Industrial virus revives power grid hacking fears

Safety of power plants and distribution in question

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

Last week's disclosure of a sophisticated malware program targeting control system software from Siemens AG has renewed long-standing concerns about whether the US power grid can withstand targeted cyberattacks. The malware program, called Stuxnet, is designed to exploit a Windows Zero Day flaw to find and steal industrial data from Supervisory Control And Data Acquisition (SCADA) systems running Siemens' Simatic WinCC or PCS 7 software.

Stuxnet is the first publicly-known malicious software program written specifically to exploit vulnerabilities in a SCADA system. "It could be a proof-of-concept to show control systems can be attacked" in a deliberate fashion, said Eric Knapp, director of critical infrastructure markets at NitroSecurity, a security vendor.

SCADA systems are used to control critical equipment at power companies, manufacturing facilities, water treatment plants and nuclear power operations. Typically, the systems run on segmented networks that are not directly connected to the Internet, making them external access difficult. But analysts for long have warned that SCADA systems, especially older ones, have several exploitable vulnerabilities.

US power grid hacked by cyber-spies | Expert highlights power grid vulnerability | Hackers built Stuxnet industrial worm more than a year ago

One example was demonstrated by researchers at the Idaho National Laboratory three years ago. In a dramatic experiment, codenamed Aurora, researchers there demonstrated how a hacker could simply use a dial-up modem to exploit a SCADA vulnerability that could physically destroy a massive power turbine.

The potential for such attacks has risen sharply in recent years as many SCADA systems, including those at some very large public power companies, are increasingly integrated with networks with direct links to the Internet. In a high-profile story last year, theWall Street Journal reported that cyberspies in Russia, China and other countries had already taken advantage of such vulnerabilities to deeply penetrate the US electrical grid.

The emergence of threats like Stuxnet drives home the need for more federal oversight of cybersecurity matters in the utilities sector, said Joseph Weiss, managing partner at Applied Control Solutions.

So far there have been at least 170 known cyber-related outages in the US, including three that caused widespread regional outages, Weiss said. It's hard to know with certainty whether any of the 170 outages stemmed from a targeted cyberattack because of the relative lack of forensics-gathering capabilities in the utility business, he added.

"There has been almost minimal progress on securing control systems," said Weiss, author of the book, Protecting Industrial Control Systems from Electronic Threats, that was published earlier this year. He said progress is slowed largely due to a lack of understanding of the specific challenges associated with securing industrial control systems against cyber-threats, he said.

Currently, all bulk power system owners and operators are required to comply with reliability and security standards mandated by the North American Electric Reliability Corp (NERC), an independent regulatory organisation. NERC's mandated controls are based on a risk management framework created by the federal government's National Institute of Standards and Technology (NIST).

That framework, Weiss said, that is designed more for commercial IT systems than for industrial control systems. As a result, many of the prescribed controls are inadequate and do not cover all SCADA systems, he said.

NERC's requirements, for instance, apply only to cyberassets that use routable protocols or are dial-up accessible. The rules do not address the large number of vulnerable SCADA systems that use non-routable protocols, Weiss said. Importantly, NERC's rules do not apply to power distributors or to operators of emerging smart-grids, he added.

"Hacking a control system does not take rocket science," Weiss said. "Protecting one does."


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Related Security news

Black hole discovery could boost quantum computers

String theory of gravity connected to entanglement

Onapsis to launch ERP vulnerability testing suite

The software searches for vulnerabilities, looks for compliance problems and creates reports

Women are better at protecting corporate secrets

Defcon social engineering contest finds most people give up secrets to strangers

Facebook introduces new security measures to kick out spammers

Users will be able to use IP info to confirm if their account has been hacked in to and reset passwords



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *