Welcome | Sign In
TechNewsWorld.com
Cyberattacks

Girding the Grid for Cyberattacks

Print Version
E-Mail Article
Reprints
Girding the Grid for Cyberattacks

Regulators tasked with maintaining the U.S. power grid are aware of the dangers posed by cyberattacks on the nation's electrical system. They're just not necessarily in agreement over how to secure it. Meanwhile, engineers look forward to a time when the power grid will give us not only electricity, but also data. The so-called smart grid will need barriers as well.


Crystal Reports - Discover the Latest Innovations.
Download a free trial, view real-time 'behind the scenes' functionality, and learn about new Crystal Reports Server trade in options! Learn more.

The future of the U.S. energy grid is at a crossroads. Energy grids and power distribution systems face a number of daunting challenges. One of the most critical is the ability to respond to changing variables in real-time. Meanwhile, the energy industry is often slow to implement new technology that optimizes energy consumption and bolsters the power grid from electronic intrusion.

Energy generation, supply, consumption, distribution and security pose numerous high-tech challenges. Every change in these components requires the execution of sophisticated analytics to predict the downstream or upstream impact and the required actions to re-balance the network. In addition, the ever-increasing number of nodes on the energy network provide new potential security holes, which need to be monitored and managed.

"It is critical that any legislation to secure the electric grid include proper identity assurance. This will ensure that even successful hackers/intruders are curtailed at every access point and an audit trail created should an intrusion occur. Identity assurance limits access and accessibility, and the standards already exist," Dominic Fedronic, CTO of ActivIdentity and chairperson of the GlobalPlatform Government Task Force (GTF), told TechNewsWorld

Government Action

At least some of what Fedronic called for may be in the works. Last month, the North American Electric Reliability Corporation's (NERC) independent board of trustees approved eight revised cybersecurity standards for the North American bulk power system.

This action represents the completion of the first phase of the NERC's cybersecurity standards revision work plan, which was launched in July 2008. Work continues on phase two of the revision plan, with new standards already under development, according to the NERC.

The standards comprise some 40 good housekeeping requirements designed to lay a solid foundation of security practices. If properly implemented, the energy industry will develop the capabilities needed to secure critical infrastructure from cybersecurity threats, according to the NERC. Roughly half of those requirements were modified to clarify or strengthen the standards in this initial phase.

Heavy Fines

These revisions begin to address the concerns the Federal Energy Regulatory Commission (FERC) raised in its Order No. 706, according to the NERC. That order conditionally approved the standards currently in effect.

Organizations that violate the standards can be fined up to US$1 million per day per violation in the U.S., with other enforcement provisions in place throughout much of Canada. Audits for compliance with 13 requirements in the cybersecurity standards currently in effect will begin on July 1, 2009.

"The approval of these revisions is evidence that NERC's industry-driven standards development process is producing results, with the aim of developing a strong foundation for the cybersecurity of the electric grid," said Michael Assante, vice president and chief security officer at the NERC.

More to Come

The NERC expects to act on the revisions for phase two in early 2010, according to Assante.

However, he cautioned that these standards are not designed to address specific, imminent cybersecurity threats. For that, direct legislative action is needed.

"We firmly believe carefully crafted emergency authority is needed at the government level to address this gap," he said.

All Not Happy

However, critics say the NERC's action in revising the standards for grid cyber-protection may be falling short. It will take more stringent action to make the energy grids more dependable and secure, according to their arguments.

"Just as all critical infrastructure government systems are subjected to best practice security hardening, the energy grid cannot be an exception. Hardening includes securing network access with firewalls, applying intrusion detection, protecting critical applications with strong authentication and TLS (transport layer securit), equipping personnel with FIPS 201 PIV credentials and requiring strong authentication through VPNs for any remote access," ActivIdentity's Fedronic said.

The NERC's revisions are falling short, agreed JT Keating, vice president of marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales for security firm CoreTrace. Critical Infrastructure Protection (CIP) requirements are driving utilities' implementation of alternative solutions, like application whitelisting, designed to stop malware and prevent unapproved applications installed by employees and contractors, he explained.

"Despite months of work, the only notable change to these particular CIPs was a slightly expanded definition of which assets need to be protected against malware. Fundamentally, the CIPs need to be changed to reflect their actual purpose, preventing the execution of any unauthorized code, rather than prescribing specific technologies -- especially technologies that are completely inconsistent with the operational realities of energy management systems and distributed control systems that are the core of the critical infrastructure," Keating told TechNewsWorld.

Growing Threats

With much of the energy industry relying on the Internet, concern has been raised about the potential for security exploitation, especially considering the popularity of active (and sometimes vulnerability-ridden) content on Web sites.

"There was not much active content five years ago. The Internet carried not much more than simple HTML and Java coding. Today that is too boring. Today any browser can bring down active content. This is the biggest threat today," Jay Chaudhry, CEO of cloud security firm Zscaler, told TechNewsWorld.

The concern isn't so much with the security or lack thereof with Microsoft (Nasdaq: MSFT) Windows so much as the vulnerability of the browser, he explained. The energy grid is threaded across the Internet. Workers access this grid from within physical plants as well as remotely, making a common security bridge.

"The browser has become the new OS for desktops. They are more powerful and can do so much more. That combination is very deadly," said Chaudhry.

He likened using the Internet to using a kitchen knife -- it's a good tool when used right and a dangerous weapon when used wrong, he said.

Security Holes

The entire system needs better authentication to regulate those who log onto the systems that regulate the grid, according to Chaudhry. Power grid management programs are old and in many cases need to be upgraded, he noted.

"This is a tough job. Upgrading is often delayed due to complacency and complexity," said Chaudhry.

Some security firms focus on products to provide a single access control point. Others preach the benefits of multiple access.

Single control is both good and bad, Chaudhry believes. Nothing is wrong with multiple control agencies; what is more important is knowing who is running on the grid and managing it and whether the bad guy is being spotted, he argued.

"The problem is multifaceted. The industry needs to figure out where to start. Not much is being done yet," he said.

Smart Grid Mentality

Energy grid engineers are looking ahead to transition into a type of infrastructure known as a "smart grid" -- in other words, a power grid that not only delivers energy but also communicates data to both users and operators.

One problem a smart grid addresses is the need to optimize traditional energy sources and integrate new sources of energy from new suppliers like wind generators, water dams, etc., according to John Morrell, vice president of product marketing at Aleri. His company develops complex event processing (CEP) technology solutions.

"Companies are looking to create a smarter energy grid. This is a real interesting area. With today's economy, people are going in with economic stimulus funds. The problems that need fixing can take two to four years to solve," Morrell told TechNewsWorld.

Infrastructure issues include smart metering technology. These new types of meters are gradually being installed at customer Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse locations. However, the huge volume of data they generate largely goes unused by many companies, he explained.

For instance, many energy companies aren't currently convinced about how reliable the data is and haven't determined how to use it. The data about all of the dynamics associated with energy distribution and consumption flows like water from a fire hose.

"Even basic business issues such as overcharging or undercharging customers can occur due to lack of familiarity with the new technology," he said.

What It Does

Smart meters could give energy users the ability to reduce their consumption more reliably and provide more dependable billing cycles. Customers that agree to these opt-in programs could get much better energy rates. Energy companies could send alerts to heavy consumers. This would help consumers monitor the causes of excessive consumption, according to Morrell.

"Another benefit is the cost effectiveness. There won't be a need to read meters every other month. This technology is out there. Companies are learning how to use it," he said.

Locking Up the Grid

The smart grid requires that both production and distribution centers be secured. End-user end-points must be ultimately as secure as any other access point in the grid, according to Fedronic.

Secure terminals will have to be created. It makes sense to equip these terminal points with certified security chips that can operate cryptographic algorithms, he noted.

"With secure terminals using certified security chips and operating cryptographic algorithms, cybersecurity easily moves to immediate capabilities of analysis, isolation and elimination. Today, through strong authentication methodologies of varied types, users or machines can be suspended in action and access shut down in seconds at the first alert to any inconsistency or any pre-set parameters," Fedronic explained.


Print Version E-Mail Article Reprints More by Jack M. Germain


Talkback: Join the Discussion.
Communications for smart grid and meters
AMenergy
Posted 2009-06-04
Electricity grids rely today on complex telecommunication networks to monitor the flow of power, ...
Infrastructure 'grid' security
akcoyote
Posted 2009-06-03
I agree that access points need to be secure, but believe the nation's infrastructure should run ...

More by Jack M. Germain

Yahoo Lets FOSS Community Drive Its Traffic Server
November 04, 2009
Yahoo Traffic Server is an app server for builders of cloud services. The software package enables session management, authentication, configuration management, load balancing and routing for an entire cloud computing stack. Yahoo has now open sourced a version of the application through Apache.
Is AES Encryption Crackable?
November 03, 2009
A team of researchers has discovered what they think could be a flaw that leaves AES encryption open to attack. The technique has only been shown in a theoretical setting; in practice, such a hack would be very difficult to pull off. Still, such a finding could bring into question the faith that's been placed in AES -- and spur new innovation to make encryption even better.
Windows 7 Is a Snooze
October 29, 2009
It's accurate to say that Windows 7 straightens out some of the problems with Vista. Aside from that, though, there aren't a whole lot of standout reasons to upgrade to the new OS, especially if you're currently on XP or you honestly don't mind Vista. The new features that are present aren't quite worth the trouble to learn how to use, and if you happen to have even slightly old equipment, forget about it.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network