Risk
12/6/2011
12:32 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Smart Grid Security Threatened By Fragmented Control

MIT study finds smart grid cybersecurity led by fiefdoms, says central leadership would better protect the nation's power lines from hackers.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
The United States government should consolidate the currently splintered operational control of cybersecurity in the emerging smart power grid under the authority of one federal agency, according to a two-year study by a group of researchers at the Massachusetts Institute of Technology.

The study, which set out to analyze whether the U.S. power grid is prepared for technologies and power sources over the next 20 years, recommended a host of policy changes to gird the grid against coming challenges, including new powers and authorities regarding the emerging smart grid, particularly around cybersecurity.

Currently, the Federal Energy Regulatory Commission and the North American Electric Reliability Corporation are empowered to create and police cybersecurity standards for power plants, but no organization has oversight over the grid itself, and states are headed in their own directions. In addition, the agencies with cybersecurity responsibilities aren't working together enough, the study found.

[ Cybersecurity is one part of the feds' four-pillar smart grid plan. Learn about the other three: White House Unveils National Smart Grid Strategy Framework. ]

"To cope more effectively with increasing cybersecurity threats, a single federal agency should be given responsibility for cybersecurity preparedness, response, and recovery across the entire electric power sector, including both bulk power and distribution systems," the report says. "Ongoing jurisdictional confusion raises security concerns, underscoring the need for action."

That's a point of major concern for a power system that the MIT report points out will soon see massive growth in the amount of data flowing over its lines as smart meters and synchophasors (devices that measure and help optimize power transmission) come online and power companies begin to push more and more data-enabled services over power lines.

"With the collection, transmission, processing, and storage of increasing amounts of information also comes heightened concern for protecting the privacy of that information," the report said. Information on personal electricity use habits, for example, will become more widely available to electric companies than ever before.

Hackers, not just the corporations themselves, will likely be interested in this data and opportunities to disrupt the grid. The Wall Street Journal reported in 2009 that Chinese and Russian government hackers were likely already looking for points of cyber weakness in the smart grid.

Various observers and policymakers also have argued for a centralized point of authority for smart grid cybersecurity, with various parties arguing for the Department of Homeland Security, the Department of Energy, or the current electricity and energy regulatory bodies. MIT didn't recommend any particular agency over any other, but said designating one should be a high priority.

In addition to better management of cybersecurity, the MIT researchers recommended that the government spend more on research and development into procedures for response to and recovery from cyberattacks on the grid.

Cybersecurity wasn't the only IT fix the MIT study recommended to bolster the power grid in the future. The researchers also suggested that the energy industry do more R&D into using IT for bulk power system operations and planning for power transmission over wide geographic areas.

In this new Tech Center report, we profile five database breaches--and extract the lessons to be learned from each. Plus: A rundown of six technologies to reduce your risk. Download it here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
renttester
50%
50%
renttester,
User Rank: Apprentice
2/25/2012 | 11:12:44 AM
re: Smart Grid Security Threatened By Fragmented Control
thanks for sharing
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/7/2011 | 2:44:02 AM
re: Smart Grid Security Threatened By Fragmented Control
Interesting. Ponemon Institute put out a study earlier this year that found that there were a number of security gaps at many utility companies:
http://www.darkreading.com/sec...
Brian Prince, InformationWeek/Dark Reading Comment Moderator
FTC Opens Probe into Equifax Data Breach
Jai Vijayan, Freelance writer,  9/14/2017
Equifax CIO, CSO Step Down
Dark Reading Staff 9/15/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Jan, check this out! I found an unhackable PC.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.