The Macrosite for News, Analysis and Opinion about the Future of the Internet
Ira Winkler

How to Take Down the Power Grid

Written by Ira Winkler
10/16/2007 6 comments
DISCUSS     Email This

The first time I broke into our country’s electrical power grid was a decade or so ago. Hacking into the control systems set up by utility companies wasn’t surprising then, and it isn’t surprising now. While people find this shocking, it really isn’t. When you think about how insecure computer infrastructures are, why would you think that the power grid would be any more secure? Frankly, the power grid is even less secure than most other computer networks. I wrote about it many times, including some details in my recent book, Spies Among Us.

All of this came back to me as I watched news stories about “Hackers Blow Up a Generator.” The Department of Homeland Security (DHS) put out a video showing a test from Idaho Nuclear Laboratory where someone broke into a SCADA (Supervisory Control and Data Acquisition) computer and caused the generator to run wild until it blew itself up.

News reports by Fox News and other networks explained how this process could bring down the power grid. Of course, they were all wrong. If the worst of our problems was that a couple of generators would blow themselves up, we should be happy.

For anyone who’s not aware of my background, I am most noted for performing espionage or terrorist simulations -- or what most people might naively refer to as penetration tests. In the case I mentioned at the beginning of this article, my team was supposed to perform a simple assessment of the security of a Website owned by a power company. The Website had security vulnerability and provided us a connection to the company’s internal network. From there, we could get to any system in the company, including its SCADA systems. We were told by the security manager to leave out access to the SCADA system in our report, but we were allowed to download the personnel records of the CEO and CIO, so that the results would be hard for them to ignore.

Since many readers might not be computer security experts, let me first cover some basic computer security issues to explain how computer systems can be compromised. There are two primary ways to break into a computer: (1) take advantage of bugs in the software, and (2) take advantage of the way a user or administrator configures or uses the computer.

With regard to taking advantage of bugs in the software, everyone will acknowledge that all software has bugs. Some bugs create elevated privileges, provide unauthorized access, or cause information leakage. These are security vulnerabilities. If you can connect to a computer that has not corrected such a vulnerability, you can take it over. It is that simple.

The vulnerability can exist in the operating system, SCADA applications software, Web browser, or any other software on the computer. In the case of SCADA and its supporting systems, power companies are very slow to mitigate the vulnerabilities, and may never do so, because they are afraid that any change can create problems. This is why power grid systems are likely to be more vulnerable to cyber attacks than most other computers.

With regard to taking advantage of configuration problems, even perfectly secure software can be set up insecurely. For example, I have seen many computers where the password on the Administrator account is “administrator.” Passwords can otherwise be insecure. Low-level users can be given high-level access. There are also more technical ways to insecurely configure a computer. Again, if you can access a poorly configured computer, you can take it over.

Many people might now be thinking, “But isn’t it impossible to actually connect to or otherwise access a power grid SCADA system?” The answer is very sadly, “Hell no!”

Initially, the power grid control systems were on closed networks. However when the Internet started to blossom, power companies decided that it was too costly to maintain separate networks. After all, they would need two computers on every desk, which wouldn’t be able to talk to each other. At the time, they rationalized that this only required adding extra protection to logically separate the power grid from the corporate networks. Don’t count on the hope that they actually followed through with that.

In addition to being able to access the SCADA systems through the Internet, there are still elements of the traditional power grid that provide access to outsiders. For example, there are modems connected to critical systems for maintenance purposes. Wireless access has been added to many systems. Now, since power companies can buy and trade power with other companies, they need to know the available capacity. In order to know the available capacity, you have to eventually connect to SCADA systems. So there is even an outside connection engineered into the power grid.

So fundamentally, you can connect to the power grid, and critical supporting systems are vulnerable to cyber attacks and will remain that way.

Again, the news video of the generator blowing itself up is really cheesy, and too much was made of that individual demonstration. However, that is really a misapplication of the video, which was released to create fear, uncertainty, and doubt. It should be interpreted to mean: If a malicious party were to connect to a SCADA system, here is one, small result. More importantly, it is easy for malicious parties to connect to many systems throughout the power grid and create damage on a massive scale with the proper planning.

I hope the intent of the DHS was to create enough fear for Congress to start writing laws that force power companies to secure their computers. Right now, computer security on the power grid is an oxymoron. The reality is that Congress doesn’t have the balls to pass such laws, bowing to the mind games of power company lobbyists like a storm trooper bowing to the mind games of a Jedi.

The situation is really this bad. Congress is impotent, as the power grid remains incredibly vulnerable, and people need to be outraged.

There are many people out there who are trying to downplay the DHS video, and ridiculing it. Again, it is true that the video has not been put in the proper context. However, anyone who claims that the power grid is not at serious risk is very naïve and/or ignorant.

For the record, the last time I broke into a nuclear power generation system was about a year ago. The “simulation” had to be called off after a few hours, because the results were “too successful”. It is that bad.

— Ira Winkler, Former National Security Agency analyst and author of Spies Among Us

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
orchid1
Rank: Cave Painter
Monday November 16, 2009 1:46:34 AM
no ratings

I agree, it is not surprising and whats more, all this without any social engineering. I think the government needs to realize that this sort of attack will never go away and the only thing the govenment do is minimize damage.

I say this only because I realize how much more could be done with less technical skills and more social skills. One might get 100 percent technical coverage but social engineering will make all that tech stuff incosequential.

Love the article. Think it has the correct perpective. But it is also deflating. There are way too many loopholes in the system for the country to ever be even 50% safe right now we are naked and the tide has gone out.

 

chadwyk
IQ Crew
Friday October 19, 2007 3:12:44 AM
no ratings
Not only did he break in to the 911 system, he sent a SWAT unit to a house with two children.  Apparently the guy had a knife in his hand as he knew something wasn't right.  It is a good thing he didn't get shot!
Michael Singer
IQ Crew
Wednesday October 17, 2007 4:49:11 PM
no ratings

Ira, What continues to confound and amaze me is that security is continually breached on mission-critical systems.

Certainly decentralization is helpful, but it seems internal and external threats are on the rise. Unplugging them from the network or setting up a siloed grid is an acceptable answer.

However, it doesn't seem like it's going to let up if the management is eager to adopt software-based communications. Forget malicious Web browsers or bot attacks, looks like VoIP is the latest weak link in the chain.

Just last week, security firm Radu State found a vulnerability in the Linksys SPA-941 (version 5.1.8) that allows a malicious hacker to conduct a cross-site scripting (XSS) attack using SIP. That kind of exposure is scary considering some of the CIOs I talk with are eager to migrate from PBX systems.

But, that's just fine with hackers who suggest that breaking systems is "so easy a caveman can do it."

Ken Trough
Thinkernetter
Wednesday October 17, 2007 12:46:13 PM
When it comes to security testing, I can certainly understand not publicizing results widely, but here you have a report (from a more than credible expert) detailing internal security managers instructing the experts to leave key information out of internal reports in order to hide the worst vulnerabilities from their own executive staff. Further, you have testing that is being stopped early due to it being too successful.  This is certainly outrageous if not criminal negligence. The fact that vulnerabilities exist does not concern me especially, as there are vulnerabilities in every system. That is what you pay security experts to discover and illuminate for you. But when the worst of the exposure is obscured at best, or intentionally omitted at worst, then the companies don’t get an accurate risk analysis and they don’t build an appropriate culture of security vigilance for these critical infrastructure systems. We live in a world where computer security is being hammered on by parties from all over the planet with both malevolent and benign intent on a 24/7/365 basis. This is not a matter of speculation nor of interpolation. It is well established fact.  Which is the easier mountain to move? Energy company executives that don’t understand or don’t believe their company’s current risk exposure or an ineffective congress who is either completely reactionary or proactive (but only on the behalf of major corporate and sponsor interests)?  Given the interconnected nature of the grid, I believe a company by company approach to infrastructure security insures that you will always have weak entry points and overall grid vulnerability (the weakest link syndrome). As such, I think this is properly addressed at the national infrastructure security level. 

So, the real question is how do we engage our leadership to implement the fundamental policy changes and security improvements that we desperately need? Are we going to wait until our grid is totally and publicly compromised on a regular basis before political will to implement effective policies is generated?

 Perhaps this would best be driven by the executive branch by this or the next president. As security conscious as we are supposed to be, it seems like the concept of improving national infrastructure in a meaningful way would not be a hard sell, and there are always a lot of resources in the energy markets to work with so funding should not be a significant issue either. 

Is there a better approach?

Jabbermouth
Rank: Cave Painter
Wednesday October 17, 2007 11:45:51 AM
no ratings
Seems we can't be riminded too often of how vulnerable all network types are. Here's a disturbing account of a kid who broke into four states' 911 systems to generate faux emergency calls:

FredMars
Rank: Cave Painter
Tuesday October 16, 2007 3:27:00 PM
no ratings
It does seem that the best defense against an attack would be first to decentralize the power grid. Decentralization would make taking down any one part of the grid isolated from disturbing the rest.
Computer security aside, and while this is a major issue. The way everything is centrally controlled and distributed is an issue that makes cyber-based attacks so devastating.
Biometrics can and should be used for all power grid control terminals, so that only authorized users can access the control applications. Internet access may be breached, but that should only gain access to viewing data, not changing it.
Security like other requirements that are often put aside, are more a matter of economics than technology. Throw enough money at a problem and it can be fixed. The ability or willingness to throw money at a problem is another story. It seems that most of the software industry uses blame to abstain from taking on the responsibility themselves. If the operating system has a security flaw, that means all of the applications running under that OS will have security issues. As you said, bugs in software are a fact and fixing a bug in one application will not fix a bug in another app or the OS.
With all of the alternative energy generation technologies emerging to replace burning fossil fuels, it should be paralleled with an equal amount of innovation withregard to distributing that power and securing access to the control system(s) for it. And Congress cannot legislate against stupidity, so it is up to the power utilities themselves to provide secure generation and distribution of power. DHS guidlines would help set standards, but only the diligence of the industry will close the holes.
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Ira Winkler
Ira Winkler
Ira Winkler   3/30/2010   38 comments
While I try to think that one should never be happy with the misfortunes of others, it is satisfying to see that Albert Gonzalez was sentenced to 20 years in prison for basically masterminding the compromise of more than 100 million credit cards.
Ira Winkler
Ira Winkler   3/23/2010   12 comments
I am surprised a recent news story is not getting more attention. In short, Iran took down 29 Websites the government said were operated by Iranian dissidents, supposedly backed by CIA operations intended to destabilize the country. The government arrested 30 people assumed to be affiliated with those sites.
Ira Winkler
Ira Winkler   3/1/2010   22 comments
Given what I do, I felt compelled to watch the CNN special, Cyber Shock, which featured a simulated cyber-attack against the United States. As I watched I wanted two things: a bullet in my head, and the return of Dick Cheney's take-charge governance style.
Ira Winkler
Ira Winkler   2/8/2010   22 comments
In his recent Congressional testimony, Dennis Blair, the U.S. director of national intelligence, stated that the U.S. is "severely threatened" by cyber attacks and that the recent Google (Nasdaq: GOOG) attacks should serve as a wake-up call.
Ira Winkler
Ira Winkler   1/27/2010   42 comments
I keep telling people that if they do everything right, they will be generally secure. I like to think I do everything right myself to minimize the likelihood of being hit by malware. I avoid going to unusual sites. I don’t click on links in strange emails. When reading normal emails, I verify any embedded links, just in case.
5
of
Mitch Wagner
A Humbling Lesson From Libya on Why IT Matters

9|17|12   |   3:09   |   5 comments


Sean Smith, a US Foreign Service IT manager, gave his life in service of his country and the world. His life and death are a humbling example for all of us who work in IT.
Wisdom of the Big Chair
Home Security: An Emerging Internet Battlefield

6|11|12   |   2:22   |   4 comments


With the advent of low-cost Web cameras and broadband network connections, home security systems have become a hot business. In addition to traditional security suppliers, like ADT, the market is attracting telcos, cable companies, and energy providers, thereby creating an area of increasing competition.
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
what.the.ferraro
CMAS Alert! Something's Wrong! Or Not!

11|2|11   |   03:18   |   27 comments


If you have a CMAS-enabled handset, be prepared to receive scary alerts from the government.
The Sole Man
The UK's Antisocial Network

8|17|11   |   2:22   |   2 comments


Police Forces across the UK are using social media and messenger services to track down looters. BlackBerry Messenger users, that means you, too.
Wisdom of the Big Chair
Facial Recognition Looms on the Horizon

7|27|11   |     |   4 comments


Law enforcement agencies are poised to use iPhones as facial recognition systems in the coming months. The technical advance promises efficiency but has created a backlash among civil liberties proponents.
Full Nelson
Cyber Crime as Cyber War

10|19|09   |   2:02   |   4 comments


Earlier this year, Heartland Payment Systems was breached by Russian hackers who had also hit 300 other financial institutions. The scope of the Russian operation is mind-blowing and points to a new era in cyber attacks.
Full Nelson
The New Cyber War

10|8|09   |   3:06   |   4 comments


Cyber Warfare may be the next frontier for tactical hacking. It has already reared its head in Estonia, Russia, and Georgia, and some say it has been used by North Korea, China, and other world powers. The implications and the potential are both fascinating and scary.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Second Shooter
Terrorists Attack Our Refrigerators!

2|28|13   |   2:22   |   No comments


50 billion household devices will be on the Internet by 2020, according to Cisco. And we're hearing foreign governments are hacking our infrastructure. Surely our refrigerators are next!
IETV: the thinkerNet on film
5
of
John Kennedy
How Big-Data Is Changing Marketing

6|13|13   |   1:07   |   1 comment


Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   10 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   1 comment


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
2pm EDT
Fri
Jun 21st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   6/18/2013   Post a comment
The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
NSA Leaks Shine Spotlight on Perils of Contractor Partnerships
Jason Mick
The US National Security Agency learned the
hard way that it can be dangerous to give a contractor too much money and access, with too little scrutiny. The NSA and other government agencies hire tens of thousands of contractors a year to analyze data. Edward Snowden -- who revealed himself as the NSA leaker after fleeing the country -- was one such contractor, reportedly holding a $122,000 salaried position at Booz Allen Hamilton at the time of his departure.

CLICK FOR MORE