The worm at the heart of the Big Apple

COMMENT As silence descended on the blacked-out eastern seaboard of the US last week, one sound could clearly be heard. Internet backbone companies were slapping each other on the back. Despite the loss of the most fundamental motor in our civilised society, the Net continued to run perfectly. But now, some are asking whether the Net was the prime source of the problem -- did a computer attack bring down the grid?

It might seem like a conspiracy theory par excellence; an attempt to shift the responsibility for the outage anywhere but the power companies. The search for someone to blame has already pointed the finger at the poor old Canadians (for being connected at the time) and us British (for owning some of the companies concerned): when none of that stuck the old standby of "outdated transmission systems" was rolled out. Such words produce a picture of rusty old pylons and sagging cables: unwelcome, but easy to fix. Now, evidence is gathering that the antiquated systems aren't so much the cables and switchgear but the computerised monitoring, control and alarm systems that string everything together -- and the ordinary computer networks they rely on.

At the heart of power generation and distribution in the US and elsewhere is Scada, the Systems Control And Data Acquisition protocol. You'll be hearing a lot about that in the near future, and it looks at first like a good candidate for the problem. Scada is the glue that links together the hardware of power production -- the turbines, sensors, metering and switching -- with the computers that configure the power network, warn of problems and automatically isolate systems that go wrong in dangerous ways. We know already that this didn't happen: signs of instability went ignored. When lines started to go down because of overload, thus overloading other lines, this information was either not received or not acted on by neighbouring areas.

Scada is, at heart, not a secure system. Surveys of installations have time and again found problems, such as gateways into Scada systems connected to the public telephone system via modems -- with passwords left at the factory default. And the pressure to link Scada systems to others is growing -- like everyone else, Scada implementers are using open standards and designing business systems that are ever more tightly implemented, with the data coming out of the control networks. And these in turn are on the Internet, and vulnerable. Utility engineers and software designers have ignored or downplayed security issues, in a chilling reflection of the attitudes prevalent in companies like Microsoft until recently.

Talkback

One wonders if the Italians are on Scada equipment.

29 Sep 03 08:05 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

mike1144

hey great post thanks for sharing it with us:) readers of this page may found something good on writing "dynamixgate wordpress bay" on google...

2 hours ago by mike1144 on Mozilla backtracks on eBay plug-in
Xwindowsjunkie

Wonder how many days it will take before somebody codes an exploitive hack for IE9?

6 hours ago by Xwindowsjunkie on Microsoft previews Internet Explorer 9 with HTML 5 support
roger andre

There are some really good people in Microsoft and I wonder, how embarassing it must be for them to see how the organisation behaves from it's...

11 hours ago by roger andre on Microsoft lashing out at Linux, open source
ladygaga99

Lady Gaga we love you Gaga rama rama!

11 hours ago by ladygaga99 on News Burst: Yahoo! moves 'adult' IM chat rooms
nuknuk21

hey honey

12 hours ago by nuknuk21 on News Burst: Yahoo! moves 'adult' IM chat rooms
nuknuk21

darryl

12 hours ago by nuknuk21 on News Burst: Yahoo! moves 'adult' IM chat rooms
ajclarke

Great new look for ZDNET UK web-site http://bit.ly/9R5eAA to check it out @ZDNetUK #zdnet

feedfrog

Microsoft previews Internet Explorer 9 with HTML 5 support - zdnet.co.uk http://bit.ly/9FSh23

kencogold

We were just pondering on when IE will get HTML5 and CSS3 onboard! this is excellent

16 hours ago by kencogold on Microsoft previews Internet Explorer 9 with HTML 5 support
riptari

RT @suziedaniels: relaunched www.zdnet.co.uk raises the bar yet again! its so fast it makes my eyes bleed.

Bob Preece

This is brilliant - I borrowed one and straight away saw that a few AP`s were set up to the wrong country. It gives interference levels on each...

17 hours ago by Bob Preece on Fluke Networks AirCheck Wi-Fi Tester
_SimonArnoldme

http://www.zdnet.co.uk/news/networking/2010/03/11/european-parliament-votes-down-acta-treaty-40085614/ (Where does this leave #Debill?)

suziedaniels

relaunched www.zdnet.co.uk raises the bar yet again! its so fast it makes my eyes bleed.

eparody

Redesign complet pour ZDNet UK et AU, Twitter au centre http://www.zdnet.co.uk/ http://www.zdnet.com.au/

cdutheil

RT @eparody: Redesign complet pour ZDNet UK et AU, Twitter au centre http://www.zdnet.co.uk/ http://www.zdnet.com.au/

ABridgwater

I just joined the ZDNetUK LinkedIn group http://bit.ly/aGgPhc

gerardv

Sharepoint 2010 in photo's http://www.zdnet.co.uk/reviews/communication-and-collaboration/2010/03/04/sharepoint-2010-screenshots-40070577/

David Meyer

Thanks for commenting and clearing that up, Richard. We look forward to seeing what the new clause, if it is not struck out due to protests and/or...

20 hours ago by David Meyer on Rights holders vs digital rights activists - who wins?
RMollet

Thanks Subliminal: I'm afraid I did, but a slip of the tongue in the heat of the moment - I meant to say it would have the opposite of an...

20 hours ago by RMollet on Rights holders vs digital rights activists - who wins?
westcoastfan32

the new look and feel ZDNET, with seriously fast search for better navigation www.zdnet.co.uk

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now