Risk
12/6/2011
12:32 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Smart Grid Security Threatened By Fragmented Control

MIT study finds smart grid cybersecurity led by fiefdoms, says central leadership would better protect the nation's power lines from hackers.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
The United States government should consolidate the currently splintered operational control of cybersecurity in the emerging smart power grid under the authority of one federal agency, according to a two-year study by a group of researchers at the Massachusetts Institute of Technology.

The study, which set out to analyze whether the U.S. power grid is prepared for technologies and power sources over the next 20 years, recommended a host of policy changes to gird the grid against coming challenges, including new powers and authorities regarding the emerging smart grid, particularly around cybersecurity.

Currently, the Federal Energy Regulatory Commission and the North American Electric Reliability Corporation are empowered to create and police cybersecurity standards for power plants, but no organization has oversight over the grid itself, and states are headed in their own directions. In addition, the agencies with cybersecurity responsibilities aren't working together enough, the study found.

[ Cybersecurity is one part of the feds' four-pillar smart grid plan. Learn about the other three: White House Unveils National Smart Grid Strategy Framework. ]

"To cope more effectively with increasing cybersecurity threats, a single federal agency should be given responsibility for cybersecurity preparedness, response, and recovery across the entire electric power sector, including both bulk power and distribution systems," the report says. "Ongoing jurisdictional confusion raises security concerns, underscoring the need for action."

That's a point of major concern for a power system that the MIT report points out will soon see massive growth in the amount of data flowing over its lines as smart meters and synchophasors (devices that measure and help optimize power transmission) come online and power companies begin to push more and more data-enabled services over power lines.

"With the collection, transmission, processing, and storage of increasing amounts of information also comes heightened concern for protecting the privacy of that information," the report said. Information on personal electricity use habits, for example, will become more widely available to electric companies than ever before.

Hackers, not just the corporations themselves, will likely be interested in this data and opportunities to disrupt the grid. The Wall Street Journal reported in 2009 that Chinese and Russian government hackers were likely already looking for points of cyber weakness in the smart grid.

Various observers and policymakers also have argued for a centralized point of authority for smart grid cybersecurity, with various parties arguing for the Department of Homeland Security, the Department of Energy, or the current electricity and energy regulatory bodies. MIT didn't recommend any particular agency over any other, but said designating one should be a high priority.

In addition to better management of cybersecurity, the MIT researchers recommended that the government spend more on research and development into procedures for response to and recovery from cyberattacks on the grid.

Cybersecurity wasn't the only IT fix the MIT study recommended to bolster the power grid in the future. The researchers also suggested that the energy industry do more R&D into using IT for bulk power system operations and planning for power transmission over wide geographic areas.

In this new Tech Center report, we profile five database breaches--and extract the lessons to be learned from each. Plus: A rundown of six technologies to reduce your risk. Download it here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/7/2011 | 2:44:02 AM
re: Smart Grid Security Threatened By Fragmented Control
Interesting. Ponemon Institute put out a study earlier this year that found that there were a number of security gaps at many utility companies:
http://www.darkreading.com/sec...
Brian Prince, InformationWeek/Dark Reading Comment Moderator
renttester
50%
50%
renttester,
User Rank: Apprentice
2/25/2012 | 11:12:44 AM
re: Smart Grid Security Threatened By Fragmented Control
thanks for sharing
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.