Cyber attacks on utilities tipped to soar
By Stewart Mitchell
Posted on 8 Oct 2010 at 09:12
Cyber-attacks on physical systems such as electricity grids and hospitals are likely to increase in number and sophistication over the coming year, a report has said.
The Emerging Cyber Threats Report for 2011 from the Georgia Tech Information Security Center's said attackers were better funded and more determined than ever before and that it was inevitable some would succeed.
“In recent years, we have seen an emerging environment of persistence on the part of attackers,” said David Batz, cyber and infrastructure security manager at the Edison Electric Institute.
“Whether it is a representative from a competing business, someone with strong philosophical or religious motives, or a representative of a nation-state, there are individuals out there with the determination and resources needed to make a concerted investment in launching whatever attacks they can to realise their objectives.”
The more proliferation there is of intelligent metering and energy usage, the more opportunities there are for attackers
Citing unconfirmed suspicions that last year's massive power failure in Brazil was the result of cyber attacks, Batz said grids would be increasingly targeted over the coming year as they became more reliant on smart metering systems.
This also applied, the report said, to water and gas systems, which are rolling out smart meters and advanced metering infrastructure. “The more proliferation there is of intelligent metering and energy usage, the more opportunities there are for attackers,” said Heath Thompson, CTO at metering company Landis+Gyr.
Hospitals also at risk
The report also claimed that hospital infrastructure could be caught in the crossfire - if not via a direct attack, then through unpatched software on critical systems.
“Hospitals and other medical facilities operate under a very different regulatory framework than in other industries,” said GTISC researcher David Dagon.
“If an infected device is used in patient care, it may not be possible to patch it the same way as other systems because the FDA may have specific guidelines for making changes to devices that interact with patients," he said. “Some facilities may choose not to patch known infected systems, which can cause a whole new set of issues.”
The researchers said they had already seen an upsurge in attacks hitting hospital hardware, including radiology systems.
According to security firm SecureWorks, hacker attacks launched against their healthcare clients nearly doubled during the last quarter of 2009, from an average of 6,587 a day per healthcare client earlier in the year to 13,379 attacks a day.
From around the web
I don't understand how this is even an issue...
As worrying as all this is, I can't help wondering why half these systems are online at all. Surely there's no need?
OK, I understand the rational behind energy providers wanting to put their systems online in the case of 'smart-metering', but, if it's going to be putting the entire system at risk it seems ludicrous to go ahead with it, just in order to try and gain a few percentage points in economy and efficiency.
I do think our energy security should be the primary concern, and if the utility providers insist on ploughing ahead with these systems regardless then I do think our (generally negligent) regulators should be insisting otherwise.
As for healthcare, again, why are such systems online in the first place? Surely the best firewall of all is 'unplugged'?
If a hospital wants to offer things such as websites to patients, fine, but surely they should be on an entirely separate system and not just part of the main hospital network?
Unless I'm missing some glaringly obvious points, isn't the solution to most of this relatively straightforward?
By Mr_John_T on 9 Oct 2010 ![]()
advertisement
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- Why you have to be left in the dark on OS patches
- Publishing your email address isn't a security disaster
- Why antivirus is fighting a losing battle in your office
- Four year olds used to steal their parents' data
- An acceptable use policy for your kids
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
advertisement
