Security risk to 'smart grids'

Malware could be used to takeover smart grids, security experts have warned.

Just when you thought we might be getting a handle on internet viruses, worms and other malware, here comes an electrical "smart grid" that could be hacked with even more devastating consequences, warn security experts familiar with the new systems.

Composed of a dense IT network set up to monitor everything from individual appliances to entire power plants, the energy smart grid promises to bring unparalleled efficiency to the American electrical system.

Advertisement - Article continues below

"Boosted in large part by $4.5 billion (3.05 billion) in economic stimulus funding, the smart grid offers huge potential both for significant energy conservation and for chilling the 1960s grid technology and bring it into the 21st century," said Josh Pennell, president and chief executive of IOActive, a security service firm based in Seattle that verified critical flaws in the next-generation energy infrastructure.

But because security concerns are being voiced early, "there's still plenty of opportunity to bake security in as we move forward," he said.

"Security Development Lifecycle, or SDL, can help solve these problems before they get out of control."

Without such precautions now, however, IOActive warns in a report to the Committee on Homeland Security that an attacker with a modicum of engineering and software knowledge plus perhaps $500 in equipment and materials could "take command and control of the AMI (advanced meter infrastructure), allowing for the en masse manipulation of service to homes and businesses".

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

If security isn't addressed in the design and implementation of the smart grid from the start, the report says it may be too expensive to address security issues after millions of the devices already are deployed.

Researchers at IOActive created a worm that was able to spread from one automated meter to another over the wireless network used to connect them. Once the worm spread through the smart grid, the researchers would have been able to control, and even shut down, the entire electrical grid.

Because of the sensitivity of much of the material in IOActive's report, Pennell said the company would not release the entire document. Instead, only excerpts of greatest use for security planning would be released.

Featured Resources

Successful digital transformations are future ready - now

Research findings identify key ingredients to complete your transformation journey

Download now

Cyber security for accountants

3 ways to protect yourself and your clients online

Download now

The future of database administrators in the era of the autonomous database

Autonomous databases are here. So who needs database administrators anymore?

Download now

The IT expert’s guide to AI and content management

Your guide to the biggest opportunities for IT teams when it comes to AI and content management

Download now
Advertisement

Recommended

Visit/security/cyber-security/355267/zoom-hires-ex-facebook-cso-to-boost-platform-security
cyber security

Zoom hires ex-Facebook CSO Alex Stamos to boost platform security

8 Apr 2020
Visit/security/vulnerability/355236/hp-support-assistant-flaws-leave-windows-devices-open-to-attack
vulnerability

HP Support Assistant flaws leave Windows devices open to attack

6 Apr 2020
Visit/security/cyber-security/355234/safari-bug-let-hackers-access-cameras-on-iphones-and-macs
cyber security

Safari bug let hackers access cameras on iPhones and Macs

6 Apr 2020
Visit/software/video-conferencing/355229/zoom-we-moved-too-fast
video conferencing

Zoom CEO admits company "moved too fast" as privacy issues mount

6 Apr 2020

Most Popular

Visit/mobile/mobile-phones/355239/microsofts-patent-design-reveals-a-mobile-device-with-a-third-screen
Mobile Phones

Microsoft patents a mobile device with a third screen

6 Apr 2020
Visit/security/cyber-security/355271/microsoft-gobbles-up-corpcom-domain-to-keep-it-from-hackers
cyber security

Microsoft gobbles up corp.com domain to keep it from hackers

8 Apr 2020
Visit/server-storage/servers/355254/a-critical-flaw-in-350000-microsoft-exchange-remains-unpatched
servers

A critical flaw in 350,000 Microsoft Exchange remains unpatched

7 Apr 2020