IDG News Service - DUSSELDORF, Germany -- The arsenal of modern weapons that terrorists might someday use to disrupt power grids, gas lines and other parts of the nation's critical infrastructure includes conventional weapons as well as bits and bytes -- in other words cyberterror attacks. The cyberthreat to the electricity we use and the water we drink is real, experts say, but there's no need to panic -- at least not yet.
"Our research shows that terrorist groups are definitely interested in attacking critical infrastructures," said Eric Byres, research director at the Internet Engineering Laboratory of the British Columbia Institute of Technology in Burnaby. "The good news is that we don't think they have the technical ability yet -- in other words, the combined IT and control system skills needed to penetrate a utility network. The bad news is that they're beginning to acquire some of these skills."
Confidential documents about supervisory control and data acquisition (SCADA) systems, for instance, have been found in al-Qaeda hiding places in Afghanistan, while the Irish Republican Army has said it plans cyberattacks on crucial supply systems, according to Justin Lowe, principal consultant with PA Consulting Group.
Equally disturbing is that talented hackers in many parts of the world are willing to peddle their expertise for the right price or political cause, according to DK Matai, chairman of Mi2g Ltd., a London security service provider. "We have evidence of Russian hackers selling their skills to radical Islamic groups," he said.
Few, if any, of the industrial control systems used today were designed with cybersecurity in mind because hardly any of them were connected to the Internet. For the most part, these companies viewed their infrastructures as secure from cyberattacks because of their isolated structure.
However, utilities and factories are now using the Internet to carry SCADA messages from an increasing number of Web-enabled, remote-control systems, said Joe Weiss, who served as security director at the Electric Power Research Institute in Palo Alto, Calif., and its Enterprise Infrastructure Security Initiative before joining KEMA Consulting.
Not only that, but also many of their "private" networks now are built with the help of competitively priced fiber-optic connections and transmission services provided by telecom companies, which have become the frequent target of cyberattacks.
Last year, a power utility crash that was caused indirectly by the Slammer worm paralyzed a leased telecom service. For its SCADA communications network, the utility used a frame-relay service, which a carrier provided over its ATM ( Asynchronous Transfer Mode) backbone. The ATM network was overwhelmed by the worm, blocking SCADA traffic to substations.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Acxiom Case Study This case study, which focuses on Acxiom, explores how the company was able to secure employee data, reduce migration costs and boost productivity...
- Windows® XP Migration: Protect and Secure Critical Data With the end of the Microsoft Windows XP operating system's lifecycle on April 8, 2014, businesses are faced with the decision to migrate...
- Enhancing Application Protection and Recovery with a Modern Approach to Snapshot Management This CommVault Business Value and Technology White Paper explains how Simpana IntelliSnap® Recovery Manager can make your application recovery fast and reliable.
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts