Skip the navigation
News

Report highlights Smart Grid security vulnerabilities

Strategy needed to address security and privacy issues, NIST report says

By Jaikumar Vijayan
September 29, 2009 08:17 PM ET

Computerworld - A cybersecurity coordination task force released a report this week that assesses various security and privacy requirements for the U.S. Smart Grid, as well as strategies needed to address them.

The 256-page document was compiled by the task force, comprised of individuals from the government, industry, academia and regulatory bodies, and led by the National Institutes of Standards and Technology (NIST). Now open for comment, NIST will release a final version of the document in March 2010 describing a overall Smart Grid security architecture and security requirements.

The draft report highlights the need for planners to address threats that could potentially allow attackers to penetrate the smart grid, gain access to control software, and alter load conditions to cause widespread disruptions. Cybersecurity strategies for protecting the smart grid need to address not only deliberate attacks but also inadvertent compromises resulting from user errors, equipment failures and buggy software, the report said.

Released as part of the report was a Privacy Impact Analysis that examines some of the privacy implications of establishing a smart grid for power distribution.

A smart grid uses digital technology to transmit, distribute and deliver power to consumer in a more reliable and efficient manner than traditional electricity systems. A key component of the smart grid is the real-time, two-way communication it establishes between consumers and power distributors for tracking energy use and enabling smarter consumption and pricing. Current plans call for nearly 17 million two-way connected smart meters to be installed in U.S. homes over the next few years.

While proponents of a smart grid have touted its potential to improve the electricity system, others have expressed concern about their susceptibility to cyber attacks and inadvertent compromises. Many are concerned that the software, wireless sensor networks and the Advanced Metering Infrastructure (AMI) networks that go into a smart grid present too many points of vulnerability into the network.

In June, security consultancy IOActive Inc. disclosed how its researchers had tested Smart Grid components for security vulnerabilities and had discovered several that could allow attackers to access the network and cut off power. IOActive researchers showed how attackers could spread malware through the network and remotely shut down power to consumers by taking advantage of flaws in the metering devices.

The NIST report is an attempt to assess such threats. The vulnerabilities that are listed in the report were gathered from existing research and security documents including NIST's own guide to industrial control systems security and the Open Web Application Security Project (OWASP) vulnerabilities list.

It looks at vulnerabilities that can arise during the operation a smart grid as well as on problems such as authenticating and authorizing users to substations, key management for meters, and intrusion detection for power equipment. The report also considers vulnerabilities arising from inadequate patch, configuration and change management processes, weak access controls, and lack of risk assessment, audit, management and incident response plans.

Vulnerabilities associated with bad software coding practices, including input validation errors and user authentication errors, can also pose a risk to the integrity of a smart grid, the report said.

The real-time, two-way communication between consumers and suppliers in a smart grid also raises several privacy concerns, the NIST report noted. One major issue that needs to be addressed is the data that will be collected automatically from smart meters. There needs to be more of an understanding of how that data will be distributed and utilized throughout the smart grid system, the report said.

"In the current operation of the electric grid, data taken from meters consists of basic data usage readings required to create bills," the report said. "Under a smart grid implementation, meters can and will collect other types of data," some of which could be personally identifiable information that needs to be protected with strong privacy controls it said.

Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs