Foreign cyber attack hits US infrastructure: expert
A man uses a laptop computer at a wireless cafe. A cyber strike launched from outside the United States hit a public water system in the Midwestern state of Illinois, an infrastructure control systems expert said on Friday.
A cyber strike launched from outside the United States hit a public water system in the Midwestern state of Illinois, an infrastructure control systems expert said on Friday.
"This is arguably the first case where we have had a hack of critical infrastructure from outside the United States that caused damage," Applied Control Solutions managing partner Joseph Weiss told AFP.
"That is what is so big about this," he continued. "They could have done anything because they had access to the master station."
The Illinois Statewide Terrorism and Intelligence Center disclosed the cyber assault on a public water facility outside the city of Springfield last week but attackers gained access to the system months earlier, Weiss said.
The network breach was exposed after cyber intruders burned out a pump.
"No one realized the hackers were in there until they started turning on and off the pump," according to Weiss.
The attack was reportedly traced to a computer in Russia and took advantage of account passwords stolen during a hack of a US company that makes Supervisory Control and Data Acquisition (SCADA) software.
There are about a dozen or so firms that make SCADA software, which is used around the world to control machines in industrial facilities ranging from factories and oil rigs to nuclear power and sewage plants.
Stealing passwords and account names from a SCADA software company was, in essence, swiping keys to networks of facilities using the programs to control operations.
"We don't know how many other SCADA systems have been compromised because they don't really have cyber forensics," said Weiss, who is based in California.
The US Department of Homeland Security has downplayed the Illinois cyber attack in public reports, stating that it had seen no evidence indicating a threat to public safety but was investigating the situation.
Word also circulated on Friday that a water supply network in Texas might have been breached in a cyber attack, according to McAfee Labs security research director David Marcus.
"My gut tells me that there is greater targeting and wider compromise than we know about," Marcus said in a blog post.
"Does this mean that I think it is cyber-Armageddon time?" Marcus continued. "No, but it is certainly prudent to evaluate our systems and ask some questions."
(c) 2011 AFP
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
33 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
42 comments
-
Landmark calculation clears the way to answering how matter is formed,
55 comments
-
Research team claims to have found evidence Lake Cheko is impact crater for Tunguska Event,
18 comments
-
Need a rigid insulation material???
May 26, 2012
-
magnets or EMF in car bumpers to protect from fender bender
May 26, 2012
-
length of wire in a coil of known dimensions?
May 25, 2012
-
India Engineering Powerhouse
May 25, 2012
-
electromagnet core dereference between hard and soft iron
May 25, 2012
-
Measuring water pressure in an open tank
May 24, 2012
- More from Physics Forums - General Engineering
More news stories
Browser wars flare in mobile space
The browser wars are heating up again, but this time the fight is for dominance of the mobile Internet.
19 hours ago |
4 / 5 (4) |
3
Probability of contamination from severe nuclear reactor accidents is higher than expected: study
Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...
Technology / Energy & Green Tech
May 22, 2012 |
3.6 / 5 (25) |
56
|
HyperSolar shows dirty water no barrier to power world
(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the companys ultimate vision, successfully producing ...
Tesla to launch electric sedan in US on June 22
Tesla Motors said Tuesday it would begin deliveries of "the world's first premium electric sedan" on June 22, slightly ahead of schedule.
Technology / Energy & Green Tech
May 22, 2012 |
4.5 / 5 (12) |
18
SpotterRF debuts Radar Backpack Kit (w/ Video)
(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...
Stunning image of smallest possible five-ringed structure
Scientists have created and imaged the smallest possible five-ringed structure about 100,000 times thinner than a human hair and you'll probably recognise its shape.
'Unzipped' carbon nanotubes could help energize fuel cells, batteries
Multi-walled carbon nanotubes riddled with defects and impurities on the outside could replace some of the expensive platinum catalysts used in fuel cells and metal-air batteries, according to scientists at ...
Change in developmental timing was crucial in the evolutionary shift from dinosaurs to birds: study
At first glance, it's hard to see how a common house sparrow and a Tyrannosaurus Rex might have anything in common. After all, one is a bird that weighs less than an ounce, and the other is a dinosaur that ...
Computer model used to pinpoint prime materials for efficient carbon capture
When power plants begin capturing their carbon emissions to reduce greenhouse gases and to most in the electric power industry, it's a question of when, not if it will be an expensive undertaking.
T cells 'hunt' parasites like animal predators seek prey, study shows
By pairing an intimate knowledge of immune-system function with a deep understanding of statistical physics, a cross-disciplinary team at the University of Pennsylvania has arrived at a surprising finding: T cells use a movement ...
Yale study concludes public apathy over climate change unrelated to science literacy
Are members of the public divided about climate change because they don't understand the science behind it? If Americans knew more basic science and were more proficient in technical reasoning, would public consensus match ...
Nov 19, 2011
Rank: 5 / 5 (3)
Nov 19, 2011
Rank: 4.2 / 5 (5)
Obviously, security is being discarded in favor of convenience.
Recovering Human's question remains valid. Why would you sacrifice security on critical systems?
Nov 19, 2011
Rank: 5 / 5 (4)
"Hey bro would you pass me that wireless keyboard? and a budwieser?"
"what do you want the keyboard for?"
"well my boss says i gotta turn the pump off at 2am. Like I'm gonna stay there til 2am. As If!"
"no but so whats they keyboard for, dude?"
"Remote desktop, homie!"
*high fives*
Nov 19, 2011
Rank: 5 / 5 (6)
The vast majority of all government spending, at all levels, goes to payroll one way or another. In an age of massive budget cuts where should we get the money to fix these problems?
I dont have a solution and dont pretend to, but I think we need to start owning up to seriousness of our situation.
Nov 19, 2011
Rank: not rated yet
Nov 19, 2011
Rank: 0.8 / 5 (53)
Nice dodge. I'll ask again. Any theories dogbert?
Nov 19, 2011
Rank: not rated yet
Nov 19, 2011
Rank: 3 / 5 (2)
The fact is, they're not. We live in a complex, global economy where systems of all kinds are interconnected and where the technical expertise needed to implement and maintain systems is not readily available at all times at all locations on the planet. This doesn't appear to be a problem that will be solved any time soon.
So, can we move past that?
Nov 19, 2011
Rank: 1 / 5 (1)
Nov 19, 2011
Rank: 3.7 / 5 (3)
I think it can be argued that the small expenditures to create a closed network is justified when compared to the costs of open access to critical systems, but you can create virtual private networks over a public network for essentially zero extra cost.
There is really no excuse to providing open access to critical systems.
Nov 19, 2011
Rank: 5 / 5 (2)
Nov 19, 2011
Rank: 5 / 5 (2)
How much simpler it would be to fire those responsible for securing these critical applications for not doing their jobs in the first place. But then, that would be like demanding accountability in government. How crazy is THAT!
Nov 20, 2011
Rank: 5 / 5 (1)
Nov 20, 2011
Rank: 5 / 5 (1)
Actually, this is a standard operating procedure in IT departments around the world. Please take your political views elsewhere.
Nov 20, 2011
Rank: 5 / 5 (2)
You are truly out of your element here and stating misinformation. There is nothing "small" about the expenditures. There is no possible way to fix this with a closed, off-limits system.
This is not the CIA we're talking about. It's municipal water depts. and they barely have the cash to keep the water pumping.
This can not -- and will not -- be fixed in this manner.
Please move on.
Nov 20, 2011
Rank: not rated yet
Wrong. Read my posts for some enlightenment.
Nov 20, 2011
Rank: 3 / 5 (2)
Wow, you guys just aren't listening.
This is NOT NEWS.
This is NOT NEW.
This has been going on for about 20 years, and is standard operating procedure for IT departments EVERYWHERE ON THE PLANET.
Other than military, intelligence and other high-security government agencies, NO ONE has all the expertise in-house to do EVERYTHING that might come up.
We need to talk about improving security where and how it is doable, and stop wasting time talking about taking one million or more systems off-line. We are ALL hyper-connected, and it will stay that way.
Now, other than pulling the plug, what ELSE can we do?
Nov 20, 2011
Rank: not rated yet
Nov 20, 2011
Rank: 5 / 5 (2)
Nov 20, 2011
Rank: 3.7 / 5 (3)
Are you?
We can stop saying we cannot do anything.
If remote access is necessary and the network is small, a private network is not prohibitively expensive.
If remote access is necessary and the network much include multiple sites, a virtual private network is not difficult to set up or maintain and is essentially free. That is, since the utility can afford internet access, it can afford a virtual private network.
This story is about a water plant and a burned out water pump. Suppose it was about a dam and gates blocked open?
It is not necessary to subject our critical systems to open access. Criminal incompetence is not excusable.
Nov 20, 2011
Rank: 3.1 / 5 (7)
Interesting that the US government found hundreds of billions of dollars to bale out crooks in the housing/banking rip-off which of course led to huge bonus payouts for the culprits.
So it's merely a matter of priorities.
Nov 20, 2011
Rank: not rated yet
Yes and no. The problem described here was almost unheard of even a few years ago. But, even now, it's not really viewed as something with the potential for disastrous consequences. Incorrectly, IMO, but I don't sit on the appropriate legislative committees either. Also, there have been some dollars designated for this kind of thing. But, the majority are being spent on things like physical security at the big nuke plants.
Nov 20, 2011
Rank: 5 / 5 (1)
Nov 20, 2011
Rank: not rated yet
True, but that probably wouldn't have helped here. Remember, they got the logins from a previous hack, which might have included the VPN credentials. Rolling VPN is very expensive.
I'm not really arguing; you make a decent point. However, it's much more complicated than simply slapping a VPN on the remote access problem. Only addressing one flaw will just expose the next weakest link. There's almost no point at only addressing one aspect of security.
And anyway, it looks like all they had to do is replace a pump. A pump that almost certainly costs much less than a thorough independent IT security audit and subsequent upgrade(s). We don't know if they had more critical systems exposed or not.
Nov 20, 2011
Rank: not rated yet
Can I get a quote for that? Those keychain VPN systems take a lot of manpower to manage and are cost prohibitive if you only have a few remote uses / users, which I assume is the case here.
Maybe they are cheaper now and these yahoos should have known that. I've been out of the security side of IT for a while.
Nov 20, 2011
Rank: not rated yet
More than 5 years ago I saw this same type of hack performed by the US's DHS - also burning up a pump motor by the same method. They were tying to prove a point, but the warnings haven't gotten any traction yet. I have no idea other than another darn government mandate what will get federal, state and local governments to wake up and take proactive measures to secure their systems.
Were I an aggressive nation state and wanted to disable another country pre-invasion, I'd shut down their internet & SCADA systems. 90 days in a first-world nation without monetary flow, commerce, electrical or coordinated defences - an army could walk right in with little resistance.
Nov 20, 2011
Rank: not rated yet
I'm mostly just throwing ideas out there, so no need for a heated debate with me. All I'm really saying is that there is a very complicated financial cost/benefit risk analysis that must be done on these systems and budgets, and many posts here are not appreciating that fact.
Nov 20, 2011
Rank: not rated yet
Defense is useless. The enemy waits like the lion in the grass, looking for weakness, and attacks when IT is ready.
People long ago learned that the only lasting defense against lions is to hunt them. Any gamer will tell you this.
Nov 20, 2011
Rank: not rated yet
Yep; we've known this for a few years. See Sun Tzu's "The Art of War," or for a more recent example, No Limit Texas Hold'em strategy. Blind attack is usually a high risk. It's better to probe then prepare a crushing counter-attack than to "show your hand" with little intel on the defender's power.
I think it's a bit of a stretch to claim that local municipalities are knowingly giving themselves up as bait. I'm sure Otto has a riveting conspiracy theory at-the-ready, though. :)
Nov 20, 2011
Rank: not rated yet
Nov 21, 2011
Rank: not rated yet
That was my exact thought as I read the article and the subsequent posts... How much does it cost to change passwords?
Nov 21, 2011
Rank: not rated yet
Kudos to you. That was just damned funny. And that comes from the heart of a Texas Hold'em enthusiast.
Nov 21, 2011
Rank: not rated yet