Vulnerabilities / Threats
9/13/2012
09:50 AM
Dark Reading
Dark Reading
Products and Releases
Connect Directly
RSS
E-Mail
50%
50%

China's Cyberattack Fears To Spark Massive Defense Spending

GlobalData study describes country's cybersecurity market as an ‘anomaly’

LONDON, UK (GlobalData), 13 September 2012 - China's concerns over the safety of its power infrastructure will result in astronomical security spending over the next decade, states the latest report by international business analysts GlobalData.

The new paper* says that China's cyber security market will expand remarkably in the coming years, from a valuation of $1.8 billion in 2011 to $50 billion by 2020, representing a dramatic compound annual growth rate (CAGR) increase of 44.7%.

The study describes the country's cyber security market as an 'anomaly', due to the scale of expenditure when compared with that of other regions - Europe and North America combined are predicted to spend a comparatively modest $16 billion during the same period.

The Asian giant has a strained relationship with a number of nations in relation to cyber security, with the US in particular often accusing Chinese hackers of attempting to breach their power systems, although this has never been confirmed by Chinese government. Such accusations may have fostered an environment of mistrust in which the Chinese authorities expect retaliatory cyber-attacks on their own power infrastructure.

However, as GlobalData explains, for a country experiencing rapid urbanization and undertaking smart grid construction on a vast geographical scale, the cost of protecting all available access points will be huge. The smart grid building phase is expected to be complete by 2015, at which point tens of thousands of homes will be securely connected at an approximate cost of $1,000 per household.

The Stuxnet computer worm, discovered in 2010, was a major example of the vulnerability of power grids to malicious cyber-attack. The worm focused on five Iran-based organizations and was believed by many to be a deliberate attempt to disrupt the Iranian nuclear power program.

* Cyber Security in Smart Grid – Market Size, Key Issues, Regulations and Outlook to 2020

-ENDS-

-NOTES TO EDITORS-

This report provides insights into global developments related to cyber security in smart grid.

This report was built using data and information sourced from proprietary databases, primary and secondary research, and in-house analysis conducted by GlobalData's team of industry experts.

-ABOUT GLOBALDATA-

GlobalData is a leading global business intelligence provider offering advanced analytics to help clients make better, more informed decisions every day. Our research and analysis is based on the expert knowledge of over 700 qualified business analysts and 25,000 interviews conducted with industry insiders every year, enabling us to offer the most relevant, reliable and actionable strategic business intelligence available for a wide range of industries.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.