Feeds

CIA claims crackers took out power grids

Future threat or urban myth in the making

High performance access to file storage

Crackers have blackmailed foreign governments after disrupting the operating of utilities, according to a CIA analyst. Skeptics said the unspecified claims amount to nothing more than urban myths, although other sections of the security community are treating the possibility of attacks against Supervisory Control And Data Acquisition (SCADA) systems seriously.

SCADA systems lie at the heart of networks that control water, sewage and electricity systems. These devices allow utilities to remotely control and monitor generation equipment and substations over phone lines, radio links and, increasingly, IP networks.

Interconnection between SCADA environments and corporate networks introduce specific security needs around protocols and applications used that are not addressed by the majority of existing cyber security products. Existing standards are immature, and power systems have different requirements in terms of reliability and availability to corporate systems.

CIA senior analyst Tom Donahue told 300 delegates at a SANS Institute conference in New Orleans last week that utilities were being actively targeted in cyber attacks. Some of these attacks have been accompanied by subsequent blackmail attempts, a pattern first seen in the online gambling industry six or seven years ago. The level of knowledge applied in the attack suggests an internal attack.

"We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge," Donahue said, according to a statement posted on the SANS web site. "We have information that cyber attacks have been used to disrupt power equipment in several regions outside the US. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the internet," he added.

Delegates at the SANS conference shared data on how attackers are eluding current defenses and on best practices for mitigating vulnerabilities. They also shared a jointly developed "SCADA and Control Systems Survival Kit".

According to Donahue, the CIA only decided to make a (highly non-specific) warning about attacks on utilities after a period of internal soul searching. Some security watchers are highly skeptical about the claims, noting the irony that dire predictions of cyberattacks were made in a city that suffered the US's worst ever natural disaster.

Rob Rosenberger, Vmyths co-founder and scourge of cybersecurity fear-mongering, said the CIA had confirmed nothing. In an entertaining rant against SANS for treating unspecified reports of disruption seriously, he described the topic as the genesis of an urban myth.

Reports of successful cyberattacks on utility systems are thin on the ground. There is an Australian case, dating back more than seven years, where a disgruntled ex-employee, Vitek Boden, hacked into a water control system and flooded the grounds of a hotel with a million of gallons of sewage in March and April 2000. In Russia, malicious crackers managed to take control of a gas pipeline run by Gazprom for around 24 hours in 1999. Then there's a case where the Slammer worm affected the operation of the corporate network at Ohio's inactive Davis-Besse nuclear plant and disabled a safety monitoring system for nearly five hours in January 2003.

We've never heard of a "disruption (that) caused a power outage affecting multiple cities". That's not to say attacks against SCADA systems, which are increasingly connected to the net, are impossible or that the topic doesn't deserve careful analysis. The threat level, for now at least, remains at around the same level of the possibility of mobile malware taking down a phone network. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Bad PUPPY: Undead Windows XP deposits fresh scamware on lawn
Installing random interwebs shiz will bork your zombie box
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.