NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Policy
Slice by Program

Public utility's bare insecurities

By: Richard Bray, columnist, CIO Government Review(Oct 31, 2007 06:00:00)

Editorial

The shocking image of an electrical generator ripping itself apart in a simulated hacking attack opens a CNN report on SCADA (supervisory control and data acquisition) vulnerabilities.

The computer network attached to the generator has been breached and the SCADA controller settings changed to make it self-destruct.

The report moves on to experts worried about simultaneous cyber attacks that would lay waste to the electrical power infrastructure for months, and features a think tank executive who says such an attack could be like "40 to 50 large hurricanes striking all at once."

The frightening message was that critical infrastructure - everything from power and water plants to food processing and pipeline systems - is at risk from terrorists. The CNN report ended in a somewhat lame fashion, however, by wondering whether the cyber security holes could be closed "before the hackers find them."

The report did its best to be sensational, but in fact, it may not have been sensational enough. It could have said that hackers have found lots of holes, they know how to find more and they know what to do with them.

A man named Scott Lunsford hacked into a nuclear power station. It took a day to breach the network and a week to assume complete control. First, people told him it was impossible to get in. Then, when he did, they told him he couldn't have done any harm. He thinks he could have shut down all the power to most of an American state.

Fortunately, Lunsford works for IBM's Internet Security Systems and he was taking part in a controlled experiment.

But the lesson is clear: much of our privately owned but publicly critical infrastructure is highly vulnerable to attack.

SCADA systems monitor flows of fluid or power, open and close valves, and trigger alarms when things go wrong. Whoever controls these controllers controls the system. They are simple devices, typically transmitting and receiving data at slow speeds.

Randy Sutton of Ottawa's Elytra Enterprises has been trying for years to get government's attention about SCADA vulnerabilities. He says that until about five years ago, most SCADA systems were at least nominally under human control. They are, however, increasingly being attached to computer networks.

"The operational system is now connected to the corporate network and that's where the trouble starts," he says.

There is a basic philosophical difference between a SCADA engineer and an IT security specialist, Sutton points out. Both groups are concerned about the CIAs of security, confidentiality, integrity and availability, but with a different emphasis.

"In the IT security business, we get all worked up about confidentiality and integrity, but reliability and availability, well, while it's important, it tends to get lost in the shuffle.

"SCADA people are just the opposite. They don't care about the confidentiality of some little device that's putting out data at 9600 bits a second. What they care about is 100 per cent availability because if the grid goes down, there's no point maintaining your confidentiality," he says.

Sutton makes it clear that hacking into a SCADA system is not particularly easy, but then it might not have to be. "Certainly, if you had some insider assistance, it could become extremely dangerous."

He points out that IT security is often only as good as the physical and personnel security around it. A classic case of insider sabotage took place in Australia in 2000, when a hacker used wireless equipment to cause the release of some raw sewage.

So far, there are remarkably few such stories and they are endlessly recycled - the successful 2001 hack attack at a California power plant, the nuclear safety monitoring system crippled by the Slammer worm in 2003 - but many in IT security believe incidents have gone unreported and there is even some suspicion that utilities have paid ransoms to halt or prevent attacks.

SCADA security is probably years behind the rest of IT security, Sutton believes, but existing programs could quickly be ported over to plug the gaps. In the electricity sector, the North American Electric Reliability Council has published standards for SCADA security that any big utility tying into the continental grid will have to meet by 2010.

Where governments have regulatory powers, such as in energy or transportation, SCADA systems will inevitably come under some form of mandatory IT security. It will probably take successful attacks, and lots of sensational journalism about those attacks, to bring the rest.

Richard Bray is an Ottawa-based freelance journalist specializing in high technology and security. Contact him at rbray@itworldcanada.comB )

Related content:

Hactivism attacks could rise, warns security expert

Privacy, link analysis and counter-terrorism

The compromising CIO: forever compromised

Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement

2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada