Risk
12/6/2011
12:32 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Smart Grid Security Threatened By Fragmented Control

MIT study finds smart grid cybersecurity led by fiefdoms, says central leadership would better protect the nation's power lines from hackers.

Federal Data Center Consolidation Makes Progres
Federal Data Center Consolidation Makes Progress
(click image for larger view and for slideshow)
The United States government should consolidate the currently splintered operational control of cybersecurity in the emerging smart power grid under the authority of one federal agency, according to a two-year study by a group of researchers at the Massachusetts Institute of Technology.

The study, which set out to analyze whether the U.S. power grid is prepared for technologies and power sources over the next 20 years, recommended a host of policy changes to gird the grid against coming challenges, including new powers and authorities regarding the emerging smart grid, particularly around cybersecurity.

Currently, the Federal Energy Regulatory Commission and the North American Electric Reliability Corporation are empowered to create and police cybersecurity standards for power plants, but no organization has oversight over the grid itself, and states are headed in their own directions. In addition, the agencies with cybersecurity responsibilities aren't working together enough, the study found.

[ Cybersecurity is one part of the feds' four-pillar smart grid plan. Learn about the other three: White House Unveils National Smart Grid Strategy Framework. ]

"To cope more effectively with increasing cybersecurity threats, a single federal agency should be given responsibility for cybersecurity preparedness, response, and recovery across the entire electric power sector, including both bulk power and distribution systems," the report says. "Ongoing jurisdictional confusion raises security concerns, underscoring the need for action."

That's a point of major concern for a power system that the MIT report points out will soon see massive growth in the amount of data flowing over its lines as smart meters and synchophasors (devices that measure and help optimize power transmission) come online and power companies begin to push more and more data-enabled services over power lines.

"With the collection, transmission, processing, and storage of increasing amounts of information also comes heightened concern for protecting the privacy of that information," the report said. Information on personal electricity use habits, for example, will become more widely available to electric companies than ever before.

Hackers, not just the corporations themselves, will likely be interested in this data and opportunities to disrupt the grid. The Wall Street Journal reported in 2009 that Chinese and Russian government hackers were likely already looking for points of cyber weakness in the smart grid.

Various observers and policymakers also have argued for a centralized point of authority for smart grid cybersecurity, with various parties arguing for the Department of Homeland Security, the Department of Energy, or the current electricity and energy regulatory bodies. MIT didn't recommend any particular agency over any other, but said designating one should be a high priority.

In addition to better management of cybersecurity, the MIT researchers recommended that the government spend more on research and development into procedures for response to and recovery from cyberattacks on the grid.

Cybersecurity wasn't the only IT fix the MIT study recommended to bolster the power grid in the future. The researchers also suggested that the energy industry do more R&D into using IT for bulk power system operations and planning for power transmission over wide geographic areas.

In this new Tech Center report, we profile five database breaches--and extract the lessons to be learned from each. Plus: A rundown of six technologies to reduce your risk. Download it here (registration required).

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
12/7/2011 | 2:44:02 AM
re: Smart Grid Security Threatened By Fragmented Control
Interesting. Ponemon Institute put out a study earlier this year that found that there were a number of security gaps at many utility companies:
http://www.darkreading.com/sec...
Brian Prince, InformationWeek/Dark Reading Comment Moderator
renttester
50%
50%
renttester,
User Rank: Apprentice
2/25/2012 | 11:12:44 AM
re: Smart Grid Security Threatened By Fragmented Control
thanks for sharing
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.