Feeds

CIA claims crackers took out power grids

Future threat or urban myth in the making

3 Big data security analytics techniques

Crackers have blackmailed foreign governments after disrupting the operating of utilities, according to a CIA analyst. Skeptics said the unspecified claims amount to nothing more than urban myths, although other sections of the security community are treating the possibility of attacks against Supervisory Control And Data Acquisition (SCADA) systems seriously.

SCADA systems lie at the heart of networks that control water, sewage and electricity systems. These devices allow utilities to remotely control and monitor generation equipment and substations over phone lines, radio links and, increasingly, IP networks.

Interconnection between SCADA environments and corporate networks introduce specific security needs around protocols and applications used that are not addressed by the majority of existing cyber security products. Existing standards are immature, and power systems have different requirements in terms of reliability and availability to corporate systems.

CIA senior analyst Tom Donahue told 300 delegates at a SANS Institute conference in New Orleans last week that utilities were being actively targeted in cyber attacks. Some of these attacks have been accompanied by subsequent blackmail attempts, a pattern first seen in the online gambling industry six or seven years ago. The level of knowledge applied in the attack suggests an internal attack.

"We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge," Donahue said, according to a statement posted on the SANS web site. "We have information that cyber attacks have been used to disrupt power equipment in several regions outside the US. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the internet," he added.

Delegates at the SANS conference shared data on how attackers are eluding current defenses and on best practices for mitigating vulnerabilities. They also shared a jointly developed "SCADA and Control Systems Survival Kit".

According to Donahue, the CIA only decided to make a (highly non-specific) warning about attacks on utilities after a period of internal soul searching. Some security watchers are highly skeptical about the claims, noting the irony that dire predictions of cyberattacks were made in a city that suffered the US's worst ever natural disaster.

Rob Rosenberger, Vmyths co-founder and scourge of cybersecurity fear-mongering, said the CIA had confirmed nothing. In an entertaining rant against SANS for treating unspecified reports of disruption seriously, he described the topic as the genesis of an urban myth.

Reports of successful cyberattacks on utility systems are thin on the ground. There is an Australian case, dating back more than seven years, where a disgruntled ex-employee, Vitek Boden, hacked into a water control system and flooded the grounds of a hotel with a million of gallons of sewage in March and April 2000. In Russia, malicious crackers managed to take control of a gas pipeline run by Gazprom for around 24 hours in 1999. Then there's a case where the Slammer worm affected the operation of the corporate network at Ohio's inactive Davis-Besse nuclear plant and disabled a safety monitoring system for nearly five hours in January 2003.

We've never heard of a "disruption (that) caused a power outage affecting multiple cities". That's not to say attacks against SCADA systems, which are increasingly connected to the net, are impossible or that the topic doesn't deserve careful analysis. The threat level, for now at least, remains at around the same level of the possibility of mobile malware taking down a phone network. ®

3 Big data security analytics techniques

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.