-critical cyber gets an independent path.
How the model is used
Each control in this section maps to threats it mitigates and residual risks it leaves. The model is revisited as the design evolves; new subsystems are added to the surface list and re-scored. Design status: the threat model is a living design document exercised against the twin and red-team simulations - see red-team validation - not against an operating reactor, which does not yet exist.