In this file image from video released by the Department of Homeland Security, smoke pours from an expensive diesel electric generator during a March 2007 demonstration by the Idaho National Laboratory, which was simulating a hacker attack against the US electrical grid.
In this file image from video released by the Department of Homeland Security, smoke pours from an expensive diesel electric generator during a March 2007 demonstration by the Idaho National Laboratory, which was simulating a hacker attack against the US electrical grid.
Dept. of Homeland Security/AP/file
up
  • In this file image from video released by the Department of Homeland Security, smoke pours from an expensive diesel electric generator during a March 2007 demonstration by the Idaho National Laboratory, which was simulating a hacker attack against the US electrical grid.
  • The sun is seen filtering through wildfire smoke at the evacuation center at the Steele Canyon HIgh School in Jamul, Calif. on Oct. 24. With a key power transmission line off because of wildfires, authorities are asking San Diego residents to conserve energy.
down

New U.S. tack to defend power grid

Lawmakers are on alert as hackers increase attacks on US infrastructure.

Page 2 of 3

Page 1 | 2 | Page 3

This feature requires a newer version of Macromedia Flash Player and javascript-enabled browser.

Get Flash Player

Reporter Mark Clayton discusses government and private sector efforts to prevent cyber attacks on the U.S. power grid and other energy infastructures.

Danger to SCADA systems for the electric grid, for instance, was highlighted in a 2002 National Research Council report. At a key meeting in July 2003, officials from the US Department of Energy, DHS, the national laboratories, and other agencies convened to develop a national cybersecurity plan.

Despite that and other efforts since 9/11 to protect control systems from cyberattack, "the federal government lacks an overall strategy for coordinating public and private sector efforts," the Government Accountability Office (GAO) reported to Congress earlier this month.

Some experts describe a patchwork defense that has many gaps – and they note that malicious attacks, directed in particular at the electric grid, are growing.

Internet attacks on the 100 electric utility clients protected by SecureWorks, an Atlanta-based cybersecurity firm, leaped 90 percent this year – from 43 attacks per utility per day at the beginning of the year to 93 since May, company officials reported this month. That's about double the rate for other industries SecureWorks protects.

The US has been "in a race against time" since early 2005, when the attention of "black hat" hackers shifted to focus more on probing and exploiting SCADA control-system weaknesses of electric utilities, says Mr. Borg. Yet lights have mostly stayed on – a testament to the notion that industry and government still appear to be ahead in the race.

In a bid to plug gaps, the National Electric Reliability Corp. (NERC) in June was put in charge of grid reliability. It has proposed eight new cybersecurity requirements that are already being adopted by the electric-power industry. Those standards, though, were attacked as inadequate by experts during an Oct. 17 congressional hearing.

Known examples of hackers infiltrating the grid and taking parts of it down are rare. Such cases exist, security experts insist, though nondisclosure contracts prohibit them from talking about them to the press.

A year ago, Ira Winkler, a security expert taking part in an exercise to test the cyberdefenses of a nuclear-power plant, used his computer to hack into the plant's control system. After a few hours, the whole thing was called off because the "simulation" was too successful. Mr. Winkler had wrested control of key systems from plant engineers and could do what he wanted with the plant.

"A lot of people have stock answers saying everything's just fine, but the point is, if the underlying systems are vulnerable, that's all there is to it, says Mr. Winkler, a former NSA cryptanalyst who is now president of Internet Security Advisors Group, an Internet security company.

1 | Page 2 | 3 | Next Page

Related Stories
Get Monitor stories by e-mail:
(Your e-mail address will be protected by csmonitor.com's tough privacy policy.)
(Mary Knox Merrill/Staff)
EDITOR'S PICK Five cities that will rise in the New Economy
From Seattle to Huntsville, Ala., five cities are poised to prosper in the New Economy because of exports, innovation, clean technology, and healthcare.

In Pictures:
Get ready for gridlock
POLITICS Patchwork Nation
The American voter beyond red and blue

Daily podcast

Monitor Reports

Discussions with Monitor reporters from around the world


Today

Peter Grier

The Monitor's Peter Grier talks with reporter Ron Scherer about how Black Friday will effect the economy this year.




Making a difference
Making a Difference

What happens when ordinary people decide to pay it forward? Extraordinary change. See how individuals are making a difference, finding solutions, overcoming adversity, and giving back globally.

Richard Berry stands in a former Sunday School classroom in the basement of Trinity Evangelical Free Church. The room has been turned into a men's homeless shelter.

Sarah Beth Glicksteen

A church that is home to the homeless

Pastor Richard Berry lives the motto 'faith without works is dead'