Hiển thị các bài đăng có nhãn vulnerabilities. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn vulnerabilities. Hiển thị tất cả bài đăng

A Novel Approach to Grid Cybersecurity Awareness


Not long ago I was in a meeting with the CIO of a large electric utility and when I inquired as to the cybersecurity awareness of the board of directors, was told it had recently skyrocketed.

Why the sudden shift I asked?  Had the company just endured a serious and/or highly public breach? Nope, things had been mercifully static on that front. A classified threat briefing by DHS? No, not that either. Well, what was it then?

Apparently one board member had read the latest Tom Clancy book, Threat Vector and once exposed to Clancy's fictional vision of how the US could be brought low through largely cyber means, it changed his thinking. Spoke in language he could understand, and captured his imagination too. It soon spread to the rest of the board.

Now comes former Senator Byron Dorgan with a cautionary novel of his own, and this one is much more grid-centric, from the title on. I later read Threat Vector myself ... 900 pages or so if I remember right, looking for power sector specific attacks and breaches and they were few. I've read some of the reviews of Gridlock, though, and in it the US grid is front and center and not doing so well.

Dorgan and co-author David Hagberg don't have anywhere near Clancy's readership, not close. But if an executive in your company were to happen upon a copy, well, apparently it's quite a page turner, and you might have a new, more cybersecurity-aware board to work with in a few weeks.


Looking Again at the Markey-Waxman Grid Vulnerability Publication

Where would I be without feedback? Many thanks to SGSB readers who chimed in on this.

I recently published a post titled "House of Reps Report Reams Utilities on Cybersecurity." Not accurate and all you have to do is read the cover page which, just below the House seal, says "A Report written by the staff of congressmen Edward J. Markey (D-MA) and Henry A. Waxman (D-CA)". Mea Gulpa.

So on second look I looked a little closer and found some things to like and some things I had to wonder about. For example, I'm happy to see congressmen seeking more information about the current state of security in our sector. Who could argue with that?

But their methods are not fully sound.
For example, in the cover letter to the questionnaire their staffers mailed out, it asks utilities: "... to provide responses from your entity ... and request that you submit your response electronically." But unless I'm much mistaken, the types of detailed information they sought regarding breaches and ensuing damage to bulk power systems should not and can not be shared in plain text via standard email. Please tell me if I'm wrong about that.

See question 10 which asks for info for the past 5 years re: breaches and damage, as well as how many incidents listed were and were not reported to FERC, NERC and DHS. We're still in the middle of a huge information sharing debate in this country and I don't believe we've reached agreement that this type of very sensitive information is fare game for staffers or the general public.

To sum, this curious document is the product of 2 and only 2 congressman, not the entire House, not the House Energy & Commerce Committee (which is where you'd expect something like this to have its origins), nor anywhere else. There are definitely a few good things in there, though. But my bet is most of what it tells you you already know.

So if you read it please do so with a generous helping of NaCl.
URLs for the above, below:

House Report on Electric Grid Cyber Vulnerability

http://markey.house.gov/sites/markey.house.gov/files/documents/Markey%20Grid%20Report_05.21.13.pdf

SGSB post "House of Reps Report Reams Utilities on Cybersecurity."

http://smartgridsecurity.blogspot.com/2013/05/house-of-reps-report-reams-utilities-on.html

House of Reps Report Reams Utilities on Cybersecurity

Was trying to capture spirit of Jesse Berst's headline on the same subject:
Utilities to FERC: Take your security measures and shove it
That's not very nice, is it?  I think they toned it down with a later change, but this headline was what was in my inbox in this morning's SmartGridNews.com newsletter. The subject is a recent report published by the House of Representatives that's highly critical of electric utilities behavior to date re: grid cybersecurity.

Moving on! The Wall Street Journal's Rachel King did a fine write-up of recent testimony from the CEO of the American Gas Association (AGA), Dave McCurdy. King began by noting that:
The oil and gas sector faces many of the same cyber security challenges as the electric industry. Yet, there’s one major difference between the industries, both of which need to secure software-based industrial control systems from intruders. There are no regulations governing cyber security among the oil and gas companies.
She also heard McCurdy say that no regulations were needed and that the sector’s voluntary approach is working just fine, and:
AGA remains concerned that prescriptive cyber security regulations will have little practical impact on cyber security and, in fact, will hinder implementation of robust cyber security programs.
If you know this subject pretty well, you're aware that there is some interesting psychology and rhetoric going on here. Most agree that mandatory, prescriptive cybersecurity rules are painful to implement and audit, and too slow to adapt to new types of attack. So in a major sense, the AGA CEO's quote is dead on. 

But the rub is that "robust cyber security programs," loosely defined, are not commonplace in the natgas distribution sector, and it's hard to imagine that market forces alone will drive companies to move of the schneid.  And the same dynamic largely holds true for the electric power sector.

The language is getting a little saucy. What's going to give?

URLs for the above, below:

House Report on Electric Grid Cyber Vulnerability

http://markey.house.gov/sites/markey.house.gov/files/documents/Markey%20Grid%20Report_05.21.13.pdf

SmartGridNews.com on Utilities' Unhappiness with Cybersecurity Regulation

http://www.smartgridnews.com/artman/publish/Technologies_Security/Utilities-to-FERC-Take-your-security-measures-and-shove-it-5778.html/?fpt#.UZ4dcSt4ZyE

WSJ: Oil and Gas Lobby Resists Regulation Despite Cyber Risk

http://blogs.wsj.com/cio/2013/05/22/oil-and-gas-lobby-resists-regulation-despite-cyber-risk/

Sanity Check: Nuclear Cyber Security Should be the Best, Right?


A few recent missile launchings notwithstanding, you may recall a little over a month ago things were hot and heavy in the North vs. South Korea showdown. On April 15th Japan Times published this account: South Korea Bolsters Security of Nuclear Plant Network, which opened thusly:
SEOUL – The state-run operator of South Korea’s nuclear power plants has separated its internal computer network from the Internet in an effort to guard against possible North Korean cyber attacks, Yonhap News Agency reported Sunday.
and continued:
It said Korea Hydro & Nuclear Power Co. has also completely divided its nuclear plant control systems from its internal computer networks and restricted both systems’ access to the Internet, while USB ports of the plant control systems have also been sealed.
This sounded nutty to me, so I ran it by someone who knows better, and as he, an expert in nuclear security said over a blueberry tart:
Of course, they never should have been connected in the first place. 
Not sure if South Korean nuclear cyber security practices are representative of the wider state of affairs in the world, but in my dealings, South Korea has been at the forefront of cyber security thinking in Asia for some time. Maybe the press garbled this a bit?  I'd sure like to think so.

Kori nuclear plant photo credit: WSJ.com