Foreign cyber attack hits US infrastructure: expert
November 19, 2011
A man uses a laptop computer at a wireless cafe. A cyber strike launched from outside the United States hit a public water system in the Midwestern state of Illinois, an infrastructure control systems expert said on Friday.
A cyber strike launched from outside the United States hit a public water system in the Midwestern state of Illinois, an infrastructure control systems expert said on Friday.
"This is arguably the first case where we have had a hack of critical infrastructure from outside the United States that caused damage," Applied Control Solutions managing partner Joseph Weiss told AFP.
"That is what is so big about this," he continued. "They could have done anything because they had access to the master station."
The Illinois Statewide Terrorism and Intelligence Center disclosed the cyber assault on a public water facility outside the city of Springfield last week but attackers gained access to the system months earlier, Weiss said.
The network breach was exposed after cyber intruders burned out a pump.
"No one realized the hackers were in there until they started turning on and off the pump," according to Weiss.
The attack was reportedly traced to a computer in Russia and took advantage of account passwords stolen during a hack of a US company that makes Supervisory Control and Data Acquisition (SCADA) software.
There are about a dozen or so firms that make SCADA software, which is used around the world to control machines in industrial facilities ranging from factories and oil rigs to nuclear power and sewage plants.
Stealing passwords and account names from a SCADA software company was, in essence, swiping keys to networks of facilities using the programs to control operations.
"We don't know how many other SCADA systems have been compromised because they don't really have cyber forensics," said Weiss, who is based in California.
The US Department of Homeland Security has downplayed the Illinois cyber attack in public reports, stating that it had seen no evidence indicating a threat to public safety but was investigating the situation.
Word also circulated on Friday that a water supply network in Texas might have been breached in a cyber attack, according to McAfee Labs security research director David Marcus.
"My gut tells me that there is greater targeting and wider compromise than we know about," Marcus said in a blog post.
"Does this mean that I think it is cyber-Armageddon time?" Marcus continued. "No, but it is certainly prudent to evaluate our systems and ask some questions."
(c) 2011 AFP
-
Software smart bomb fired at Iranian nuclear plant: experts
Sep 24, 2010 |
not rated yet |
0
-
After cyber attack, Canada unveils network changes
Aug 05, 2011 |
not rated yet |
0
-
Stuxnet-like virus points to new round of cyber war
Oct 20, 2011 |
not rated yet |
0
-
Hackers hit videogame giant Electronic Arts
Jun 24, 2011 |
not rated yet |
0
-
Lockheed Martin hit by cyber attack
May 29, 2011 |
not rated yet |
0
-
Stars containing dark matter should look different from other stars
Feb 20, 2012 |
4.5 / 5 (17) |
11
-
Physicists discover evidence of rare hypernucleus, a component of strange matter
Feb 17, 2012 |
4.7 / 5 (38) |
22
-
Fast photon control brings quantum photonic technologies closer
Feb 13, 2012 |
5 / 5 (8) |
1
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (36) |
32
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
Calculating forces involved in seesaw motion
4 hours ago
-
Writing shear and moment equations for a simple beam problem?
5 hours ago
-
Furnace Shell Spray Cooling Design
21 hours ago
-
Ways to measure the speed of a golf ball?
Feb 21, 2012
-
Water Skin Effect in Plastic Pipe
Feb 21, 2012
-
Undergraduate Engineering Physics To Graduate Aerospace Engineering
Feb 21, 2012
- More from Physics Forums - General Engineering
More news stories
Stanford research team cracks animated NuCaptcha
(PhysOrg.com) -- The research team from Stanford University, led by Elie Bursztein, that previously had cracked regular CAPTCHAs and then audio CAPTCHAs, now has also successfully cracked the animated version called NuCapt ...
Tiny, implantable medical device can propel itself through bloodstream
Someday, your doctor may turn to you and say, "Take two surgeons and call me in the morning." If that day arrives, you may just have Ada Poon to thank.
17 hours ago |
5 / 5 (9) |
8
|
Italian engineer invents floating solar panels
Rays of the winter sun bounce off gleaming mirrors on the tiny lake of Colignola in Italy, where engineers have built a cost-effective prototype for floating, rotating solar panels.
Technology / Energy & Green Tech
21 hours ago |
4.7 / 5 (6) |
5
Microsoft hits Motorola, Google with EU complaint
Microsoft on Wednesday lodged a formal complaint with the European Union's competition regulator against Motorola Mobility and its soon-to-be owner Google, saying Motorola's aggressive enforcement of patent ...
17 hours ago |
2 / 5 (1) |
2
Calif. pledges better mobile privacy disclosures
(AP) -- Mobile applications seeking to collect personal information will have to forewarn users as part of an agreement reached in California.
9 hours ago |
not rated yet |
0
Researchers build first physical 'metatronic' circuit
(PhysOrg.com) -- The technological world of the 21st century owes a tremendous amount to advances in electrical engineering, specifically, the ability to finely control the flow of electrical charges using ...
Spitzer finds solid buckyballs in space
(PhysOrg.com) -- Astronomers using data from NASA's Spitzer Space Telescope have, for the first time, discovered buckyballs in a solid form in space. Prior to this discovery, the microscopic carbon spheres ...
Faster than light neutrinos? More like faulty wiring
You can shelf your designs for a warp drive engine (for now) and put the DeLorean back in the garage; it turns out neutrinos may not have broken any cosmic speed limits after all.
Physicists surprised by disappearing and reappearing superconductivity in iron selenium chalcogenides
Superconductivity is a rare physical state in which matter is able to conduct electricity -- maintain a flow of electrons -- without any resistance. This phenomenon can only be found in certain materials at low temperatures, ...
Going up: Japan builder eyes space elevator
A Japanese construction firm claimed Wednesday it could execute an out-of-this-world plan to put tourists in space within 40 years by building an elevator that stretches a quarter of the way to the moon.
Flesh-eating bacteria inspire superglue
(PhysOrg.com) -- A bio-inspired superglue has been developed by Oxford University researchers that cant be matched for sticking molecules together and not letting go.
Nov 19, 2011
Rank: 5 / 5 (3)
Nov 19, 2011
Rank: 5 / 5 (4)
Obviously, security is being discarded in favor of convenience.
Recovering Human's question remains valid. Why would you sacrifice security on critical systems?
Nov 19, 2011
Rank: 5 / 5 (4)
"Hey bro would you pass me that wireless keyboard? and a budwieser?"
"what do you want the keyboard for?"
"well my boss says i gotta turn the pump off at 2am. Like I'm gonna stay there til 2am. As If!"
"no but so whats they keyboard for, dude?"
"Remote desktop, homie!"
*high fives*
Nov 19, 2011
Rank: 5 / 5 (6)
The vast majority of all government spending, at all levels, goes to payroll one way or another. In an age of massive budget cuts where should we get the money to fix these problems?
I dont have a solution and dont pretend to, but I think we need to start owning up to seriousness of our situation.
Nov 19, 2011
Rank: not rated yet
Nov 19, 2011
Rank: 0.8 / 5 (53)
Nice dodge. I'll ask again. Any theories dogbert?
Nov 19, 2011
Rank: not rated yet
Nov 19, 2011
Rank: 3 / 5 (2)
The fact is, they're not. We live in a complex, global economy where systems of all kinds are interconnected and where the technical expertise needed to implement and maintain systems is not readily available at all times at all locations on the planet. This doesn't appear to be a problem that will be solved any time soon.
So, can we move past that?
Nov 19, 2011
Rank: 1 / 5 (1)
Nov 19, 2011
Rank: 5 / 5 (2)
I think it can be argued that the small expenditures to create a closed network is justified when compared to the costs of open access to critical systems, but you can create virtual private networks over a public network for essentially zero extra cost.
There is really no excuse to providing open access to critical systems.
Nov 19, 2011
Rank: 5 / 5 (2)
Nov 19, 2011
Rank: 5 / 5 (2)
How much simpler it would be to fire those responsible for securing these critical applications for not doing their jobs in the first place. But then, that would be like demanding accountability in government. How crazy is THAT!
Nov 20, 2011
Rank: 5 / 5 (1)
Nov 20, 2011
Rank: 5 / 5 (1)
Actually, this is a standard operating procedure in IT departments around the world. Please take your political views elsewhere.
Nov 20, 2011
Rank: 5 / 5 (2)
You are truly out of your element here and stating misinformation. There is nothing "small" about the expenditures. There is no possible way to fix this with a closed, off-limits system.
This is not the CIA we're talking about. It's municipal water depts. and they barely have the cash to keep the water pumping.
This can not -- and will not -- be fixed in this manner.
Please move on.
Nov 20, 2011
Rank: not rated yet
Wrong. Read my posts for some enlightenment.
Nov 20, 2011
Rank: 3 / 5 (2)
Wow, you guys just aren't listening.
This is NOT NEWS.
This is NOT NEW.
This has been going on for about 20 years, and is standard operating procedure for IT departments EVERYWHERE ON THE PLANET.
Other than military, intelligence and other high-security government agencies, NO ONE has all the expertise in-house to do EVERYTHING that might come up.
We need to talk about improving security where and how it is doable, and stop wasting time talking about taking one million or more systems off-line. We are ALL hyper-connected, and it will stay that way.
Now, other than pulling the plug, what ELSE can we do?
Nov 20, 2011
Rank: not rated yet
Nov 20, 2011
Rank: 5 / 5 (2)
Nov 20, 2011
Rank: 5 / 5 (2)
Are you?
We can stop saying we cannot do anything.
If remote access is necessary and the network is small, a private network is not prohibitively expensive.
If remote access is necessary and the network much include multiple sites, a virtual private network is not difficult to set up or maintain and is essentially free. That is, since the utility can afford internet access, it can afford a virtual private network.
This story is about a water plant and a burned out water pump. Suppose it was about a dam and gates blocked open?
It is not necessary to subject our critical systems to open access. Criminal incompetence is not excusable.
Nov 20, 2011
Rank: 3.5 / 5 (6)
Interesting that the US government found hundreds of billions of dollars to bale out crooks in the housing/banking rip-off which of course led to huge bonus payouts for the culprits.
So it's merely a matter of priorities.
Nov 20, 2011
Rank: not rated yet
Yes and no. The problem described here was almost unheard of even a few years ago. But, even now, it's not really viewed as something with the potential for disastrous consequences. Incorrectly, IMO, but I don't sit on the appropriate legislative committees either. Also, there have been some dollars designated for this kind of thing. But, the majority are being spent on things like physical security at the big nuke plants.
Nov 20, 2011
Rank: 5 / 5 (1)
Nov 20, 2011
Rank: not rated yet
True, but that probably wouldn't have helped here. Remember, they got the logins from a previous hack, which might have included the VPN credentials. Rolling VPN is very expensive.
I'm not really arguing; you make a decent point. However, it's much more complicated than simply slapping a VPN on the remote access problem. Only addressing one flaw will just expose the next weakest link. There's almost no point at only addressing one aspect of security.
And anyway, it looks like all they had to do is replace a pump. A pump that almost certainly costs much less than a thorough independent IT security audit and subsequent upgrade(s). We don't know if they had more critical systems exposed or not.
Nov 20, 2011
Rank: not rated yet
Can I get a quote for that? Those keychain VPN systems take a lot of manpower to manage and are cost prohibitive if you only have a few remote uses / users, which I assume is the case here.
Maybe they are cheaper now and these yahoos should have known that. I've been out of the security side of IT for a while.
Nov 20, 2011
Rank: not rated yet
More than 5 years ago I saw this same type of hack performed by the US's DHS - also burning up a pump motor by the same method. They were tying to prove a point, but the warnings haven't gotten any traction yet. I have no idea other than another darn government mandate what will get federal, state and local governments to wake up and take proactive measures to secure their systems.
Were I an aggressive nation state and wanted to disable another country pre-invasion, I'd shut down their internet & SCADA systems. 90 days in a first-world nation without monetary flow, commerce, electrical or coordinated defences - an army could walk right in with little resistance.
Nov 20, 2011
Rank: not rated yet
I'm mostly just throwing ideas out there, so no need for a heated debate with me. All I'm really saying is that there is a very complicated financial cost/benefit risk analysis that must be done on these systems and budgets, and many posts here are not appreciating that fact.
Nov 20, 2011
Rank: not rated yet
Defense is useless. The enemy waits like the lion in the grass, looking for weakness, and attacks when IT is ready.
People long ago learned that the only lasting defense against lions is to hunt them. Any gamer will tell you this.
Nov 20, 2011
Rank: not rated yet
Yep; we've known this for a few years. See Sun Tzu's "The Art of War," or for a more recent example, No Limit Texas Hold'em strategy. Blind attack is usually a high risk. It's better to probe then prepare a crushing counter-attack than to "show your hand" with little intel on the defender's power.
I think it's a bit of a stretch to claim that local municipalities are knowingly giving themselves up as bait. I'm sure Otto has a riveting conspiracy theory at-the-ready, though. :)
Nov 20, 2011
Rank: not rated yet
Nov 21, 2011
Rank: not rated yet
That was my exact thought as I read the article and the subsequent posts... How much does it cost to change passwords?
Nov 21, 2011
Rank: not rated yet
Kudos to you. That was just damned funny. And that comes from the heart of a Texas Hold'em enthusiast.
Nov 21, 2011
Rank: not rated yet