Risk
5/22/2008
06:16 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Power Company Slammed For Weak Cyber Security

Almost all of the workstations and servers that GAO examined on the TVA's corporate network lacked key security patches or had inadequate security settings.

The Tennessee Valley Authority (TVA), the nation's largest public power company, was found to lack adequate cybersecurity, according to a Government Accountability Office (GAO) report released on Wednesday.

"TVA had not fully implemented appropriate security practices to secure the control systems used to operate its critical infrastructures at facilities GAO reviewed," the GAO report said. "Multiple weaknesses within the TVA corporate network left it vulnerable to potential compromise of the confidentiality, integrity, and availability of network devices and the information transmitted by the network."

The GAO found that "almost all of the workstations and servers that GAO examined on the corporate network lacked key security patches or had inadequate security settings." It also found that the TVA's control system networks weren't adequately secured.

William McCollum, TVA's chief operating officer, said in prepared remarks that the TVA had already started addressing 17 of the 19 issues raised by the GAO when the GAO began its investigation last October. The TVA, he said, concurs with the GAO recommendations and is working to implement them. He said that the TVA had hired a penetration testing company to try to break into its systems. The hired hackers were unable to access TVA's process control network, but McCollum acknowledged that "the process identified several opportunities to further insulate and protect the security of our systems."

Concern about the security of the nation's power plants was heightened last year when the Department of Homeland Security leaked a video that demonstrated how a hacker could damage a power generator using only code. The problem has since been referred to as the Aurora vulnerability.

Such scenarios aren't merely theoretical: In January, CIA senior analyst Tom Donahue confirmed that online attackers had caused at least one blackout in a city outside the United States.

PA Consulting Group traces the rising number of cybersecurity incidents at utilities to the urge to connect to the Internet, which put an end to security through obscurity. "Historically, process control systems were designed and constructed using proprietary technologies and installed in isolation from corporate IT systems," the firm said in a recent report. "However, recent trends include basing newer systems on more cost effective platforms, such as Intel or Microsoft Windows."

It would be unfair, however, simply to blame Windows. There isn't a vendor out there that writes invulnerable code. In May, for example, Core Security identified a vulnerability in Wonderware's SuiteLink software, which counts about a third of the world's power plants as customers.

A 2004 study by PA Consulting Group and the British Columbia Institute of Technology found that half of all control system incidents came through corporate networks. The study estimated the average cost of such incidents to be about $1.8 million. Targeted attacks could cost over $10 million, according to the report.

At a hearing held by the House Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology on Wednesday, Rep. Jim Langevin, D-R.I., was critical of both the government's and private industry's efforts to address infrastructure security.

"I think we could search far and wide and not find a more disorganized, ineffective response to an issue of national security," said Langevin in prepared remarks. "Everything about the way this [Aurora] vulnerability was handled -- from press leaks, to DHS's failure to provide more technical details to support the results of its test, to [the North American Electric Reliability Corp.'s] dismissive attitude, to the industry's half-hearted approach towards mitigation -- leaves me with little confidence that we are ready or willing to deal with the cybersecurity threat. "

Testifying at the hearing, Joseph T. Kelliher, chairman of the Federal Energy Regulatory Commission (FERC), said in prepared remarks that progress has been made in the three years since Congress established FERC oversight of the nation's power system. But he also said that more needs to be done to secure critical infrastructure.

Kelliher noted that because compliance with critical infrastructure protection rules is voluntary, there's often confusion about how to respond to security problems such as the Aurora vulnerability. He suggested allowing the FERC to set mandatory, enforceable standards in circumstances when a national security or intelligence agency identifies a national security threat to the power system.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2531
Published: 2014-10-21
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) R...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.