Present the Ability of Risk Approaches to Adapt to Technology Evolution
978-1-5386-7531-1/18/$31.00 ©2018 IEEE
Intelligent System for Risk Identification of Cybersecurity Violations in Energy Facility
Gaskova Daria, Aleksei Massel Laboratory of Information Systems in energetics Melentiev Energy Systems Institute of SB RAS
Irkutsk, Russia [email protected], [email protected]
Abstract—The article describes risk-based approach intended
for analyzing threat and assessing risk of cybersecurity violations in the energy facilities. In the energy sector this approach should consider harm produced by damage or demolition of the object using quantitative and qualitative parameters. It is based on the probability of damage or destruction of the facility resulting in the cascade failure. It can be employed for developing the information-analytical system aimed to monitor cybersecurity violations in the energy sector.
Keywords—cybersecurity; critical infrastacture; risk assessment; intelligent system
I. INTRODUCTION The Russian energy infrastructure is truly significant, as it
combines power plants and energy systems, including energy transporting main lines. The critical infrastructures are currently being explored [1-2]. Because the energy penetrated all life spheres in the modern society, it is believed to be the vital component of national security [3]. It is noteworthy, that energy security (ES) makes an important part of Russia’s national security. The development of Smart Grid conception in Russia exacerbates the problem of cybersecurity in energy. ES threats are traditionally classified into five main groups: economic, social-political, technogenous, natural and managerial-legal [4]. This threat list was supplemented with the cybersecurity threats [2], their implementation possibly provoking serious emergency situations in energy fraught with drastic reduction of energy resources to be provided to consumers.
The rapid spread of the computer environment, development of information technologies and the trend of transition to intellectual energy make the cyber threats most notable tactical threats of ES. As a matter of fact, both systematic preventive measures of cyber threats averting and continuous protection updating are underrated. It can lead to significant long-term deficit of energy supply, which negative impacts depend on cyber threats scale and damage.
Complimented by the reasons above, the authors propose to create an intelligent system capable to identify risk of cybersecurity violations in the energy facility based on a risk- based approach.
II. ENERGY AS AN IMPORTANT CRITICAL INFRASTRUCTURE Critical infrastructure is part of civil infrastructure, which
makes up a combination of physical or virtual systems and
means that are important for the country, as their failure or destruction can trigger disastrous consequences in the fields of defense, economy, and health and nation security [1].
The requirements for ensuring cybersecurity in the energy sector were formed in the foreign countries [5]. Actually in Russia the normative framework for ensuring cybersecurity in critical infrastructures is beginning to be formed. Information protection in the automatic process control system in energy is usually provided on the basis of the Federal Service for Technical and Export Control of Russia order № 31 [6]. This order establishes requirements to ensure protection of information in critical objects from illegal actions, including computer attacks. The development of the normative framework of the information protection in critical infrastructure is that the project stage of the Federal Law “On the Security of the Critical Information Infrastructure of the Russian Federation (RF)”. The draft law establishes the main directions and principles to ensuring security of critical information infrastructure, the government agent powers of the RF in this area, and also the rights, duties and responsibilities of owners, communications, providers and operators and also state information system operators that provide the functioning and interaction of these facilities [7].
Investigations of critical infrastructure and, in particular, identification of critically dangerous facilities are a focus area in many countries and primarily in the United States. The reason for this is that the development level of information technologies and capacity of modern simulation complexes constantly increase [1].
Nowadays the energy sector in Russia occurs at the stage of intellectualization, including both technological equipment (e.g. smart sensors, data transmission networks) and application of modern information technologies, primarily in the electrical energy industry. At the same time, the introduction of information technologies into the energy industry carries many risks and threats [8].
III. CYBERSECURITY According to the standard T-REC-X.1205 - ITU-T [9],
cybersecurity is treated as a set of tools, strategies, principles of security, security guarantees, guidelines, risk management approaches, actions, training, experience, insurance and technologies that can be used to protect the cyber environment, resources, organizations and users.
This work was partially supported by RFBR grants №15-07-01284, №17- 07-01341. The authors are grateful to this organization.
Authorized licensed use limited to: Northcentral University. Downloaded on October 19,2021 at 13:52:31 UTC from IEEE Xplore. Restrictions apply.
Cyber environment is connected with computing devices, personnel, infrastructure, applications, services, telecommunications systems, as well as the totality of transmitted and / or stored information.
Cybersecurity is an attempt to achieve and maintain the security properties from the resources of the organization or user against relevant security threats in the cyber environment.
According to ISO 27032: 2012 [10], cybersecurity is based on: Applications Security, Information Security; Network Security, Internet Security and Critical Information Infrastructure Protection, but – isn’t their synonymous.
The protection of key information systems of critical infrastructures primarily concerns ensuring ES facility.
The main concepts of cybersecurity are the asset, threat, vulnerability and risk. The main definitions of security and their relationships, described in foreign and translated standards [2] share similarities. Security is concerned with the assets protecting from threats classified based on the potential of protected assets abuse, and particular attention is paid to the threats that are associated with malicious or other human actions [11].
The ontology of cybersecurity in the energy sector [12] and the methodology for threats analysis and risk assessment of security violations in energy complexes were developed at the Melentiev Energy Systems Institute SB RAS. The methodology including eight stages is based on expert assessments and methods of qualitative risk analysis [13].
An asset is some entity valuable to a person or organization [11]. A security threat is possible action that can directly or indirectly damage the information security. The damage to security is understood as violation of confidentiality, accessibility or / and integrity of information.
Threats are classified by the nature of the occurrence, deliberateness degree, manifestation of direct threat source, position of threat source, extent of dependence upon activity, degree of impact on the system, resources access methods, current location of information stored and processed in the system. In particular threats are classified by the degree of deliberateness:
Threats caused by human errors or negligence.
Threats of deliberate action.
Cybernetic attack is the threat of deliberate action, initiated by a man.
Vulnerability is the weakness in the information system, security system and internal controls gaps that can be exploited or caused by a threat source [14].
Risk is an event with negative consequences caused by external or internal factors [14]. Risk can be defined as a combination of the accident probability and the scale of the damage it can cause, or as a combination of the event probability and impact [2].
Risk management is the process of in-depth study factors that can lead to realization of possible threats to the assets of
the system. The PDCA (Plan, Do, Check, Act) process model also known as the Deming-Shewhart cycle is common for risk assessment [11].
The widespread interest in the industrial systems security arose not so long ago after a series of specialized computer virus incidents, such as Flame and Stuxnet. At that time it was transpired, that international intelligence agencies, competing corporations or cyber-terrorists can use inadequate attention to the information security of the automatic process control system and their components for their own purposes (for instance, Supervisory Control And Data Acquisition SCADA / Power-Line Communication PLC) [15].
The development of an effective cybersecurity strategy requires a holistic approach to risk analysis. This means that systematic documentation and prioritization of the existing vulnerabilities (threats) of the management system and their possible consequences are required. Therefore, the owners of energy assets can make adequate decisions to anticipate and respond to the existing and potential threats.
IV. RISK-BASED APPROACH Risk-based approach considers harm from damage or
demolition of the object using quantitative and qualitative parameters, as well as further damage or destruction probability of the object components, based on probability of damage or destruction of object leading to cascade failure. The formula of risks consists of three components (1),
R = {T, V, D}, (1)
T – threats, V – vulnerabilities, D – damage by threat realization.
Threats are defined through the probability of events occurrence leading to critical situations (for example, conditional probabilities used in the Bayesian networks). Cyber threats can call subsequent implementation of the other ES threats. It was suggested to apply the Bayesian networks to build cyber threats implementation scenarios using conditional probability.
Assets vulnerabilities are determined by an expert poll using production expert system. The knowledge base of the expert system includes the standards of the five components of cybersecurity.
The damage is traditionally evaluated in monetary terms; however, conventional units are applied at this stage.
It is proposed to develop an intelligent system to support decision-making concerning assurance of energy facility cybersecurity by a specialist involved in information security. This system utilizing the risk-based approach should contribute to identifying critical assets, their vulnerabilities and threats to security violations, determination scenarios for applying threats and measures to protect assets from threats. The system will dwell upon the methodology for analyzing threats and assessing risk of information technology security violations of the energy complexes proposed by A. Massel [16].
Authorized licensed use limited to: Northcentral University. Downloaded on October 19,2021 at 13:52:31 UTC from IEEE Xplore. Restrictions apply.
V. THE INTELLIGENT SYSTEM DEVELOPMENT In current times the structure of intelligent system for risk
identification of cybersecurity violations in energy facilities is designed, and also scientific-research prototype for system describe above is implemented. One consists of three interrelated components: (1) an expert system for recognizing vulnerability and primary threats, (2) the Bayesian network for modeling threat scenarios, and (3) the module for assessing risk of cybersecurity violations, which includes visualization as a risk map.
The intelligent system structure is shown in Figure 1.
Expert system
Bayesian network
Risk evaluation
Expert
List of vulnerabilities
List of threats
Threats scenarios
Damage Threats scenarios
Map of risks
Fig. 1. Structure of intelligent system.
Figure 2 shows the ontology of basic concepts of cyber threats incorporated into an intelligent system.
Fig. 2. The ontology of basic concepts of cyber threats.
Assets are considered in terms of the information infrastructure of critical facility, e.g. assets of automatic process control system are considered at the levels of: operator, automatic control, and executive devices.
Threats and vulnerabilities are first considered at the top level, including general concepts and their most extensive list, and then at a detailed level that provides specific names, technical and software types and species.
The expert system involves three issues: (1) the energy facility asset, (2) vulnerability of information technology system and (3) cybersecurity violation threat of the facility. The expert system is intended for detecting primary vulnerabilities and threats of the facility. It is based on the user that is information security specialist answers to the questions offered by the system in the form of a questionnaire.
The interconnection between assets, vulnerabilities and threats within the system is established by templates. The template has a number of main fields. The vulnerability pattern is exemplified as:
<Vulnerabilities >
< Title >…</ Title >
<Assets >…</Assets >
<Threats>…</Threats> or <List of threats> …</List of threats>
<Control>…</ Control>
</Vulnerabilities >
The most common vulnerabilities and threats described to instance energy facility are searched for, and then their list is formed.
Further the list of threats is delivered to the Bayesian network to determine conditional probabilities and build threats realization scenarios.
The scientific prototype of the production expert system has been recently implemented. Figure 3 illustrates the prototype structure.
JAVA CLIPS
JNI
Swing
Listeners
Core of Expert system
Knowledge base
Inference engine
Rules Templates
Graphical Users Interface
Interaction interface
Fig. 3. Prototype structure.
The graphical user interface (GUI) includes data display, user interface event service; it is accomplished in the high-level Java language using the Swing library. The interaction interface is a Java native interface (JNI) mechanism for running code controlled by the Java virtual machine, which is employed for the GUI to C Language Integrated Production System (CLIPS) interaction. The core of the expert system is produced using software environment for the expert systems development CLIPS, and it is a logical inference mechanism and knowledge base.
Authorized licensed use limited to: Northcentral University. Downloaded on October 19,2021 at 13:52:31 UTC from IEEE Xplore. Restrictions apply.
The Bayesian network will be employed with the same software tools that were used for the expert system prototype for their integration. Threats and their partial communication established in the expert system are transferred to the Bayesian network for the expert work. It is assumed that the threat pattern has tag fields containing lists of threats that usually cause or are the cause of the other threat. An expert checks the existing links and establishes the missing links between the threats, resulting in a threat graph, i.e. scenarios of threat realization. The graph model determines conditional probabilities sated a priori probability of realizing threats acting as an initiating event. The use of the Bayesian network allows analyzing the cyber threats impact on energy security violation threats. Figure 4 illustrates the “unauthorized access” threat scenario.
Fig. 4. Realization of threat “unauthorized access” using the Bayesian
network in the Netica program.
For example, let us define the probability of “unauthorized access” to the automated workstation of the SCADA system manager threat. Suppose that the result of the expert's work with the expert system is a list of threats, such as the possibility to steal password, weak password policy and, as a consequence, the probability of unauthorized access by an attacker. The easy, average and difficult accessibility of stolen password are the three states of the “steal a password” threat. The password policy can also have three states: weak, medium and strong. Depending on the likelihood of described above threats implementing the threat of “unauthorized access” can be either realizable or unrealizable with a certain calculated probability. The attacker’s obtained access can affect the state of the energy facility data transmission. With that energy facility functioning can be disrupted, if information about the pre-crisis state of the system will be significantly detained or lost.
The presented example assumes weak password policy, and that the password on the facility can be easily stolen. Then the fact of the system pre-crisis state is the case. Most probably, an attacker will not disclose his unauthorized access and will delay information on the system state. In this case, the probability of transiting from the pre-crisis to the crisis state is high.
Risk will be assessed by graph traversing for each plausible scenario in the expert view. In order to do that an expert will fill in “damage” fields for each field of final states in the scenario. The module will calculate risk, where the risk is a multiplication of the likelihood of the threat realized for damage from it, and display a ranked list of scenarios.
In addition, the risk assessment module should provide a visualization of threat implementation risk card for a certain asset. A risk map is needed to display risks following threat types and the risk acceptance boundary. Figure 5 displays a risk map. The ranked list of critical assets of the facility is also supposed to be displayed. In these instances, critical assets are the assets, which accounted for the greatest number of threats in the scenarios, and the likelihoods of the threat implementation are over than the limit likelihood assigned by an expert.
Type of threats1
Ty pe
of th
re ats
2
Type of threats3
Ty pe
of th
re ats
2
Ty pe
of th
re ats
2
Critical threats
Type of threats1
Type of threats1
Type of threats3 Type of threats3
Risk acceptability line
Fig. 5. Example of risk map.
VI. CONCLUSION The article reports the energy sector as a critical
infrastructure and important part of national security. Considering, there is a tendency to introduce new information and telecommunication technologies into the energy sector, it is vital to ensure high-quality provision of cybersecurity. A risk-based approach is proposed to allow linking cybersecurity violations vulnerabilities, threats and damages. It is proposed to develop an intelligent system for risk assessment of cybersecurity violations from most feasible cyber threats with risk-based approach and the methodology of threat analysis and risk assessment applied.
REFERENCES [1] A. Kondratev, “The current trends in research of Critical Infrastructure
in foreign countries,” Foreign Military Review, no. 1, 2012, pp. 19-30. [2] L.V. Massel, N.I. Voropai, S.M. Senderov, A.G. Massel, “Cybersecurity
as one of the strategic threats to energy security,” Cybersecurity issues, no. 4 (17), 2016, pp. 2-10.
[3] B.G. Saneev, S.P. Filipov et al, “System researches of energy problems”, Novosibirsk: Nauka, p. 588, 2000.
[4] N.I. Pyatkova, V.I. Rabchuk, S.M. Senderov, M.B. Cheltsov, “Energy security of Russia: problems and solutions,” SB RAS Publishing House Novosibirsk, p. 211, 2011.
Unauthorized access Realizable Unrealizable
99.0 1.0
System state Normal Precrisis Crisis
0 100
0
Steal password Easy Average Difficult
100 0 0
Password policy Weak Medium Strong
100 0 0
Violation of energy facility function Normal function Precrisis function Crisis
14.5 31.5 54.0
Pre-emergency information transfer Successful transfer Information loss Information delay
15.1 29.9 55.0
Authorized licensed use limited to: Northcentral University. Downloaded on October 19,2021 at 13:52:31 UTC from IEEE Xplore. Restrictions apply.
[5] L.V. Massel, A.G. Massel, “Cyber security of Russia’s energy infrastructure as a component of national security,” 6th International Conference on Liberalization and Modernization of Power Systems, 2015, pp. 66-72.
[6] Requirements to ensure the information protection in automatic process control system of production and technological processes in critical facilities, potentially hazardous facilities, and also objects that present an increased danger to human life and the environment, [Online]. Available: http://fstec.ru/prikazy/864-prikaz-fstek-rossii-ot-14-marta- 2014-g-n-31
[7] The Security of the Critical Information Infrastructure of the Russian Federation, [Online]. Available: https://www.consultant.ru/law/hotdocs/48095.html
[8] L.V. Massel, “Modern information technologies in the Smart Grid as a threat to the cybersecurity of Russia's energy systems,” Information technology and security Kiev, no. 1 (3), 2013, pp. 56-65.
[9] T-REC-X.1205 – ITU-T: Overview of cybersecurity, [Online]. Available: https://www.itu.int/rec/T-REC-X.1205-200804-I
[10] ISO standard of Information technology. Security techniques. Guidelines for cybersecurity, ISO/IEC 27032:2012.
[11] V.V. Mohor, A.M. Bogdanov, A.S. Kilevoj, “Information Technology. Methods of security. Сybersecurity manual (ISO/IES 27032:2012),” Three-K Kiev, p. 129, 2013.
[12] T.N. Vorozhtsova, “Development of the ontology of cybersecurity in the energy sector,” International Conference “Cybersecurity-2013” Kiev, 2013, pp. 19-25.
[13] L.V. Massel, A.G. Massel, “The current state of cyber security in Russia's energy systems and the proposed activities for situation improving,” 6th International Conference on Liberalization and Modernization of Power Systems, 2015, pp. 165-170.
[14] V.F. Shanguin, “Protection of information in computer systems and networks,” DMK Moscow, p. 593, 2012.
[15] G.V. Grytsay, A.G. Timorin, “Safety of industrial systems in figures,” Positive Technologies, 2012, [Online]. Available: http://www.ptsecurity.ru/download/SCADA_analytics_russian.pdf
[16] A.G. Massel, “Methodology for threat analysis and risk assessment of information technology security violation of energy complexes,” 20th Baikal Russian Conference, vol. 3, 2015, pp. 186-195.
Authorized licensed use limited to: Northcentral University. Downloaded on October 19,2021 at 13:52:31 UTC from IEEE Xplore. Restrictions apply.
<< /ASCII85EncodePages false /AllowTransparency false /AutoPositionEPSFiles false /AutoRotatePages /None /Binding /Left /CalGrayProfile (Gray Gamma 2.2) /CalRGBProfile (sRGB IEC61966-2.1) /CalCMYKProfile (U.S. Web Coated \050SWOP\051 v2) /sRGBProfile (sRGB IEC61966-2.1) /CannotEmbedFontPolicy /Warning /CompatibilityLevel 1.4 /CompressObjects /Off /CompressPages true /ConvertImagesToIndexed true /PassThroughJPEGImages true /CreateJobTicket false /DefaultRenderingIntent /Default /DetectBlends true /DetectCurves 0.0000 /ColorConversionStrategy /LeaveColorUnchanged /DoThumbnails false /EmbedAllFonts true /EmbedOpenType false /ParseICCProfilesInComments true /EmbedJobOptions true /DSCReportingLevel 0 /EmitDSCWarnings false /EndPage -1 /ImageMemory 1048576 /LockDistillerParams true /MaxSubsetPct 100 /Optimize false /OPM 0 /ParseDSCComments false /ParseDSCCommentsForDocInfo false /PreserveCopyPage true /PreserveDICMYKValues true /PreserveEPSInfo false /PreserveFlatness true /PreserveHalftoneInfo true /PreserveOPIComments false /PreserveOverprintSettings true /StartPage 1 /SubsetFonts false /TransferFunctionInfo /Remove /UCRandBGInfo /Preserve /UsePrologue false /ColorSettingsFile () /AlwaysEmbed [ true /Arial-Black /Arial-BoldItalicMT /Arial-BoldMT /Arial-ItalicMT /ArialMT /ArialNarrow /ArialNarrow-Bold /ArialNarrow-BoldItalic /ArialNarrow-Italic /ArialUnicodeMS /BookAntiqua /BookAntiqua-Bold /BookAntiqua-BoldItalic /BookAntiqua-Italic /BookmanOldStyle /BookmanOldStyle-Bold /BookmanOldStyle-BoldItalic /BookmanOldStyle-Italic /BookshelfSymbolSeven /Century /CenturyGothic /CenturyGothic-Bold /CenturyGothic-BoldItalic /CenturyGothic-Italic /CenturySchoolbook /CenturySchoolbook-Bold /CenturySchoolbook-BoldItalic /CenturySchoolbook-Italic /ComicSansMS /ComicSansMS-Bold /CourierNewPS-BoldItalicMT /CourierNewPS-BoldMT /CourierNewPS-ItalicMT /CourierNewPSMT /EstrangeloEdessa /FranklinGothic-Medium /FranklinGothic-MediumItalic /Garamond /Garamond-Bold /Garamond-Italic /Gautami /Georgia /Georgia-Bold /Georgia-BoldItalic /Georgia-Italic /Haettenschweiler /Impact /Kartika /Latha /LetterGothicMT /LetterGothicMT-Bold /LetterGothicMT-BoldOblique /LetterGothicMT-Oblique /LucidaConsole /LucidaSans /LucidaSans-Demi /LucidaSans-DemiItalic /LucidaSans-Italic /LucidaSansUnicode /Mangal-Regular /MicrosoftSansSerif /MonotypeCorsiva /MSReferenceSansSerif /MSReferenceSpecialty /MVBoli /PalatinoLinotype-Bold /PalatinoLinotype-BoldItalic /PalatinoLinotype-Italic /PalatinoLinotype-Roman /Raavi /Shruti /Sylfaen /SymbolMT /Tahoma /Tahoma-Bold /TimesNewRomanMT-ExtraBold /TimesNewRomanPS-BoldItalicMT /TimesNewRomanPS-BoldMT /TimesNewRomanPS-ItalicMT /TimesNewRomanPSMT /Trebuchet-BoldItalic /TrebuchetMS /TrebuchetMS-Bold /TrebuchetMS-Italic /Tunga-Regular /Verdana /Verdana-Bold /Verdana-BoldItalic /Verdana-Italic /Vrinda /Webdings /Wingdings2 /Wingdings3 /Wingdings-Regular /ZWAdobeF ] /NeverEmbed [ true ] /AntiAliasColorImages false /CropColorImages true /ColorImageMinResolution 200 /ColorImageMinResolutionPolicy /OK /DownsampleColorImages true /ColorImageDownsampleType /Bicubic /ColorImageResolution 300 /ColorImageDepth -1 /ColorImageMinDownsampleDepth 1 /ColorImageDownsampleThreshold 1.50000 /EncodeColorImages true /ColorImageFilter /DCTEncode /AutoFilterColorImages false /ColorImageAutoFilterStrategy /JPEG /ColorACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /ColorImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /JPEG2000ColorACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000ColorImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasGrayImages false /CropGrayImages true /GrayImageMinResolution 200 /GrayImageMinResolutionPolicy /OK /DownsampleGrayImages true /GrayImageDownsampleType /Bicubic /GrayImageResolution 300 /GrayImageDepth -1 /GrayImageMinDownsampleDepth 2 /GrayImageDownsampleThreshold 1.50000 /EncodeGrayImages true /GrayImageFilter /DCTEncode /AutoFilterGrayImages false /GrayImageAutoFilterStrategy /JPEG /GrayACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /GrayImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /JPEG2000GrayACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000GrayImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasMonoImages false /CropMonoImages true /MonoImageMinResolution 400 /MonoImageMinResolutionPolicy /OK /DownsampleMonoImages true /MonoImageDownsampleType /Bicubic /MonoImageResolution 600 /MonoImageDepth -1 /MonoImageDownsampleThreshold 1.50000 /EncodeMonoImages true /MonoImageFilter /CCITTFaxEncode /MonoImageDict << /K -1 >> /AllowPSXObjects false /CheckCompliance [ /None ] /PDFX1aCheck false /PDFX3Check false /PDFXCompliantPDFOnly false /PDFXNoTrimBoxError true /PDFXTrimBoxToMediaBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXSetBleedBoxToMediaBox true /PDFXBleedBoxToTrimBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXOutputIntentProfile (None) /PDFXOutputConditionIdentifier () /PDFXOutputCondition () /PDFXRegistryName () /PDFXTrapped /False /CreateJDFFile false /Description << /CHS <FEFF4f7f75288fd94e9b8bbe5b9a521b5efa7684002000410064006f006200650020005000440046002065876863900275284e8e55464e1a65876863768467e5770b548c62535370300260a853ef4ee54f7f75280020004100630072006f0062006100740020548c002000410064006f00620065002000520065006100640065007200200035002e003000204ee553ca66f49ad87248672c676562535f00521b5efa768400200050004400460020658768633002> /CHT <FEFF4f7f752890194e9b8a2d7f6e5efa7acb7684002000410064006f006200650020005000440046002065874ef69069752865bc666e901a554652d965874ef6768467e5770b548c52175370300260a853ef4ee54f7f75280020004100630072006f0062006100740020548c002000410064006f00620065002000520065006100640065007200200035002e003000204ee553ca66f49ad87248672c4f86958b555f5df25efa7acb76840020005000440046002065874ef63002> /DAN <FEFF004200720075006700200069006e0064007300740069006c006c0069006e006700650072006e0065002000740069006c0020006100740020006f007000720065007400740065002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e007400650072002c0020006400650072002000650067006e006500720020007300690067002000740069006c00200064006500740061006c006a006500720065007400200073006b00e60072006d007600690073006e0069006e00670020006f00670020007500640073006b007200690076006e0069006e006700200061006600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020004400650020006f007000720065007400740065006400650020005000440046002d0064006f006b0075006d0065006e0074006500720020006b0061006e002000e50062006e00650073002000690020004100630072006f00620061007400200065006c006c006500720020004100630072006f006200610074002000520065006100640065007200200035002e00300020006f00670020006e0079006500720065002e> /DEU <FEFF00560065007200770065006e00640065006e0020005300690065002000640069006500730065002000450069006e007300740065006c006c0075006e00670065006e0020007a0075006d002000450072007300740065006c006c0065006e00200076006f006e002000410064006f006200650020005000440046002d0044006f006b0075006d0065006e00740065006e002c00200075006d002000650069006e00650020007a0075007600650072006c00e40073007300690067006500200041006e007a006500690067006500200075006e00640020004100750073006700610062006500200076006f006e00200047006500730063006800e40066007400730064006f006b0075006d0065006e00740065006e0020007a0075002000650072007a00690065006c0065006e002e00200044006900650020005000440046002d0044006f006b0075006d0065006e007400650020006b00f6006e006e0065006e0020006d006900740020004100630072006f00620061007400200075006e0064002000520065006100640065007200200035002e003000200075006e00640020006800f600680065007200200067006500f600660066006e00650074002000770065007200640065006e002e> /ESP <FEFF005500740069006c0069006300650020006500730074006100200063006f006e0066006900670075007200610063006900f3006e0020007000610072006100200063007200650061007200200064006f00630075006d0065006e0074006f0073002000640065002000410064006f00620065002000500044004600200061006400650063007500610064006f007300200070006100720061002000760069007300750061006c0069007a00610063006900f3006e0020006500200069006d0070007200650073006900f3006e00200064006500200063006f006e006600690061006e007a006100200064006500200064006f00630075006d0065006e0074006f007300200063006f006d00650072006300690061006c00650073002e002000530065002000700075006500640065006e00200061006200720069007200200064006f00630075006d0065006e0074006f00730020005000440046002000630072006500610064006f007300200063006f006e0020004100630072006f006200610074002c002000410064006f00620065002000520065006100640065007200200035002e003000200079002000760065007200730069006f006e0065007300200070006f00730074006500720069006f007200650073002e> /FRA <FEFF005500740069006c006900730065007a00200063006500730020006f007000740069006f006e00730020006100660069006e00200064006500200063007200e900650072002000640065007300200064006f00630075006d0065006e00740073002000410064006f006200650020005000440046002000700072006f00660065007300730069006f006e006e0065006c007300200066006900610062006c0065007300200070006f007500720020006c0061002000760069007300750061006c00690073006100740069006f006e0020006500740020006c00270069006d007000720065007300730069006f006e002e0020004c0065007300200064006f00630075006d0065006e00740073002000500044004600200063007200e900e90073002000700065007500760065006e0074002000ea0074007200650020006f007500760065007200740073002000640061006e00730020004100630072006f006200610074002c002000610069006e00730069002000710075002700410064006f00620065002000520065006100640065007200200035002e0030002000650074002000760065007200730069006f006e007300200075006c007400e90072006900650075007200650073002e> /ITA (Utilizzare queste impostazioni per creare documenti Adobe PDF adatti per visualizzare e stampare documenti aziendali in modo affidabile. I documenti PDF creati possono essere aperti con Acrobat e Adobe Reader 5.0 e versioni successive.) /JPN <FEFF30d330b830cd30b9658766f8306e8868793a304a3088307353705237306b90693057305f002000410064006f0062006500200050004400460020658766f8306e4f5c6210306b4f7f75283057307e305930023053306e8a2d5b9a30674f5c62103055308c305f0020005000440046002030d530a130a430eb306f3001004100630072006f0062006100740020304a30883073002000410064006f00620065002000520065006100640065007200200035002e003000204ee5964d3067958b304f30533068304c3067304d307e305930023053306e8a2d5b9a3067306f30d530a930f330c8306e57cb30818fbc307f3092884c3044307e30593002> /KOR <FEFFc7740020c124c815c7440020c0acc6a9d558c5ec0020be44c988b2c8c2a40020bb38c11cb97c0020c548c815c801c73cb85c0020bcf4ace00020c778c1c4d558b2940020b3700020ac00c7a50020c801d569d55c002000410064006f0062006500200050004400460020bb38c11cb97c0020c791c131d569b2c8b2e4002e0020c774b807ac8c0020c791c131b41c00200050004400460020bb38c11cb2940020004100630072006f0062006100740020bc0f002000410064006f00620065002000520065006100640065007200200035002e00300020c774c0c1c5d0c11c0020c5f40020c2180020c788c2b5b2c8b2e4002e> /NLD (Gebruik deze instellingen om Adobe PDF-documenten te maken waarmee zakelijke documenten betrouwbaar kunnen worden weergegeven en afgedrukt. De gemaakte PDF-documenten kunnen worden geopend met Acrobat en Adobe Reader 5.0 en hoger.) /NOR <FEFF004200720075006b00200064006900730073006500200069006e006e007300740069006c006c0069006e00670065006e0065002000740069006c002000e50020006f0070007000720065007400740065002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e00740065007200200073006f006d002000650072002000650067006e0065007400200066006f00720020007000e5006c006900740065006c006900670020007600690073006e0069006e00670020006f00670020007500740073006b007200690066007400200061007600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020005000440046002d0064006f006b0075006d0065006e00740065006e00650020006b0061006e002000e50070006e00650073002000690020004100630072006f00620061007400200065006c006c00650072002000410064006f00620065002000520065006100640065007200200035002e003000200065006c006c00650072002e> /PTB <FEFF005500740069006c0069007a006500200065007300730061007300200063006f006e00660069006700750072006100e700f50065007300200064006500200066006f0072006d00610020006100200063007200690061007200200064006f00630075006d0065006e0074006f0073002000410064006f00620065002000500044004600200061006400650071007500610064006f00730020007000610072006100200061002000760069007300750061006c0069007a006100e700e3006f002000650020006100200069006d0070007200650073007300e3006f00200063006f006e0066006900e1007600650069007300200064006500200064006f00630075006d0065006e0074006f007300200063006f006d0065007200630069006100690073002e0020004f007300200064006f00630075006d0065006e0074006f00730020005000440046002000630072006900610064006f007300200070006f00640065006d0020007300650072002000610062006500720074006f007300200063006f006d0020006f0020004100630072006f006200610074002000650020006f002000410064006f00620065002000520065006100640065007200200035002e0030002000650020007600650072007300f50065007300200070006f00730074006500720069006f007200650073002e> /SUO <FEFF004b00e40079007400e40020006e00e40069007400e4002000610073006500740075006b007300690061002c0020006b0075006e0020006c0075006f0074002000410064006f0062006500200050004400460020002d0064006f006b0075006d0065006e007400740065006a0061002c0020006a006f0074006b006100200073006f0070006900760061007400200079007200690074007900730061007300690061006b00690072006a006f006a0065006e0020006c0075006f00740065007400740061007600610061006e0020006e00e400790074007400e4006d0069007300650065006e0020006a0061002000740075006c006f007300740061006d0069007300650065006e002e0020004c0075006f0064007500740020005000440046002d0064006f006b0075006d0065006e00740069007400200076006f0069006400610061006e0020006100760061007400610020004100630072006f0062006100740069006c006c00610020006a0061002000410064006f00620065002000520065006100640065007200200035002e0030003a006c006c00610020006a006100200075007500640065006d006d0069006c006c0061002e> /SVE <FEFF0041006e007600e4006e00640020006400650020006800e4007200200069006e0073007400e4006c006c006e0069006e006700610072006e00610020006f006d002000640075002000760069006c006c00200073006b006100700061002000410064006f006200650020005000440046002d0064006f006b0075006d0065006e007400200073006f006d00200070006100730073006100720020006600f60072002000740069006c006c006600f60072006c00690074006c006900670020007600690073006e0069006e00670020006f006300680020007500740073006b007200690066007400650072002000610076002000610066006600e4007200730064006f006b0075006d0065006e0074002e002000200053006b006100700061006400650020005000440046002d0064006f006b0075006d0065006e00740020006b0061006e002000f600700070006e00610073002000690020004100630072006f0062006100740020006f00630068002000410064006f00620065002000520065006100640065007200200035002e00300020006f00630068002000730065006e006100720065002e> /ENU (Use these settings to create PDFs that match the "Required" settings for PDF Specification 4.01) >> >> setdistillerparams << /HWResolution [600 600] /PageSize [612.000 792.000] >> setpagedevice
-
- 2018-10-03T04:32:56-0400
- Preflight Ticket Signature