Blaster Worm Linked to Severity of Blackout
Exposure of communications flaws heightens concerns about security of the U.S. power grid
Computerworld - WASHINGTONThe W32.Blaster worm may have contributed to the cascading effect of the Aug. 14 blackout, government and industry experts revealed last week.
On the day of the blackout, Blaster degraded the performance of several communications lines linking key data centers used by utility companies to manage the power grid, the sources confirmed.
"It didn't affect the [control] systems internally, but it most certainly affected the timeliness of the data they were receiving from other networks," said Gary Seifert, a researcher at the U.S. Department of Energy's Idaho National Engineering and Environmental Laboratory in Idaho Falls, referring to flow-control and load-balancing data that's transmitted over public telecommunications networks. "It certainly compounded the problems" relating to the congestion of key communications links used by utilities to coordinate contingency efforts, Seifert added.
The inability of critical control data to be exchanged quickly across the grid could have hampered the operators' ability to prevent the cascading effect of the blackout, he said. Seifert stressed, however, that no one is certain at this point what caused the blackout.
A former Bush administration adviser who has consulted with the U.S. Department of Homeland Security on the power grid issue said the Blaster worm also hampered the ability of utilities in the New York region to restore power in a more timely manner because some of those companies were running Windows-based control systems with Port 135 openthe port through which the worm attacked systems.
Utilities that responded to requests for comment for this article said they weren't adversely affected.
Carol Murphy, vice president of government affairs at the New York Independent System Operator, acknowledged that Blaster affected the utility but said the problem was handled quickly, with no impact on power restoration operations. Joe Petta, a spokesman for Consolidated Edison Company of New York Inc., said there were "absolutely no computer-related problems of any sort that delayed our restoration effort."
The control systems referred to by Seifert, also known as supervisory control and data acquisition (SCADA) systems, are used to manage large industrial operations, such as the natural gas and electric power grids. They're often based on Windows 2000 or XP operating systems and rely on commercial data links, including the Internet and wireless systems, for exchanging information.
Scott Charney, chief security strategist at Microsoft Corp., said that Blaster raised a security and network performance issue for all Microsoft customers and that there was nothing unique about the electric power industry.
Joe Weiss, a control system expert and executive consultant at Cupertino, Calif.-based Kema Consulting Inc., said that in the Blaster case, the power grid fell victim to a worm that attacked the communications infrastructure.
- Mobile First: Securing Information Sprawl Learn how the partnership between Box and MobileIron can help you execute a "mobile first" strategy that manages and secures both mobile apps...
- Cybersecurity Imperatives: Reinvent your Network Security The Rise of CyberSecurity
- Surescripts Case Study- Securing Keys and Certificates Surescripts implemented Venafi's Trust Protection Platform™ to secure digital keys and certificates, ensure the privacy and confidentiality of electronic clinical information for its...
- Ponemon 2014 SSH Security Vulnerability Report According to research by the Ponemon Institute, 3 out of 4 enterprises have no security controls in place for SSH which leaves organizations...
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities.
- Deep Dive into Advanced Networking and Security with Hybrid Cloud Security and networking are among the top concerns when moving workloads to the cloud. VMware vCloud® Hybrid Service™ enables you to extend your... All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!