ArabianBusiness.com - Middle East Business News
Saturday, 21 November 2009 15:31 UAE time

YOUR DIRECTORY /

| Share |

Cyber watch

by ArabianBusiness.com staff writer  on Tuesday, 16 December 2008

Utilities are looking to install software to protect key infrastructure from threats to network security.

Cracking a power company network and gaining access that could shut down the grid is simple.

So says Ira Winkler, a penetration-testing consultant, who along with his  team of  experts took a day to set up the tools they needed then launched their attack, which paired social engineering with corrupting browsers on a power company's desktop computers.

Story continues below
advertisement

SCADA systems are inherently insecure because they are software running on standard operating systems on standard server hardware, making them subject to all the vulnerabilities.- Ira Winkler, penetration testing consultant.

By the end of a full day of the attack, they had taken over several machines, giving the team the ability to hack into the control network that was overseeing power production and distribution.

Winkler says he and his team were hired by the US-based utility, which he would not name, to test the security of its network and the power grid it oversees. The company called off the test after the team took over the machines.

"We had to shut down within hours," Winkler says, "because it was working too well already. We more than proved that they were royally screwed."

The problem is pervasive across the power industry, he says, because of how power company networks evolved. Initially their supervisory, control and data acquisition (SCADA) networks were built as closed systems, but over time intranets and internet access have been added to the SCADA networks.

Individual desktops have internet access and access to business servers as well as the SCADA network, making the control systems subject to internet threats. "These networks aren't enclosed anymore. They've been open for more than a decade," Winkler explains.

Deep penetration

The penetration team started by tapping into distribution lists for SCADA user groups, where they harvested the e-mail addresses of people who worked for the target power company. They sent the workers an e-mail about a plan to cut their benefits and included a link to a web site where they could find out more. When employees clicked on the link, they were directed to a web server set up by Winkler and his team.

The employees' machines displayed an error message, but the server downloaded malware that enabled the team to take command of the machines. "Then we had full system control," Winkler says. "It was effective within minutes."

Winkler says SCADA systems are inherently insecure because they are software running on standard operating systems on standard server hardware, making them subject to all the vulnerabilities of those systems.

Fran Howarth, principle analyst at information technology analysts Quocirca concurs. "It is a no-brainer that terrorist are going to go after utilities. You can knock out an entire economy for a serious amount of time and you can cause enormous economic damage in the process. Our research shows that utilities in the US, the UK and Germany have been waking up to this threat and are active in writing their own specific software, but elsewhere very little appears to be happening," she says.

In the UK, RWE, Europe's second-largest power generator, has stepped up security for the systems that control operations at its UK power stations in response to UK government guidelines for members of the critical national infrastructure. RWE bought a new network security system from Industrial Defender sits on top of the SCADA.

Growing threat

Previously, power generators ran stand alone SCADA systems but privatisation meant that, to be competitive, the firm's energy trading systems had to link into the real-time systems used to control the generating turbines. This opened the SCADA network to threats such as viruses and hackers.

Power companies' desire to not risk interrupting service with software upgrades that could improve security perpetuates the inherent weaknesses in utility network systems in the Middle East, says Winkler.

"I tend to think that the systems in the Middle East are inherently vulnerable based on what I've seen of SCADA systems elsewhere in the world. The problem is that there is no financial incentive to do anything and utilities also don't want to acknowledge that issues need to be addressed and are hesitant to admit that problems exist."

"If something does happen then they claim that it's the work of some evil cyber-genius...you have knights and dragons and when bad things happen people tend to think it's because the dragon is extremely powerful when in fact the dragon can be clueless," he adds.

Risk assessment

Winkler believes the threat that hackers pose to utilities in the Middle East is particularly acute. "All military and intelligence agencies in the region are looking at this; I would be very disappointed if they weren't. Looking at Dubai specifically and the UAE, Iran has a chip on its shoulder and it has a very good cyber capability. I would imagine that Iranian intelligence has a few guys trying to subvert targets of interest and that would include utilities, the power systems of radar sites and so on. Al Qaeda is also very active in using computers, so there is the potential for serious damage," he says.

Jeff Bardin, director of risk management at security consultants EMC, believes the threat to utilities is more likely to come from a hostile state rather than from a terrorist group. "The utilities in the GCC are unlikely to be threatened by groups such as Al Qaeda as they use the internet as a tool for communication, fund-raising, stealing credit cards and recruiting, the internet is the main avenue for getting its message across. An attack on utilities would have to include quite a botnet, similar to the one Russia used earlier this year to attack the government networks in Estonia and Georgia, I don't think any terrorist group has that capability at present," says Bardin.


| Share |


READERS' COMMENTS

Disclaimer: The views expressed here by our readers are not necessarily shared by ArabianBusiness.com or its employees.
Cyber Watch
Posted by Sameh Hassan, Dubai, UAE on Tuesday 16 December 2008 at 23:18 UAE time


I totally Agree with what writers mentioned in the article. Dr Rocky Termanini has pointed a very important point regarding the infrastructure of the UAE. Lately the UAE witnessed a true example of massive hacking the UAE into the banking systems Thousands of fraud cases of credit cards have been reported. None of the banks declares how it happened and how much the losses. They kept silence because they are afraid to get the blame of their lack of information security systems or the skilled cyber security agents. I believe the and Teleco/ISP companies who runs the local cyber space in UAE should play a role and deploy an early warning system against these harmful cyber attacks and for the police to have a cyber crime centers to report such cases.

Click here to post a comment


Add your Comment
All posts are sent to the administrator for review and are published only after approval. ArabianBusiness.com reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Arabian Business would like to point out that only comments relevant to the story will be published. Any containing personal insults or inappropriate language will not be approved.
Name *
Remember me on this computer
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Notify me of further comments


Please click post only once - your comment will not be published immediately.


MORE FROM ARABIANBUSINESS.COM

From  Current Issue

SHARE PRICE CHECK

RELATED STORIES

EMC Corporation
| 96 stories
  1. Virtual reality
  2. Full capacity
  3. EMC supercharges virtual tape system
Secure Computing
| 5 stories
  1. Bringing IT mobility to the workforce
  2. Secure at all layers

RELATED LINKS

  1. Secure Computing»

 EMAIL ALERTS

  1. EMC Corporation

  2. Secure Computing

  3. Technology


CURRENCY CONVERTOR

Tell us your story

READER COMMENTS

  1. Somali pirates free UAE-owned cargo ship 02
    21 Nov ' 09 at 07:58
    In the old days pirate ships were blown out of the water as soon as spotted.Now they have to wait until they attack a ship and then...   More  »
  2. UAE announces Eid and National Day holidays 01
    20 Nov ' 09 at 15:56
    Eid and National Day are two great occassions and very close to each other. It would be a great act for the UAE authorities to extend...   More  »
  3. Where have all the optimists gone? 01
    20 Nov ' 09 at 16:54
    Dubai unfortunate is not more in fashion, the bubble was big , the growing went fast and the down turn even faster.Many of my clients...   More  »

Read all user comments >

Gitex 2009

MORE FROM ARABIANBUSINESS.COM