Skip the navigation

Blaster worm linked to severity of blackout

Exposure of communications flaws heightens concerns about security of the U.S. power grid

By Dan Verton
August 29, 2003 12:00 PM ET

Computerworld - WASHINGTON -- The W32.Blaster worm may have contributed to the cascading effect of the Aug. 14 blackout, government and industry experts revealed this week.
On the day of the blackout, Blaster degraded the performance of several communications lines linking key data centers used by utility companies to manage the power grid, the sources confirmed.
"It didn't affect the [control] systems internally, but it most certainly affected the timeliness of the data they were receiving from other networks," said Gary Seifert, a researcher at the U.S. Department of Energy's Idaho National Engineering and Environmental Laboratory in Idaho Falls, referring to flow-control and load-balancing data that's transmitted over public telecommunications networks. "It certainly compounded the problems" relating to the congestion of key communications links used by utilities to coordinate contingency efforts, Seifert added.
The inability of critical control data to be exchanged quickly across the grid could have hampered the operators' ability to prevent the cascading effect of the blackout, he said. Seifert stressed, however, that no one is certain at this point what caused the blackout.
A former Bush administration adviser who has consulted with the U.S. Department of Homeland Security on the power grid issue said the Blaster worm also hampered the ability of utilities in the New York region to restore power in a more timely manner because some of those companies were running Windows-based control systems with Port 135 open - the port through which the worm attacked systems.
Utilities that responded to requests for comment for this article said they weren't adversely affected.
Carol Murphy, vice president of government affairs at the New York Independent System Operator, acknowledged that Blaster affected the utility but said the problem was handled quickly, with no impact on power restoration operations. Joe Petta, a spokesman for Consolidated Edison Company of New York Inc., said there were "absolutely no computer-related problems of any sort that delayed our restoration effort."
The control systems referred to by Seifert, also known as supervisory control and data acquisition (SCADA) systems, are used to manage large industrial operations, such as the natural gas and electric power grids. They're often based on Windows 2000 or XP operating systems and rely on commercial data links, including the Internet and wireless systems, for exchanging information.
Scott Charney, chief security strategist at Microsoft Corp., said that Blaster raised a security and network performance issue for all Microsoft customers and that there was nothing unique about the electric power industry.
Joe Weiss, a control system expert and executive consultant at Cupertino, Calif.-based Kema Consulting Inc., said that in the Blaster case, the power grid fell victim to a worm that attacked the communications infrastructure.
However, the control systems themselves are also at risk.
Current and former energy industry executives, as well as the former Bush administration security adviser, told Computerworld on condition of anonymity that the January outbreak of the Slammer worm affected the real-time control environment of "several" utility companies around the country.
One of those companies was Akron, Ohio-based FirstEnergy Corp. Although FirstEnergy has said publicly that Slammer didn't infect any of the control systems at its Davis-Besse nuclear power plant in Oak Harbor, Ohio, knowledgeable sources said the worm did cause disruptions. However, the plant was in "cold shutdown maintenance mode" and wasn't producing electricity at the time, the sources said. FirstEnergy didn't respond to a request for comment.
"Because Slammer didn't cause any loss of power, it wasn't reported by the utilities that were infected," said an industry executive who had discussions with utility officials.
A spokesperson for the North American Electric Reliability Council (NERC), which is helping to spearhead a task force to study the causes of last month's blackout, declined to comment on the role the Blaster worm may have played. However, a NERC report dated June 20, 2003, shows that the Slammer worm had a significant impact on some utilities.
In one case, a server on a control center LAN running Microsoft's SQL Server wasn't patched, according to the report. "The worm ... apparently [migrated] through the corporate networks until it finally reached the critical SCADA network via a remote computer through a VPN connection," the report states. As a result, "the worm propagated, blocking SCADA traffic."
In a second case documented by Princeton, N.J.-based NERC, a frame-relay-based control network using Asynchronous Transfer Mode "became overwhelmed by the worm, blocking SCADA traffic."









Read more about Business Continuity in Computerworld's Business Continuity Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Business Continuity White Papers
An Interactive Guide: Bring Your Own Device
BYOD presents significant security and management challenges to IT departments who want to take advantage of the trend, but still protect corporate assets....
Malware Security Report: Protecting Your Business, Customers, and the Bottom Line
Protect your business and customers by understanding the threat from malware and how it can impact your online business. This paper highlights how...
Security Predictions for 2012
With all of the crazy 2011 security breaches, exploits and notorious hacks, what can we expect for 2012? Last year's Websense Security Labs...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
All Business Continuity White Papers
Business Continuity Webcasts
Data Protection and Information Governance
Today, legal hold and information governance are increasingly becoming drivers for data protection. However, few organizations knows what information they have, where to...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Business Continuity Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs