Risk
5/22/2008
06:16 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Power Company Slammed For Weak Cyber Security

Almost all of the workstations and servers that GAO examined on the TVA's corporate network lacked key security patches or had inadequate security settings.

The Tennessee Valley Authority (TVA), the nation's largest public power company, was found to lack adequate cybersecurity, according to a Government Accountability Office (GAO) report released on Wednesday.

"TVA had not fully implemented appropriate security practices to secure the control systems used to operate its critical infrastructures at facilities GAO reviewed," the GAO report said. "Multiple weaknesses within the TVA corporate network left it vulnerable to potential compromise of the confidentiality, integrity, and availability of network devices and the information transmitted by the network."

The GAO found that "almost all of the workstations and servers that GAO examined on the corporate network lacked key security patches or had inadequate security settings." It also found that the TVA's control system networks weren't adequately secured.

William McCollum, TVA's chief operating officer, said in prepared remarks that the TVA had already started addressing 17 of the 19 issues raised by the GAO when the GAO began its investigation last October. The TVA, he said, concurs with the GAO recommendations and is working to implement them. He said that the TVA had hired a penetration testing company to try to break into its systems. The hired hackers were unable to access TVA's process control network, but McCollum acknowledged that "the process identified several opportunities to further insulate and protect the security of our systems."

Concern about the security of the nation's power plants was heightened last year when the Department of Homeland Security leaked a video that demonstrated how a hacker could damage a power generator using only code. The problem has since been referred to as the Aurora vulnerability.

Such scenarios aren't merely theoretical: In January, CIA senior analyst Tom Donahue confirmed that online attackers had caused at least one blackout in a city outside the United States.

PA Consulting Group traces the rising number of cybersecurity incidents at utilities to the urge to connect to the Internet, which put an end to security through obscurity. "Historically, process control systems were designed and constructed using proprietary technologies and installed in isolation from corporate IT systems," the firm said in a recent report. "However, recent trends include basing newer systems on more cost effective platforms, such as Intel or Microsoft Windows."

It would be unfair, however, simply to blame Windows. There isn't a vendor out there that writes invulnerable code. In May, for example, Core Security identified a vulnerability in Wonderware's SuiteLink software, which counts about a third of the world's power plants as customers.

A 2004 study by PA Consulting Group and the British Columbia Institute of Technology found that half of all control system incidents came through corporate networks. The study estimated the average cost of such incidents to be about $1.8 million. Targeted attacks could cost over $10 million, according to the report.

At a hearing held by the House Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology on Wednesday, Rep. Jim Langevin, D-R.I., was critical of both the government's and private industry's efforts to address infrastructure security.

"I think we could search far and wide and not find a more disorganized, ineffective response to an issue of national security," said Langevin in prepared remarks. "Everything about the way this [Aurora] vulnerability was handled -- from press leaks, to DHS's failure to provide more technical details to support the results of its test, to [the North American Electric Reliability Corp.'s] dismissive attitude, to the industry's half-hearted approach towards mitigation -- leaves me with little confidence that we are ready or willing to deal with the cybersecurity threat. "

Testifying at the hearing, Joseph T. Kelliher, chairman of the Federal Energy Regulatory Commission (FERC), said in prepared remarks that progress has been made in the three years since Congress established FERC oversight of the nation's power system. But he also said that more needs to be done to secure critical infrastructure.

Kelliher noted that because compliance with critical infrastructure protection rules is voluntary, there's often confusion about how to respond to security problems such as the Aurora vulnerability. He suggested allowing the FERC to set mandatory, enforceable standards in circumstances when a national security or intelligence agency identifies a national security threat to the power system.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

CVE-2014-8154
Published: 2015-01-27
The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overf...

CVE-2014-9197
Published: 2015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

CVE-2014-9198
Published: 2015-01-27
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

CVE-2014-9646
Published: 2015-01-27
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.