Cyber Attack on Electric Grids Can be Devastating:National Research CouncilAdded 30th Nov 2012
The U.S. is in urgent need of a nationwide strategy to protect its highly vulnerable electric grid from succumbing to a cyberattack that could cause far more damage than Hurricane Sandy, a recent report said.
Terrorists who gained access to any one of a number of key facilities, either through Internet-delivered malware designed to destroy control systems or through a saboteur on the inside, could black out large regions of the nation for weeks or months, the report from the National Research Council said.
Damage from such an attack would be many billions of dollars more than the destruction caused by Sandy last month on the East Coast.
"Considering that a systematically designed and executed terrorist attack could cause disruptions even more widespread and of longer duration, it is no stretch of the imagination to think that such attacks could produce damage costing hundreds of billions of dollars," M. Granger Morgan, head of the engineering and public policy department at Carnegie Mellon University, said in a statement. Morgan was chairman of the committee that wrote the report released this month.
The grid's acute vulnerability comes from being spread across hundreds of miles and having many unguarded key facilities. In addition, federal legislation in the mid-1990s that opened the door to more competitors in the power market has stressed the nation's bulk high-voltage system, leaving it at risk to multiple failures following an attack.Ã'Â
The grid is also riddled with important pieces of equipment that are decades old and lacks advanced technology for sensing and control that could limit outages. An example is how Long Island Power Authority struggled to restore electricity after Sandy, which caused more than $70 billion in damages. News media reported that the utility was hampered by the use of decades-old mainframe computers.
"As utilities struggle to make a profit, their last concern is updating antiquated systems and investing in security," said Darren Hayes, a professor at Pace University and an expert in computer forensics and security.Ã'Â
Another problem lies with utilities over the years joining their IT operations in order to cut costs, Hayes said.
"Security has not been a priority but should be now that many utilities have centralized their IT operations to reduce costs," Hayes said in an email. "This centralization has meant that utilities networked together can be brought down together in a catastrophic manner."Ã'Â
Fear of a cyberattack on the nation's critical infrastructure was heightened following the discovery of Stuxnet, sophisticated malware that damaged Iran's nuclear facilities in 2010. Iran has vowed to take "pre-emptive" strikes against the countries it believes are responsible. The New York Times reported that the U.S. and Israel developed Stuxnet together.
[See related: The changing security battlefield]
The report recommends ways to protect the nation's power delivery system, starting with money. Funding for research is currently much smaller than needed, the study said.
Besides money, the report recommends developing, manufacturing and stockpiling "universal recovery transformers" that could temporarily replace downed high-voltage transformers, which are often custom built outside the U.S. and can take months, or even years, to replace. Recovery transformers would be less efficient, but they could drastically reduce delays in restoring power. The U.S. Department of Homeland Security (DHS) has recently started working with the U.S. power industry on a program to develop and test recovery transformers.
Other points of weakness include communication, sensor and control systems that are open to cyberattacks through an Internet connection or by sabotage from within. The best solution is to remove connections with the Internet, the report said. In those cases where that isn't possible, then state-of-art technical and managerial security systems should be in place, including systems that monitor for operator error or sabotage.
The threat of attack from the inside was made clear in August when a virus named Shamoon erased the data on three quarters of the corporate PCs of state-owned oil company Saudi Aramco. An insider is believed to have infected the computers through a USB memory stick inserted into a PC.Ã'Â
Finally, the report recommends that DHS and the Energy Department initiate and fund assessment programs across cities, counties and states. These programs should act as models for local and regional planning efforts that have a goal of eliminating vulnerabilities.
More collaboration and sharing of information between government agencies and private industry are also needed. But for that to happen, the federal government will have to address public policy and legal barriers, the report said.
That last condition may be difficult given the opposition to proposed legislation to mandate information sharing. This month, the Cyber Security Act of 2012 failed to pass the Senate, largely due to opposition from businesses and privacy advocates.
President Obama, who supported the bill, is expected to issue an executive order implementing those elements that do not require congressional approval.
Read more about critical infrastructure in CSOonline's Critical Infrastructure section.
A phenomenal idea that reveals the damage traditional toys have had on our children and facilities how we can encourage our girls to take up careers in science, technology, engineering and mathematics.
A new commercial tool designed to allow cybercriminals to easily transform legitimate Android applications into malicious software has hit the underground market, paving the way for cheap and easy development of sophisticated Android malware.
Malware often does strange things, but this one -- which looked like Skype installed on a corporate domain controller -- was most "peculiar," says Jim Butterworth, a security expert at ManTech International, whose security subsidiary HBGary recently found the custom-designed remote-access Trojan on a customer's network.
Microsoft will deliver five security updates to customers next week, two tagged as "critical," including one that will quash the open vulnerability in Internet Explorer that hackers have been exploiting since January.
Having lots of Wi-Fi networks packed into a condominium or apartment building can hurt everyone's wireless performance, but Stanford University researchers say they've found a way to turn crowding into an advantage.
Organizations can now add machine-generated data to their palate of information sources that can be aggregated and analyzed, thanks to a new connector jointly developed by Tableau Software, a provider of business intelligence software, and Splunk, which sells a log-file search engine.
The Tor network is in danger of being swamped by criminals abusing its anonymity to hide an underworld of parasitic botnets, malicious command and control and ‘darknet' markets, according to research from Kaspersky Lab.
Rogue adverts that use social engineering to persuade users to install malware have displaced porn as the leading method of attack on mobile devices, according to a report from security firm Blue Coat.
A convoluted web of applications is stunting the digital transformation of the world's biggest international organisations.
Goldman Sachs has been doing SDNs for a long time. It just wasn't called SDNs when the investment giant invested in network programmability. It was just a bunch of APIs, software development kits and other code used to cobble together a large number of various specialized networks – trading, investment banking and the like -- across the globe.
Bitcoin's biggest mystery has finally been solved: The crypto-currency's creator, Satoshi Nakamoto, has finally been unmasked. Well, maybe.
When it comes to mobile devices, it's well known that malware writers like to target Android. But a threat report published today by security firm F-Secure puts in perspective why Android malware attacks often flop and why Android itself is no pushover.
Shipments of new PCs, most of them equipped with Microsoft Windows, will decline more in 2014 than thought a few months ago, according to IDC.
SAN JOSE -- In an effort simplify enterprise customer procurements, Cisco is implementing a licensing model for data center, WAN and access product purchases.
Challenging Microsoft's Windows Azure on its own turf, Red Hat is ramping up services that would offer Microsoft .NET and SQL Server capabilities on its OpenShift platform as a service (PaaS).