Cyber Attack on Electric Grids Can be Devastating:National Research CouncilAdded 30th Nov 2012
The U.S. is in urgent need of a nationwide strategy to protect its highly vulnerable electric grid from succumbing to a cyberattack that could cause far more damage than Hurricane Sandy, a recent report said.
Terrorists who gained access to any one of a number of key facilities, either through Internet-delivered malware designed to destroy control systems or through a saboteur on the inside, could black out large regions of the nation for weeks or months, the report from the National Research Council said.
Damage from such an attack would be many billions of dollars more than the destruction caused by Sandy last month on the East Coast.
"Considering that a systematically designed and executed terrorist attack could cause disruptions even more widespread and of longer duration, it is no stretch of the imagination to think that such attacks could produce damage costing hundreds of billions of dollars," M. Granger Morgan, head of the engineering and public policy department at Carnegie Mellon University, said in a statement. Morgan was chairman of the committee that wrote the report released this month.
The grid's acute vulnerability comes from being spread across hundreds of miles and having many unguarded key facilities. In addition, federal legislation in the mid-1990s that opened the door to more competitors in the power market has stressed the nation's bulk high-voltage system, leaving it at risk to multiple failures following an attack.Ã'Â
The grid is also riddled with important pieces of equipment that are decades old and lacks advanced technology for sensing and control that could limit outages. An example is how Long Island Power Authority struggled to restore electricity after Sandy, which caused more than $70 billion in damages. News media reported that the utility was hampered by the use of decades-old mainframe computers.
"As utilities struggle to make a profit, their last concern is updating antiquated systems and investing in security," said Darren Hayes, a professor at Pace University and an expert in computer forensics and security.Ã'Â
Another problem lies with utilities over the years joining their IT operations in order to cut costs, Hayes said.
"Security has not been a priority but should be now that many utilities have centralized their IT operations to reduce costs," Hayes said in an email. "This centralization has meant that utilities networked together can be brought down together in a catastrophic manner."Ã'Â
Fear of a cyberattack on the nation's critical infrastructure was heightened following the discovery of Stuxnet, sophisticated malware that damaged Iran's nuclear facilities in 2010. Iran has vowed to take "pre-emptive" strikes against the countries it believes are responsible. The New York Times reported that the U.S. and Israel developed Stuxnet together.
[See related: The changing security battlefield]
The report recommends ways to protect the nation's power delivery system, starting with money. Funding for research is currently much smaller than needed, the study said.
Besides money, the report recommends developing, manufacturing and stockpiling "universal recovery transformers" that could temporarily replace downed high-voltage transformers, which are often custom built outside the U.S. and can take months, or even years, to replace. Recovery transformers would be less efficient, but they could drastically reduce delays in restoring power. The U.S. Department of Homeland Security (DHS) has recently started working with the U.S. power industry on a program to develop and test recovery transformers.
Other points of weakness include communication, sensor and control systems that are open to cyberattacks through an Internet connection or by sabotage from within. The best solution is to remove connections with the Internet, the report said. In those cases where that isn't possible, then state-of-art technical and managerial security systems should be in place, including systems that monitor for operator error or sabotage.
The threat of attack from the inside was made clear in August when a virus named Shamoon erased the data on three quarters of the corporate PCs of state-owned oil company Saudi Aramco. An insider is believed to have infected the computers through a USB memory stick inserted into a PC.Ã'Â
Finally, the report recommends that DHS and the Energy Department initiate and fund assessment programs across cities, counties and states. These programs should act as models for local and regional planning efforts that have a goal of eliminating vulnerabilities.
More collaboration and sharing of information between government agencies and private industry are also needed. But for that to happen, the federal government will have to address public policy and legal barriers, the report said.
That last condition may be difficult given the opposition to proposed legislation to mandate information sharing. This month, the Cyber Security Act of 2012 failed to pass the Senate, largely due to opposition from businesses and privacy advocates.
President Obama, who supported the bill, is expected to issue an executive order implementing those elements that do not require congressional approval.
Read more about critical infrastructure in CSOonline's Critical Infrastructure section.
Next year will see demonstrable evidence of the Internet of Things, real-time communications on the Web, and SDN-enabled platforms with killer applications for them.
A Stratecast survey has found that more than 80 per cent of employees admit to using unauthorised Software-as-a-Service (SaaS) applications during work.
Microsoft moved to reassure business and government customers worldwide that it is committed to informing them of legal orders related to their data, and will fight in court any 'gag order' that prevents it from sharing such information with customers.
Distributed denial-of-service attacks against financial firms and other industries have been mounting, so today the Cloud Security Alliance (CSA) announced it is establishing the Anti-Bot Working Group to help fight this threat.
The majority of today's CIOs see value in mobilizing enterprise applications and in deploying mobile-related innovations such as GPS features, location-based services (LBS), mobile payments and QR codes. Many also say their organizations are already somehow increasing revenue and developing new revenue streams directly related to mobile. But nearly as many CIOs also see the cost of deploying new innovations as prohibitive and complexity as a major concern, according to a new survey commissioned by Mobile Helix, a mobile security vendor.
The price of bitcoins may be soaring, but China isn't too thrilled with the virtual currency. On Thursday, the nation moved to regulate use of bitcoins, stating that its financial institutions could not deal in the virtual currency.
New attack campaigns have infected point-of-sale (PoS) systems around the world with sophisticated malware designed to steal payment card and transaction data.
Ruby on Rails users are advised to upgrade to newly released versions of the Web development framework that contain important security fixes, according to the Rails development team.
Mobile technology is increasing the complexity, usage and costs of mainframe applications, according to Compuware research.
Asian markets are ready for advanced mobile technology and fast connectivity, according to new insights released by Telenor Group in Asia.
Large smartphones with 5-in. or larger displays -- often called phablets -- are eating into sales of smaller tablets with screens in the 7-in. range.
Analysts have predicted that the Internet of Things will continue to grow in 2014, and more enterprises will start to realise the potential benefits.
When end users circumvent the IT department and start using software-as-a-service (SaaS) applications without permission, the IT pros complain about the plague they call "shadow IT." But it would seem the professionals are also operating in the shadows, according to a survey out today.
Once upon a time, not so long ago, the IT admin chose exactly what hardware and software would be used by employees. Recent trends like the consumerization of IT and BYOD (bring your own device) have shifted the balance of power, but IT still has to maintain some degree of control over the applications used and where sensitive data is stored. Many users just download apps or start using unsanctioned services, though, and introduce unnceccesary security risks through "shadow IT."
Once heavily reliant on the Chinese market, Lenovo is now looking to make acquisitions as it tries to expand its growing enterprise business to other countries.