US Grid: Add Hackers To The List
The US power grid is extremely vulnerable, as are those in Europe. Primarily because they are old and over-burdened, but also because they are targets. If terrorists took out a number of transmission substations or control stations, they could cause chaos. Anarchy and suffering in the US could lead to global turmoil. Now, aside from the Sun and terrorists, Scientific American reports that hackers could potentially bring down a power grid:
- Every facet of the modern electrical grid is controlled by computers. It is our greatest example of physical infrastructure interlinked with electronics.
- The Stuxnet virus that infected Iran’s nuclear program showed just how vulnerable machines could be to a well-crafted electronic virus.
- The grid shares many of the vulnerabilities that Stuxnet exposed; being larger, its vulnerabilities are, if anything, more numerous.
- A sophisticated attack could bring down a large chunk of the U.S. electrical grid.
The US grid wasn’t designed with security in mind:
A year ago I took part in a test exercise that centered on a fictitious cyberattack on the grid. Participants included representatives from utility companies, U.S. government agencies and the military. (Military bases rely on power from the commercial grid, a fact that has not escaped the Pentagon’s notice.) In the test scenario, malicious agents hacked into a number of transmission substations, knocking out the specialized and expensive devices that ensure voltage stays constant as electricity flows across long high-power transmission lines.
By the end of the exercise half a dozen devices had been destroyed, depriving power to an entire Western state for several weeks.
Computers control the grid’s mechanical devices at every level, from massive generators fed by fossil fuels or uranium all the way down to the transmission lines on your street. Most of these computers use common operating systems such as Windows and Linux, which makes them as vulnerable to malware as your desktop PC is. Attack code such as Stuxnet is successful for three main reasons: these operating systems implicitly trust running software to be legitimate; they often have flaws that admit penetration by a rogue program; and industrial settings often do not allow for the use of readily available defenses.
Even knowing all this, the average control system engineer would have once dismissed out of hand the possibility of remotely launched malware getting close to critical controllers, arguing that the system is not directly connected to the Internet. Then Stuxnet showed that control networks with no permanent connection to anything else are still vulnerable. Malware can piggyback on a USB stick that technicians plug into the control system, for example. When it comes to critical electronic circuits, even the smallest back door can let an enterprising burglar in.
The article goes on to mention a variety of vulnerabilities. Security is being upgraded, but it won’t happen overnight. Unfortunately most people are ignorant of how bad it would be if the grid went down.