Tuesday, February 15, 2011

Smart Grid Security East: Final Reminder ... and an Offer

Here are the details for logisticians:
  • Hotel: The Crowne Plaza Knoxville hotel is the site of the Conference, and it's offering discounted room rates of $99 for attendees to the conference. (Remember to specify the “Smart Grid” block or the code “IWM”) 
  • Dates: Feb 28 - Training workshops, Mar 1 and 2 - Conference
  • Click HERE for conference web site and HERE for $300 off the full price including workshops
And since I think this is a good deal, and nothing of value should be given away for free, I'm going to ask you a question, and the first 5 who answer it correctly can attend Smart Grid Security East for free. Ready? Here you go:
Yesterday, on Valentines evening, an IBM supercomputer named Watson and its two human competitors on Jeopardy were given the following clue by Alex Trebek in the category "Potent Potables Olympic Oddities": "It was the anatomical oddity of US gymnast George Eyser who won a gold medal on the parallel bars in 1904."
What did Watson say? Email your answer to andybochman at gmail dot com and I'll let you know if you were correct ... and fast enough.

Conference Alert: Heads-Up on First Asian Smart Grid Security Conference

I may (or may not) have mentioned this previously, but Asia is finally getting in on the act. The Smart Grid Cyber Security - APAC conference is coming together rapidly. If you live and work on that side of the Pacific, or enjoy  really long flights, this may be for you.

Here are basic details:
  • Where: Singapore (Venue is TBD)
  • When: July 11 and 12, 2011
  • Sample of  confirmed attendees so far: CSIRO Australia, CLP Power Hong Kong, Japan Science and Technology Agency
  • Conference web site
As you'll see, the call for topics/papers is still open, so if you have something you'd like to say or show, better hurry up and submit it to the organizers.

And while we're at it, pondering the emergence of the Smart Grid in Asian markets, HERE's a brand new report from Pike Research on the subject.

Thursday, February 10, 2011

I Don't Want to Talk about Night Dragon ...

... but looks like I have to. We're still digesting the energy sector cyber security implications of 2010's attacks on Google + 30 (confusingly named Operation Aurora), Stuxnet and Wikileaks, and now we've got another whopper.

Looks like energy sector, or more specifically, oil & gas companies were the primary target. Here's a short synopsis of the attack techniques used, which begin of course, with one of the most common (and easy to defend) attack vectors:
The attacks began with a SQL-injection technique, which compromised external web servers. Common hacking tools were then used to access intranets, giving attackers access to internal servers and desktops. Usernames and passwords were then harvested and after disabling Internet Explorer proxy settings, hackers were able to establish direct communication from infected machines to the Internet.
In my experience, oil & gas co's generally have more budget to spend on security protections than their electric utility brethren. So if they don't have their cyber houses in order yet against simple stuff like this, then it's quite likely that the same attacks would have breached electric co's as well.

Click HERE for a short article on this, and HERE for the more detailed report by McAfee.

Tuesday, February 8, 2011

Will Stuxnet be a Learning Opportunity?

Here's a guest post from my IBM colleague Brooks La Gree, with whom I attended the big Distributech conference in sunny San Diego last week. He and I have been talking about Stuxnet and its potential impact on the energy sector since it first surfaced, or rather, first surfaced on this blog, back in July 2010. Here's Brooks:

During congressional testimony on the Stuxnet worm in November 2010, it was recommended that Stuxnet should be leveraged as a learning opportunity to better prepare the industry for things to come. So bearing this in mind, I attended my first Distributech with the question "how many utilities and energy industry players are aware of Stuxnet?"

Granted, the implications of Stuxnet are subject to interpretation, but the fact remains this virus penetrated and reprogrammed parts of the critical infrastructure. Since this is such a watershed event, I’d sort of pictured alarm bells and flashing lights going off in utilities everywhere. So during Distributech I conducted a non-scientific poll to see how many utility employees had heard of Stuxnet. Here's what I found:
  • Of at least 75 people I spoke to directly, approximately ten knew of Stuxnet, with three or four aware of its potential implications to critical infrastructure
  •  The audience of the "SCADA and Network Infrastructure" panel session was asked by a panelist as to who was familiar with Stuxnet, and of approximately 200 participants, around 30 or so raised their hands 
While I know from experience there are dedicated groups of very smart people working across the industry and government to address the issues surfaced by Stuxnet, the answer to my question in general appears to be "not that many".  However, I remain optimistic that as the security conversation continues to gain traction at events and conferences, awareness and knowledge will reach the necessary critical mass. Never before has the saying "knowledge is power" been so apropos.

Monday, February 7, 2011

Grid Cyber Security and the Kill Switch Concept

Egypt's recent Internet "full stop" got us started, and now it seems like esoteric electrical grid security concepts are slowly transitioning from obscurity to mainstream, via a bunch of new bills on Capitol Hill and a provocative Scientific American article. 

In a recent SciAm piece titled "What Is the Best Way to Protect U.S. Critical Infrastructure from a Cyber Attack?", we learn that Senator Lieberman's "Protecting Cyberspace as a National Asset Act" is vying with last year's Grid Act, and as interpreted by James Lewis, senior fellow at CSIS, is going several steps further:
The central part is that voluntary action is no longer sufficient for national security and that the private sector cannot secure their networks against advanced opponents.
OK, I've got to throw the first flag here. Show me evidence that the public sector is better at cyber security than the private sector. Good luck with that. In my opinion while there's some value in discussing the merits of voluntary vs. enforced cyber security, we're not going sleep better by having private sector security leadership emulate their government counterparts.

And then there's this, again from Mr. Lewis:
We're in a transitional moment, and this debate over an Internet kill switch is part of that. You have the old-school Internet thinkers who are wedded to this pioneering vision that we have to keep the Internet open and unstructured because that will empower innovation. People really believe that. People also believe in flying saucers, and these ideas are about equal.
Wow. No offense is intended, but unless he was seriously misquoted, Mr. Lewis is equating one of the key engines of our economy, innovation, with the amusing yet unhinged true believers in Close Encounters of the Third Kind, and that makes him seem, to me at least, a somewhat less-than-serious scholar. My second flag is thrown. 

Once again, mainstream media is aiding and abetting alarmists who want the US rank and file to believe that we're just moments away from a complete cyber meltdown. In this case, it's more than a little disturbing as I've always viewed SciAm as the sober middle ground between heavy duty, peer-reviewed science journals and more overtly entertaining, though also more sensationalist publications like Popular Science and Popular Mechanics. 

For the record let me repeat: in the electric sector we have a lot of work to do re: shoring up cyber security, and (mainly) we're doing it. We're far from bullet proof, yet the work proceeds, and every day we learn a little more and make our systems a little better at weathering cyber storms. Sometimes I wish that story would command half as much attention as one's like these.

Hat tip to cyber security colleague Dave Hemsath (linchpin of the Boston-Austin connection) for this.

Thursday, February 3, 2011

DOE, NIST, and NERC Announce a Long Overdue Collaboration on Smart Grid Security

So happy to see this come to fruition. From Tuesday's press release:
Traditional cyber security approaches for electric utilities are segmented, with different approaches for control systems and information systems. This has resulted in cyber security requirements that are overly restrictive in some cases, and not restrictive enough in others. At best, requirements are overlapping, but more often result in gaps in cyber security coverage. A common approach is needed to address the unique cyber security risks that a nation-wide smart grid will pose.
Began as a conversation late last year among two friends trying to figure out how to break through some logjams, one named Dave Dalva, online and then over coffee one morning in DC.

Click HERE for full statement, and recommend you stay tuned on this.

Wednesday, February 2, 2011

January was a Rough Start for 2011 Smart Grid Security Regulation Report Cards


Hopefully the baby Smart Grid will do better in its security courses later this year and next, but it scored about a D average on its first two big US Federal tests of the year when results were reported last month.

First came the Government Accountability Office (GAO) report titled “Electricity Grid Modernization: Progress Being Made on Cybersecurity Guidelines, but Key Challenges Remain to be Addressed” which highlighted security shortcomings in the 1.0 version NISTIR 7628. Much of what it reported was not new news to those of us in the community, as it pointed out what NIST had already revealed itself: that it hadn’t been able to address every topic it originally intended by the 1 September 2010 deadline, and was working now to remedy the situation. One of these topics included strategies to defend against combined cyber and physical attacks. It also critiqued FERC’s lack of authority to regulate grid security beyond large generation and transmission systems.

Later in January, the Department of Energy’s IG office issued its report “Federal Energy Regulatory Commission's Monitoring of Power Grid Cyber Security” in which it found FERC cyber security standards (as implemented by NERC) and overall approach for the regulating the national grid quite lacking, saying current standards "were not adequate to ensure that systems-related risks to the nation’s power grid were mitigated or addressed in a timely manner." The IG also gave FERC a bit of a break when it acknowledged, "We found that these problems existed, in part, because the Commission had only limited authority to ensure adequate cyber security over the bulk electric system." 

My take away? Both of these reports are telling us what we already know: that the current Federal regulatory approach and authority over grid security matters is far from optimal, and that no one, especially Congress, is quite sure yet what to do about it. Meanwhile, as seen here at the mighty Distributech Conference in San Diego, the Smart Grid marches on just the same.