Tuesday, March 12, 2013
Saturday, February 23, 2013
Power grid is vulnerable to cyber and physical attack
Earlier this week, a report by the cyber security firm Mandiant pointed to China as the source of several cyber attacks on the U.S. One of the targets of those attacks is the power grid. Although no one has successfully pulled off a large-scale disruption of the power, there have been blackouts caused by weather. Hurricane Sandy had millions of people living by candlelight. So just how vulnerable is our power grid?
The National Research Council recently issued a 168-page report — “Terrorism and the Electric Power Delivery System.” It found the system to be highly vulnerable for two reasons.
Number one: The system is physically vulnerable, particularly the system’s large high voltage transformers. Granger Morgan is one of the authors of the report. He says many of these transformers are at facilities in wide open spaces. “So a small number of people who knew what they were doing could do very large and very disruptive damage to the system.”
Repairing broken transformers could leave large numbers of people without power for weeks or even months.
The second vulnerability is to cyber attacks. “All the hype is about cyber attack,” says Morgan. “But physical attacks can take the system down for weeks or months and it’s almost impossible to see how you do that with cyber attack.”
Whether from the Internet or the ground, the solution to these vulnerabilities is to break up the system into smaller micro grids.
Enter the bureaucracy — the government, utilities and regulators. The electric utility industry has a self-regulatory body called the North American Elecrtic Reliability Council (NIRC). There’s also the Federal Energy Regulatory Commission (FERC) and then there are the state governments.
“A lot of the nuts and bolts and making sure that the equipment is secure will be decided at the state level,” says Richard Caperton, an energy expert at the Center for American Progress.
Ninety percent of the U.S. power grid is privately owned. There isn’t much financial incentive for utilities to break up their systems into micro grids. That means the government will have to coordinate with regulators and utilities to make the necessary changes. In other words, it’s not a quick fix.
Power grid is vulnerable to cyber and physical attack
Tuesday, February 19, 2013
Don"t freak out (yet) about "scary" Chinese cyber attacks
A recent piece in the New York Times said that the Chinese army is constantly hacking American computers. The article is based on a study by cybersecurity firm Mandiant. The study shows Chinese intrusions into corporate networks in the U.S. trace back to an Army unit in Shanghai.
Scary stuff, right? Kim Zetter of Wired says “scary” may be the wrong word to use.
“I don’t like to use that word. This is espionage, and a lot of it is economic espionage; in the past, it’s happened in a lot of other ways. Computers just make it a lot easier and a lot more stealth,” said Zetter.
But how do these guys even go about hacking into corporate systems? Zetter says the main avenue for hackers is through email.
“It’s very easy to get into email. You have a lot of protections on a network, but you can’t block email from getting in,” said Zetter.
Zetter said hackers use “spearfishing” attacks: Malware emails that are crafted in a way that entice users to click. These emails usually come from a person that the user knows or is about a topic that the employee is interested in. When the email is open, it allows malware into the system, and hackers use that to dig deeper into a system.
Although it may seem like common sense to stray away from clicking something suspicious, Zetter says you can take all the measures you want to get employees not to do something, but they will still do it.
Don"t freak out (yet) about "scary" Chinese cyber attacks
