There's no shortage of cyber-attack stories in the news, but as you read them you tend to wonder how serious the problem really is. Maybe this is because no group of hackers has been able to do something big and dramatic, like say triggering a cascading power outage that knocked San Francisco off the power grid for a full day.
But just because it hasn't happened yet is no guarantee that it can't or won't happen. I spoke with Marty Meyer, president and CEO of Corero Network Security, who said utilities, if anything, are more vulnerable than entities that have already been attacked.
"We're on the first step of a twelve-step program to admitting we have a potential problem with cybersecurity," Meyer said.
Cyber-attacks on utilities are up 52 percent, according to the Department of Homeland Security's cybersecurity protection arm.
An attack like a distributed denial of service attack (or DDOS attack) can flood a computer network with a large, sudden volume of attack traffic until it is overwhelmed and shuts down, he said. The systems that support power grids weren't designed to handle this level of attack traffic, and a DDOS attack is relatively unsophisticated — easily within the capability of a small group of hackers, such as Anonymous.
"There was an attack reported on an unnamed U.S. utility, and it was one of these DDOS attacks. The impact was that people could not pay their bills online. It wasn't people losing their electricity and freezing in their homes, but it was still a successful attack that denied service to people," he said.
Cyber-attacks can range in severity from "this is annoying" to something more malicious, he said. Furthermore, a relatively simple DDOS attack could be used as a diversionary tactic to distract from a more sophisticated network intrusion.
"So while I would say there's been no advertized take-down of a major utility where people lost actual services, but there certainly could be concerned from the utilities to protect themselves now instead of waiting around," he said.
Simple firewalls by themselves are not a prudent strategy to prevent malicious attacks, he said. Geoblocking (also known as geofiltering) is an extra layer of protection that works by cutting off network access to computers from IP addresses that are affiliated with a geographic area or country that you don't want to allow access to.
Another way of launching a malicious attack is to "spoof" an IP address, which lets a malicious computer disguise itself as coming from a trusted address. Utilities can upgrade their systems to unmask such attacks, he said.
"There are technologies that can make sure that addresses are trusted," he said. "Utilities need to specifically look at technologies that restrict access in terms of geography or known problem locations to ensure that the network connection that's coming in is a real connection and not a spoofed connection."
My thanks to Marty Meyer for his help in putting this post together. His company, Corero Network Security, is based in Hudson, Massachusetts.
Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts
Thursday, March 21, 2013
Thursday, June 7, 2012
Talking Congress, security and generation at EEI
By Jennifer Van Burkleo,
Associate Editor
At the EEI Annual Convention this week, I caught up with former EEI Chairman Tom Farrell and Lew Hay, the new EEI chairman and CEO of NextEra Energy, to talk about what conventioneers were talking about in Orlando this year. I was glad to be inside, given how hot and rainy it was most of the time.
At the convention, held at the Marriott, my editor in chief Teresa Hansen and I were able to meet with both the incoming and outgoing chairmen. Hay said that although he is the incoming chairman, he will work closely with Farrell on industry priorities like cyber security, distributed generation, workforce issues and the direction of EEI.
Utilities compete in many ways, but they also pull together and work together for mutual advantage, Hay said. He also credited Farrell for helping build a consensus among EEI's member utilities.
As we sat down, the two men tackled the topic of cyber security. Hay and Farrell agreed that EEI would support a legislative solution in Congress to help private industry and the government share information on cyber threats. Such a bill is making its way through Congress, having earned approval in the House of Representatives in April and now awaiting a vote in the Senate.
The bill was introduced by Rep. Mike Rogers, a Michigan Republican, who heads the House Intelligence Committee. The Obama administration threatened to veto the bill, claiming that the country's critical infrastructure would not be adequately protected by the legislation. The administration also expressed doubts about the level of protection the bill offered for consumer privacy.
"I think my company's system gets attacked more than a million times a day, but most aren't robust and we detect them," said Hay as he ate a giant cookie, provided at the meeting.
Hay and Farrell agreed that the government and Congress should let utilities share information to better protect their customers.
"The government clearly has information (about threats) that they aren't sharing with us," Hay said. "It will take an act of Congress to work these issues out."
When we asked about the future of distributed generation, Farrell stated that it will grow in a variety of forms, many that are still unknown. Utilities should be sure that they have in place a fair way to distribute the cost of upgrading the distribution grid to accommodate distributed generation now rather than when it might be too late in the future, Farrell said.
EEI's outgoing president Thomas Kuhn, who stepped into our meeting later on, used Germany's current cost problem as an example of why the U.S. should prepare for the future now. Because Germany waited too long to deal with the issue of electric costs, utility prices are now double those seen in the U.S.
According to Hay, utilities need to communicate the value of electricity to their customers. They need to find a way to communicate what is driving utility bills.
As technology changes, so do employees and their skills. Companies need to update their training materials by including more detail to what the position is, Hay said. Utilities shouldn't assume that potential employees know what the position description is.
Hay also suggested that companies look toward military personnel and veterans to fill their open positions, adding that troops are much better trained than they were 20 years ago.
Farrell has been chairman, president and CEO of Dominion since 2007. Hay is CEO and chairman of NextEra Energy. Hay's last day as CEO will be July 1, 2012, where he will then take over as executive chairman of NextEra through 2013.
Associate Editor
At the EEI Annual Convention this week, I caught up with former EEI Chairman Tom Farrell and Lew Hay, the new EEI chairman and CEO of NextEra Energy, to talk about what conventioneers were talking about in Orlando this year. I was glad to be inside, given how hot and rainy it was most of the time.
At the convention, held at the Marriott, my editor in chief Teresa Hansen and I were able to meet with both the incoming and outgoing chairmen. Hay said that although he is the incoming chairman, he will work closely with Farrell on industry priorities like cyber security, distributed generation, workforce issues and the direction of EEI.
Utilities compete in many ways, but they also pull together and work together for mutual advantage, Hay said. He also credited Farrell for helping build a consensus among EEI's member utilities.
As we sat down, the two men tackled the topic of cyber security. Hay and Farrell agreed that EEI would support a legislative solution in Congress to help private industry and the government share information on cyber threats. Such a bill is making its way through Congress, having earned approval in the House of Representatives in April and now awaiting a vote in the Senate.
The bill was introduced by Rep. Mike Rogers, a Michigan Republican, who heads the House Intelligence Committee. The Obama administration threatened to veto the bill, claiming that the country's critical infrastructure would not be adequately protected by the legislation. The administration also expressed doubts about the level of protection the bill offered for consumer privacy.
"I think my company's system gets attacked more than a million times a day, but most aren't robust and we detect them," said Hay as he ate a giant cookie, provided at the meeting.
Hay and Farrell agreed that the government and Congress should let utilities share information to better protect their customers.
"The government clearly has information (about threats) that they aren't sharing with us," Hay said. "It will take an act of Congress to work these issues out."
When we asked about the future of distributed generation, Farrell stated that it will grow in a variety of forms, many that are still unknown. Utilities should be sure that they have in place a fair way to distribute the cost of upgrading the distribution grid to accommodate distributed generation now rather than when it might be too late in the future, Farrell said.
EEI's outgoing president Thomas Kuhn, who stepped into our meeting later on, used Germany's current cost problem as an example of why the U.S. should prepare for the future now. Because Germany waited too long to deal with the issue of electric costs, utility prices are now double those seen in the U.S.
According to Hay, utilities need to communicate the value of electricity to their customers. They need to find a way to communicate what is driving utility bills.
As technology changes, so do employees and their skills. Companies need to update their training materials by including more detail to what the position is, Hay said. Utilities shouldn't assume that potential employees know what the position description is.
Hay also suggested that companies look toward military personnel and veterans to fill their open positions, adding that troops are much better trained than they were 20 years ago.
Farrell has been chairman, president and CEO of Dominion since 2007. Hay is CEO and chairman of NextEra Energy. Hay's last day as CEO will be July 1, 2012, where he will then take over as executive chairman of NextEra through 2013.
Thursday, August 5, 2010
To worry or not to worry about icky worms
Viruses, worms and Trojans are an unfortunate part of the computerized present—albeit not a pleasant part, which Siemens has been finding out all too personally this summer. But, should we really be all that worried about our smart grid’s cyber security, or are we panicking ourselves unnecessarily?
The Siemens thing: In June, the company discovered it was the specific and directed target of some nasty malware which uses a Microsoft Windows loophole dealing with shortcut files to latch on and download secure information from supervisory control and data acquisition (SCADA) systems using a leaked Siemens password. The sticking point, though, is that the worm is rather low-tech (relatively) in its delivery: The computer has to be physically connected to an infected USB stick (although there is also a possibility of it spreading via CDs and file-sharing). If someone views an item from that infected stick, the worm sneaks on out into the system, searching out information to copy.
Named the Stuxnet worm, it seems to be hitting Middle Eastern and Asian countries the most. (Symantec Corp. revealed that over half of the systems impacted were specifically in Iran, but Indonesia and India have also seen a large set of Stuxnet issues, according to one IDG News Service report.)
The worm itself was discovered by an antivirus company in Belarus named VirusBlokAda, which has labeled the worm “very dangerous” and noted that it could lead to a “virus epidemic” on the company website. But, how dangerous is it if I need to connect an infected part and then open something up by hand to create this issue? That doesn’t really sound like a system issue as much as a personnel issue, really.
Right now, according to Siemens spokespersons, the Stuxnet worm has not yet impacted any power generation SCADA system nor any T&D SCADA system.
“To our knowledge, only two industrial systems were affected by this [malware],” a Siemens spokesperson told me, and the fact that power-system SCADA networks weren’t impacted reveals the hearty backbone of those systems, according to Scott Gosnell, CMO with Tatsoft, a developer of software tools, products and services.
“This particular attack shows the strengths of current security technologies and protocols—the worm didn’t come in through a network vulnerability,” he noted.
Industry insiders warn, however, that utilities should not assume they are out of the woods just yet, even if the Stuxnet worm has avoided corrupting power systems this round. It is still spreading, and it won’t be the last threat by far. And, of course, there are other issues recently brought up around smart grid security, including a recent Pike Research report that points to smart meters as “the weakest link in the smart grid security chain” filled to the brim with juicy data that “could be successfully eavesdropped.” (Pike report: Smart Meter Security. Easy to find on their website pikeresearch.com.)
So, what’s a smart grid planner to do? Can he think ahead to the next malware? Can he plug all the security holes? Well, maybe he can’t do it all, but it seems that it is expected that he give it the ol’ college try, really.
“This is not the time to stick your head in the sand and say ‘it can’t happen here,’” said GarrettCom President Frank Madren. “Cyber attacks on industrial control system are happening now and will probably increase.” Madren suggested best practices to prevent damange include a multi-pronged approach of good industry standards, technology and personal, targeted recommendations to fill in holes in a utility’s security program. It’s all about repetition. Never assume that all the holes have been covered. Always go back and check again and again. (In this way, malware is a lot like a zombie horde---always trying to get in a forgotten opening, an unchecked back door, an open window.)
Tatsoft’s Gosnell would add man to Madren’s best practices equation---keep him tech savvy and on top of things, ready for the onslaught.
“This [attack] also demonstrates that operational risks are an inherent part of running these systems,” Gosnell added. “One of your biggest potential problems comes from poor processes and policies at the human level. Maintaining good security hygiene at the human and social level complements good technical hygiene.”
Madren noted that North American Electric Reliability Corporation’s Critical Infrastructure Protection (NERC CIP) regulations help protect power utility substations from a variety of security issues, including worms like this one. They are incredibly comprehensive and offer a great amount of defense.
“However, no system is completely immune from creative new incursions. Constant vigilance is required,” Madren said.
So, worry? Yes. Panic? Not helpful. Just keep one eye open … and try not to fall asleep and unconsciously let in those zombie malware hordes.
The Siemens thing: In June, the company discovered it was the specific and directed target of some nasty malware which uses a Microsoft Windows loophole dealing with shortcut files to latch on and download secure information from supervisory control and data acquisition (SCADA) systems using a leaked Siemens password. The sticking point, though, is that the worm is rather low-tech (relatively) in its delivery: The computer has to be physically connected to an infected USB stick (although there is also a possibility of it spreading via CDs and file-sharing). If someone views an item from that infected stick, the worm sneaks on out into the system, searching out information to copy.
Named the Stuxnet worm, it seems to be hitting Middle Eastern and Asian countries the most. (Symantec Corp. revealed that over half of the systems impacted were specifically in Iran, but Indonesia and India have also seen a large set of Stuxnet issues, according to one IDG News Service report.)
The worm itself was discovered by an antivirus company in Belarus named VirusBlokAda, which has labeled the worm “very dangerous” and noted that it could lead to a “virus epidemic” on the company website. But, how dangerous is it if I need to connect an infected part and then open something up by hand to create this issue? That doesn’t really sound like a system issue as much as a personnel issue, really.
Right now, according to Siemens spokespersons, the Stuxnet worm has not yet impacted any power generation SCADA system nor any T&D SCADA system.
“To our knowledge, only two industrial systems were affected by this [malware],” a Siemens spokesperson told me, and the fact that power-system SCADA networks weren’t impacted reveals the hearty backbone of those systems, according to Scott Gosnell, CMO with Tatsoft, a developer of software tools, products and services.
“This particular attack shows the strengths of current security technologies and protocols—the worm didn’t come in through a network vulnerability,” he noted.
Industry insiders warn, however, that utilities should not assume they are out of the woods just yet, even if the Stuxnet worm has avoided corrupting power systems this round. It is still spreading, and it won’t be the last threat by far. And, of course, there are other issues recently brought up around smart grid security, including a recent Pike Research report that points to smart meters as “the weakest link in the smart grid security chain” filled to the brim with juicy data that “could be successfully eavesdropped.” (Pike report: Smart Meter Security. Easy to find on their website pikeresearch.com.)
So, what’s a smart grid planner to do? Can he think ahead to the next malware? Can he plug all the security holes? Well, maybe he can’t do it all, but it seems that it is expected that he give it the ol’ college try, really.
“This is not the time to stick your head in the sand and say ‘it can’t happen here,’” said GarrettCom President Frank Madren. “Cyber attacks on industrial control system are happening now and will probably increase.” Madren suggested best practices to prevent damange include a multi-pronged approach of good industry standards, technology and personal, targeted recommendations to fill in holes in a utility’s security program. It’s all about repetition. Never assume that all the holes have been covered. Always go back and check again and again. (In this way, malware is a lot like a zombie horde---always trying to get in a forgotten opening, an unchecked back door, an open window.)
Tatsoft’s Gosnell would add man to Madren’s best practices equation---keep him tech savvy and on top of things, ready for the onslaught.
“This [attack] also demonstrates that operational risks are an inherent part of running these systems,” Gosnell added. “One of your biggest potential problems comes from poor processes and policies at the human level. Maintaining good security hygiene at the human and social level complements good technical hygiene.”
Madren noted that North American Electric Reliability Corporation’s Critical Infrastructure Protection (NERC CIP) regulations help protect power utility substations from a variety of security issues, including worms like this one. They are incredibly comprehensive and offer a great amount of defense.
“However, no system is completely immune from creative new incursions. Constant vigilance is required,” Madren said.
So, worry? Yes. Panic? Not helpful. Just keep one eye open … and try not to fall asleep and unconsciously let in those zombie malware hordes.
Subscribe to:
Posts (Atom)
