One security concern involves tens of millions of wireless “smart meters” being installed in homes and businesses that potentially expose the power grid to hackers and other cyber attacks.
Photograph by: Jean Levac, Ottawa Citizen
OTTAWA — The cyber-security of the North American power grid is “in a state of near chaos,” according to report by a respected U.S. energy consultancy monitoring the industry’s transition to wireless digital technologies.
The white paper by Pike Research reveals that a $60 smart phone application can bypass security measures and allow direct communications between the phone and some control systems (ICS) that regulate breakers, relays, feeders and the flow of electricity.
The news comes on the heels of a warning from the cyber-security arm of the U.S. Department of Homeland Security that the hacker collective known as Anonymous appears intent on exploiting the ICS vulnerabilities within the energy industry.
In an unclassified October bulletin obtained by the website Public Intelligence, the National Cybersecurity and Communications Integration Center believes the group has, “a limited ability to conduct attacks against ICS. However, ... Anonymous could be able to develop capabilities to trespass on control system networks very quickly.”
In July, Anonymous threatened to target companies involved with Alberta’s oilsands.
Coincidentally, the North American Electric Reliability Corporation, which enforces reliability standards for North America’s gigantic and interconnected bulk power system of transmission lines and control systems, began a long-planned security exercise Tuesday.
It says the three-day “cyber readiness” drill will, “test the electricity industry’s crisis response plans, and validate current readiness in response to a cyber incident.”
Despite the concerns and warnings, North America’s power supply has never been disrupted by hackers, though there have been numerous uneventful penetrations of the system, including at Ontario utilities.
A chill went through the critical infrastructure industry last summer when a malicious computer worm called Stuxnet attacked Iran’s uranium enrichment plants.
Stuxnet was the first piece of malware built not only to spy on industrial control systems, but to reprogram them, and reportedly destroyed about 1,000 Iranian centrifuges.
Unlike water or gas, electricity cannot be stored, it must be generated and then immediately used. It is the world’s most extreme just-in-time commodity and that means generation and transmission operations must be constantly monitored and controlled.
As the industry evolves from largely isolated systems to a grid built around interoperable, digital technologies, security jitters are rising.
Many ICS have lifespans of 30 years and mitigation and compensation measures to help them mesh with the newer technologies are creating additional weak links and vulnerabilities.
Another worrisome change involves tens of millions of wireless “smart meters” being installed in homes and businesses for faster, more efficient two-way communications with local utilities via the Internet. Utilities, in turn, are networked with the big transmission operators and bulk power generators. More than 300,000 smart metres are installed in Ottawa homes and small businesses.
The concern is that they potentially expose the system to hackers and other cyber attacks.
In a rush to install a patchwork of fixes to address potential cyber-security gaps and with some utilities investing in compliance minimums rather than full security, “the attackers clearly have the upper hand,” says the report from Pike Research, a market research and consulting firm providing analysis of global clean technology markets.
The good news is, “a dawning awareness by utilities and vendors during the past 18 months of the importance of securing smart grids with architecturally sound solutions. There is hope.”
© Copyright (c) The Ottawa Citizen
Full article located at here
No comments:
Post a Comment