On GameSpot: The top games of the 2000s so far?
BNET Business Network:
BNET
TechRepublic
ZDNet

April 8th, 2009

The U.S. electrical grid: How big of a cyber target is it?

Posted by Larry Dignan @ 7:22 am

Categories: General, Government, Hardware Infrastructure, Security

Tags: Asset, SCADA, Grid, Intrusion, Asset Management, Enterprise Software, Security, Operational Planning, Business Operations, Software

Updated: Spies have reportedly been probing the U.S. electrical grid for months and planting software that could be activated at a future date, according to a Wall Street Journal. The report highlights the latest vulnerabilities facing U.S. power infrastructure.

The Journal notes that the spies are from China, Russia and other countries. While the news isn’t that surprising—given how vulnerable U.S. infrastructure is—it is notable because electrical grids were initially thought to be somewhat hacker proof until recently. Why? Grids run on an old mish-mash of software, which is often proprietary.

However, recent events indicate that so called SCADA systems—(Supervisory Control And Data Acquisition), which collect data from sensors and machines and send them to a centrally managed repository—are also at risk. To wit, last June Core Security detailed how SCADA systems were vulnerable. And even silly electronic road sign pranks show how SCADA systems are vulnerable.

How bad is it? According to the Journal report, a SCADA attack may be a disaster waiting to happen. The ability to hack into electric grids isn’t new–you can find reports here, here and here—and the usual techniques such as social engineering, exploits and other hijinks work well. In addition, the House Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology had a big hearing on electric grid threats a year ago and the General Accountability Office has also highlighted the issues in a report on network controls.

In a report, the GAO found the Tennessee Valley Authority (TVA), a federal corporation and the nation’s largest public power company, “had not consistently implemented significant elements of its information security program.” Meanwhile, the TVA’s corporate network “lacked key software patches and had inadequate security settings, and numerous network infrastructure protocols and devices had limited or ineffective security configurations,” according to the GAO.

Simply put, the fact the grid is wide open for malicious hackers isn’t news. What’s different is the Journal is naming names (at least countries).

The Journal notes that:

  • The Chinese have attempted to map the U.S. electrical grid;
  • The espionage is pervasive and not targeted to any one company or region;
  • The companies in charge of the infrastructure—remember most of the U.S. networks are in private hands—never knew of the intrusions;
  • Intelligence agencies discovered the intrusions;
  • Water, sewer and other systems are at risk;
  • And the intelligence gleaned through these intrusions will be critical in the event of war.

The good news is that the Obama administration is about to complete a cybersecurity review and Congress had approved $17 billion in funds to protect government networks under the Bush administration.

Also see: TechRepublic resources on SCADA security

GAO report on Tennessee Valley Authority’s security weaknesses

House hearing on electric grid vulnerabilities

However, throwing money at the problem may not help all that much.

The North American Electric Reliability Corporation told its members that utilities need to step up security procedures. In the letter, Michael Assante, chief security officer of the group, wrote:

NERC is requesting that entities take a fresh, comprehensive look at their risk-based methodology and their resulting list of CAs (critical assets) with a broader perspective on the potential consequences to the entire interconnected system of not only the loss of assets that they own or control, but also the potential misuse of those assets by intelligent threat actors.

Assante outlines the grid’s conundrum:

Most of us who have spent any amount of time in the industry understand that the bulk power system is designed and operated in such a way to withstand the most severe single contingency, and in some cases multiple contingencies, without incurring significant loss of customer load or risking system instability. This engineering construct works extremely well in the operation and planning of the system to deal with expected and random unexpected events. It also works, although to a lesser extent, in a physical security world. In this traditional paradigm, fewer assets may be considered “critical” to the reliability of the bulk electric system.

But as we consider cyber security, a host of new considerations arise. Rather than considering the unexpected failure of a digital protection and control device within a substation, for example, system planners and operators will need to consider the potential for the simultaneous manipulation of all devices in the substation or, worse yet, across multiple substations. I have intentionally used the word “manipulate” here, as it is very important to consider the misuse, not just loss or denial, of a cyber asset and the resulting consequences, to accurately identify CAs under this new “cyber security” paradigm. A number of system disturbances, including those referenced in NERC’s March 30 advisory on protection system single points of failure, have resulted from similar, non-cyber-related events in the past five years, clearly showing that this type of failure can significantly “affect the reliability (and) operability of the bulk electric system,” sometimes over wide geographic areas.

Taking this one step further, we, as an industry, must also consider the effect that the loss of that substation, or an attack resulting in the concurrent loss of multiple facilities, or its malicious operation, could have on the generation connected to it.

The good news so far: It doesn’t appear that these intrusions have led to any attacks. But as grids become smarter via technology, they’re likely to be easier to hack. It’s only a matter of when, not if, the grid—and other key infrastructure—gets hacked.

Update: I’d like to point out the following Talkback.

I am a retired engineer, formerly employed by 2 electric utilities - one of them a very large utility within the U. S; Department of Energy. In that job I was the project manager for a large SCADA/Energy Control System. So I (think) I know a little about SCADA systems and how they operate.

EVERY SCADA system that I have ever seen use its own dedicated communication network to carry data between the Master Station (the “base”), and the substation Remote Terminal Units (RTU’s) and with the powerplants. The Master Station is manned 24 hours per day, seven days per week, 52 weeks per year. In other words, ALL THE TIME. So if something happens, the knowledgeable, experienced operator can take immediate steps to counteract the event. One example: many years ago, a light airplane flew into a high voltage transmission line in Northern Arizona. The electric system “alarmed”, and a dispatcher in a Phoenix control center shut down that line and rerouted power so as to minimize outages to customers until the cause of the alarm had been identified and corrective measures taken.

Another Western US utility’s management decided to “economize” by combining the SCADA functions with the company’s corporate functions in a single computer. And, of course, there was a “firewall” between the SCADA and corporate functions. And when the firewall failed, it took down the company’s entire power grid. Needless to say, nobody in electric utility management today sees this as a way to economize.

Oh yes, did I mention that SCADA systems almost always use redundant computers, so that in the event that one fails, an automatic “failover” to the backup computer occurs?

Remember the late 1990’s, and the widespread fear that the rollover to year 2000 would cause widespread failures in the electric power grid, because microprocessors and computers had not been designed to recognize dates beyond 1999? And that once the grid crashed, taking out all electric power in North America, it would be impossible to restart, because electric power was needed just to start up a generator, etc. As the person who designed the data communications protocol for use between our Master Station and the several (hydro and steam) powerplants we had under control, I knew that the prognosticators of doom were wrong. And, remember what happened on New Year’s Day, 2000: NOTHING. The electric system continued to function, just as before. The doom-sayers were WRONG.

So, considering that utilities use dedicated, private (usually microwave) communications for their SCADA systems, and that the data communications use various coding and security methods, I, for one, will not lose any sleep worrying that the Chinese or Russians are going to tap into our country’s SCADA systems and crash the power grid.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 230 Talkback(s)
not linux not Windows but something completely
new and proprietary, closed source for this one. (Read the rest)
Posted by: tech_walker Posted on: 05/04/09 You are currently: a Guest | | Terms of Use
So, in the future...  quasilou | 04/08/09
can't fix it without Linux  Linux Geek | 04/08/09
That is the problem  GuidingLight | 04/08/09
I doubt it.  apostate | 04/08/09
I read otherwise  Intellihence | 04/09/09
Winbloze: Why am I not surprised...  hasta la Vista, bah-bie | 04/09/09
Try again  Dr. John | 04/10/09
LOL  apostate | 04/08/09
Re: LOL  StoneSatellite | 04/09/09
Stupidity this blatent  Crestview | 04/09/09
Can't take the heat?  hasta la Vista, bah-bie | 04/09/09
Google "Large hadron collider hacked"...  HypnoToad | 04/09/09
Has there ever been...  Dr. John | 04/10/09
ROFL! Too funny...  Wolfie2K3 | 04/11/09
not linux not Windows but something completely  tech_walker | 05/04/09
RE: The U.S. electrical grid: How big of a cyber target is it?  brentb@... | 04/08/09
Are you an idiot??  bioteach123 | 04/08/09
Are you an idiot??  neverhome | 04/08/09
Marxist?  apostate | 04/08/09
Where does one start?  JohnMcGrew@... | 04/08/09
Don't forget....  Erroneous | 04/08/09
I've seen some erronious statements here before  apostate | 04/08/09
@ Apostate  Erroneous | 04/08/09
Dunno, but thisis where I'll finish.  apostate | 04/08/09
Bravo, couldn't have said it better myself...  xXSpeedzXx | 04/08/09
TAX BREAK!  partman1969@... | 04/08/09
Typical. The only way you can support your arguments...  JohnMcGrew@... | 04/08/09
Just keep worshiping...........  Disgruntled M$ User | 04/09/09
Reply to JohnMcGrew  914four | 04/10/09
You'd almost think that...  JohnMcGrew@... | 04/10/09
How is that different from republican policies?  xXSpeedzXx | 04/08/09
The dems just love.....  Erroneous | 04/08/09
HEY SPED......  partman1969@... | 04/08/09
Dems = Highest TAXES in HISTORY  Christian_<>< | 04/08/09
How are they different?  JohnMcGrew@... | 04/08/09
....  n0neXn0ne | 04/08/09
Sorry, but the Democrats own most of your list  JohnMcGrew@... | 04/09/09
Reply to JohnMcGrew Re: 9/11  914four | 04/09/09
Reply to 914four: Nice try; Clinton let Bin Laden go.  JohnMcGrew@... | 04/10/09
And as for Bush & 911...  JohnMcGrew@... | 04/10/09
Re apostate  Col Mustard | 04/08/09
I Dunno.  apostate | 04/08/09
Well said!  914four | 04/09/09
Where has it gotten the French?  JohnMcGrew@... | 04/10/09
You're correct,  Update victim | 04/10/09
re:Marxist?  byter_z | 04/11/09
I will disregard this post...  bbonis@... | 04/24/09
I will disregard this Jerk!  XweAponX | 04/28/09
"less free than at any time in our history"  midenginedrift | 04/09/09
I agree  914four | 04/09/09
Less free...  JohnMcGrew@... | 04/10/09
RE:Are you an idiot??  richdave | 04/09/09
Obama a Marxist?  Ankrum@... | 04/09/09
If that is the case...  JohnMcGrew@... | 04/10/09
Yes, Obama's solution is much better.  JohnMcGrew@... | 04/08/09
Socialism on Steriods  pizzaman7 | 04/08/09
Steroids on Socialism  partman1969@... | 04/08/09
End of a free country  Christian_<>< | 04/08/09
High taxes!!!  partman1969@... | 04/08/09
Re: End of a free country  mike@... | 04/08/09
You're forgetting inflation; the biggest Obama tax  JohnMcGrew@... | 04/08/09
Re: it is a BIG joke........  Christian_<>< | 04/08/09
And, did someone call one and idiot?  windozefreak | 04/08/09
Now THERE is a real Patriot!  Stoshie | 04/09/09
In the 1950s, the tax rate was 90%. Now it's 35% and people whine when  HypnoToad | 04/09/09
Speaking of "people have nary a clue..."...  JohnMcGrew@... | 04/10/09
Well...  windozefreak | 04/08/09
Debt Can not Triple  ceh4702 | 04/13/09
RE: Yes, Obama's solution is much better  Col Mustard | 04/08/09
Idiot ??? !!!  partman1969@... | 04/08/09
I agree  thedudeistoocool@... | 04/08/09
And.,....  ImpartialObserver | 04/08/09
The service where someone had to forge phony documents  GuidingLight | 04/08/09
Of course not, It is much more patriotic to  Update victim | 04/08/09
Then you should know...  windozefreak | 04/08/09
You are all idiots, bow to me  xXSpeedzXx | 04/08/09
OBAMA has a new screen name. (NT)  Update victim | 04/08/09
Who did what?  rdhalsteatzd | 04/08/09
Defense costs  Update victim | 04/10/09
?  bbonis@... | 04/24/09
So the State of the Power-Grid is Obama's Fault?  apostate | 04/08/09
China owns the USA  Christian_<>< | 04/08/09
Typical Liberal Democrat  Update victim | 04/08/09
Obamasiah is GREAT  Christian_<>< | 04/08/09
So...  apostate | 04/08/09
This Link  windozefreak | 04/08/09
FAULT ?  partman1969@... | 04/08/09
Correct logic will never influence a PROGRESSIVE. (NT)  Update victim | 04/08/09
Don't say that....  Erroneous | 04/08/09
Sorry, But  Update victim | 04/10/09
When was America attacked by advanced aircraft?  B.O.F.H. | 04/10/09
to brenth  elderlybloke | 04/08/09
You can't?  desamuelson | 04/09/09
how many acts of war does it take?  wargammer2005 | 04/08/09
Seriously? Read a news article every now and then...  Renesistemic | 04/08/09
As if......  Erroneous | 04/08/09
To: Renesistemic  Summersond | 04/08/09
do you honestly think that a terrorist has any sort of missle that can  xXSpeedzXx | 04/08/09
The idea is to keep the world safe for all without  Update victim | 04/08/09
Red Dawn....  Erroneous | 04/08/09
I wouldn't want mine to endure one (war) on  windozefreak | 04/08/09
Sadam was responsible for ......  Erroneous | 04/08/09
Even you know that.  windozefreak | 04/08/09
Actually...  Erroneous | 04/09/09
Follow the news  desamuelson | 04/09/09
Perhaps you should leave CNN and CBS ocassionally. (NT)  Update victim | 04/08/09
I agree with Renesistemic  elderlybloke | 04/08/09
You need to find your ass in a real war. (NT)  kozmcrae | 04/08/09
Finally!  bartley@... | 04/08/09
Perfect example of a fear driven mind.  xXSpeedzXx | 04/08/09
Fear  partman1969@... | 04/08/09
re: Fear  Christian_<>< | 04/08/09
And Bush held hands with the Saudi King  xXSpeedzXx | 04/09/09
WOW  nimrod666 | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  neil.postlethwaite@... | 04/08/09
Basic security  fromthehip | 04/08/09
There has been Fascist legislation proposed that  Update victim | 04/08/09
Prove it  mike@... | 04/08/09
It is only from Wednesday , Have fun  Update victim | 04/10/09
Definitely overreaching, but don't panic  mike@... | 04/12/09
Yep, Jack Bauer to the rescue  glantz_j@... | 04/08/09
We continue to put all our eggs in one basket, ...  robertj@... | 04/08/09
@wargammer 2005: IDIOT!  ekestler | 04/08/09
Toad watch  grpugh@... | 04/08/09
Question for "Toad Watch"  kk0dj | 04/08/09
Enron rolling blackouts  gregzdnet | 04/08/09
And I thought the Cold War was over.  dsdjr | 04/08/09
cold war?  bartley@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  larry_lepage@... | 04/08/09
US is negligent - Free Gary McKinnon  David Gale | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  thedudeistoocool@... | 04/08/09
What!!!!????  qtrback | 04/08/09
China's Influence  partman1969@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  neverhome | 04/08/09
Private Network?  David Gale | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  pilothotairballoon@... | 04/08/09
nail struck on head  johnnydoe1894 | 04/08/09
Nail Stuck In Head  fromthehip | 04/08/09
Nail Stuck In Head (Mk2)  elderlybloke | 04/09/09
You are right  fromthehip | 04/09/09
Alex jones called.. he wants his gig back.  Been_Done_Before | 04/08/09
If you beleive all you have said  GuidingLight | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  harlan-b@... | 04/08/09
I worry more ...  robertj@... | 04/08/09
Everyone, Please Read  glantz_j@... | 04/08/09
Indeed. Great post.  Larry DignanZDNet Moderator | 04/08/09
Your Question............  harlan-b@... | 04/09/09
Actually, there are indeed links sometimes  RandyL | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  redking44 | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  nfiertel | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  Quantum Rift | 04/08/09
Rather Than Blame Bush, or the big "O" for this spying... Consider This...  Albee_Freeoneday | 04/08/09
Excellent Post, Albee  bartley@... | 04/08/09
YESSSSSS!!  partman1969@... | 04/08/09
Oh yes blame the democratically controlled congress  xXSpeedzXx | 04/08/09
Bush  partman1969@... | 04/09/09
You need to look back then  desamuelson | 04/09/09
Yeah I heard about those fabrications on Fox and  windozefreak | 04/08/09
A year and a few months...  Erroneous | 04/09/09
Fabrications?  Albee_Freeoneday | 04/09/09
Until 2006, the Republicans controlled all of congress - 14 years.  HypnoToad | 04/09/09
Maybe Some Day I'll Approach Your Level Intelligence  Albee_Freeoneday | 04/10/09
RE: The U.S. electrical grid: How big of a cyber target is it?  gsmcten@... | 04/08/09
Smart Grid? Hell!  kozmcrae | 04/08/09
Dumb Grid !!  thedudeistoocool@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  mtlsofar | 04/08/09
WHY WORRY???  techboy_z | 04/08/09
And for the last 8 years, Dems were accusing Bush of appeasing commies etal  HypnoToad | 04/09/09
Conspiracy Theory  websmith | 04/08/09
Re:Conspiracy Theory  namvet_mike@... | 04/08/09
Jeffrey7112  Jeff7112 | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  bartley@... | 04/08/09
I disagree whole heartedly..  OntheEdge | 04/08/09
You are wrong.  Erroneous | 04/08/09
POSTS !!!!  partman1969@... | 04/08/09
Separting Networks...  SaipanMan95 | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  thedudeistoocool@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  Richard Moon | 04/08/09
Where'd that Kilovolt Spike come from?  madrucke@... | 04/08/09
I believe.....  Erroneous | 04/08/09
Breakers and Fuses, TOO SLOW  madrucke@... | 04/08/09
Breakers and fuzes?  GuidingLight | 04/08/09
Only when....  Erroneous | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  ryderj@... | 04/08/09
You are correct!  owen.stevens@... | 04/09/09
China owns the USA, it should be China Socalist States  Christian_<>< | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  jrg5067 | 04/08/09
Take the power grid off the Internet and soon!  davetracer@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  sunday71007 | 04/08/09
The power grid is not on the Internet  BALTHOR | 04/08/09
Dude what  Zach S | 04/08/09
Just a little perspective would be nice  croberts | 04/08/09
It's THEIR fault.  donho | 04/08/09
Their fault  partman1969@... | 04/08/09
RE: The U.S. electrical grid: How big of a cyber target is it?  rdhalsteatzd | 04/08/09
Meters  liz04@... | 04/09/09
Isolation is the best policy.  CobraA1 | 04/08/09
Yeah!  liz04@... | 04/09/09
Power Grid to Political Flaming  PeterPac | 04/08/09
@erroneous  windozefreak | 04/08/09
I never watch FOX....  Erroneous | 04/09/09
"Obama" Propoganda??  XweAponX | 04/28/09
RE: The U.S. electrical grid: How big of a cyber target is it?  jhiggz@... | 04/08/09
@ reasonable limits  windozefreak | 04/08/09
the folks from this report weren't the same  benitodarder | 04/09/09
the folks from this report weren't the same  benitodarder | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  Disgruntled M$ User | 04/09/09
What about.......?  Disgruntled M$ User | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  rkempthorne | 04/09/09
PROFOUNDLY TRUE !!!  mik3 | 04/11/09
RE: The U.S. electrical grid: How big of a cyber target is it?  shaf_90@... | 04/09/09
you are a fool or a traitor  wargammer2005 | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  lgianelos@... | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  AL-COLLINS@... | 04/09/09
So just say no  Randalllind | 04/09/09
It's impossible to list all the things you got wrong, Albee  DelbertPGH | 04/09/09
What Are You Smoking???? Can I please have some?  Albee_Freeoneday | 04/09/09
Stupitity  WindowWasher | 04/09/09
The DEMOCRATS Have Been in Control SInce...  Albee_Freeoneday | 04/09/09
With Bush as president and having something called VETO POWER,  HypnoToad | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  starzbriter2003@... | 04/09/09
Hello World  jiagebusen | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  rdhalsteatzd | 04/09/09
RE: The U.S. electrical grid: How big of a cyber target is it?  atari8bit@... | 04/10/09
RE: The U.S. electrical grid: How big of a cyber target is it?  johnfranks999 | 04/10/09
Does anyone else want to borrow my soapbox?  roo_z | 04/10/09
Problem Overblown  Well... | 04/10/09
RE: The U.S. electrical grid: How big of a cyber target is it?  Bilmekanikeren | 04/10/09
RE: The U.S. electrical grid: How big of a cyber target is it?  Bilmekanikeren | 04/10/09
Is ZDNET to be Politico-Net now?  XweAponX | 04/28/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads