Skip to navigation
Latest News

Cyber attacks on utilities tipped to soar

Panic button

By Stewart Mitchell

Posted on 8 Oct 2010 at 09:12

Cyber-attacks on physical systems such as electricity grids and hospitals are likely to increase in number and sophistication over the coming year, a report has said.

The Emerging Cyber Threats Report for 2011 from the Georgia Tech Information Security Center's said attackers were better funded and more determined than ever before and that it was inevitable some would succeed.

“In recent years, we have seen an emerg­ing environment of persistence on the part of attackers,” said David Batz, cyber and infrastructure security manager at the Edison Electric Institute.

“Whether it is a representative from a competing business, someone with strong philosophical or religious motives, or a representative of a nation-state, there are individuals out there with the determination and resources needed to make a concerted investment in launching whatever attacks they can to realise their objectives.”

The more proliferation there is of intelligent metering and energy usage, the more opportunities there are for attackers

Citing unconfirmed suspicions that last year's massive power failure in Brazil was the result of cyber attacks, Batz said grids would be increasingly targeted over the coming year as they became more reliant on smart metering systems.

This also applied, the report said, to water and gas systems, which are rolling out smart meters and advanced metering infrastructure. “The more proliferation there is of intelligent metering and energy usage, the more opportunities there are for attackers,” said Heath Thompson, CTO at metering company Landis+Gyr.

Hospitals also at risk

The report also claimed that hospital infrastructure could be caught in the crossfire - if not via a direct attack, then through unpatched software on critical systems.

“Hospitals and other medical facilities operate under a very dif­ferent regulatory framework than in other industries,” said GTISC researcher David Dagon.

“If an infected device is used in patient care, it may not be pos­sible to patch it the same way as other systems because the FDA may have specific guidelines for making changes to devices that interact with patients," he said. “Some facilities may choose not to patch known infected systems, which can cause a whole new set of issues.”

The researchers said they had already seen an upsurge in attacks hitting hospital hardware, including radiology systems.

According to security firm SecureWorks, hacker attacks launched against their healthcare clients nearly doubled during the last quarter of 2009, from an average of 6,587 a day per healthcare client earlier in the year to 13,379 attacks a day.

Subscribe to PC Pro magazine. We'll give you 3 issues for £1 plus a free gift - click here

From around the web

User comments

I don't understand how this is even an issue...

As worrying as all this is, I can't help wondering why half these systems are online at all. Surely there's no need?

OK, I understand the rational behind energy providers wanting to put their systems online in the case of 'smart-metering', but, if it's going to be putting the entire system at risk it seems ludicrous to go ahead with it, just in order to try and gain a few percentage points in economy and efficiency.

I do think our energy security should be the primary concern, and if the utility providers insist on ploughing ahead with these systems regardless then I do think our (generally negligent) regulators should be insisting otherwise.

As for healthcare, again, why are such systems online in the first place? Surely the best firewall of all is 'unplugged'?

If a hospital wants to offer things such as websites to patients, fine, but surely they should be on an entirely separate system and not just part of the main hospital network?

Unless I'm missing some glaringly obvious points, isn't the solution to most of this relatively straightforward?

By Mr_John_T on 9 Oct 2010

Leave a comment

You need to Login or Register to comment.

(optional)

advertisement

More From PC Pro
Latest Blog Posts Subscribe to our RSS Feeds
Latest ReviewsSubscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010
 
 

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.