Computing

Hacking the Smart Grid

(Page 2 of 2)

  • Monday, August 2, 2010
  • By Erica Naone

Smart-grid devices also connect back to the older control equipment--known as Supervisory Control and Data Acquisition (SCADA) systems--used at utility companies. "SCADA systems are far less secure than enterprise IT systems," Pollet says. He explains that they are often connected to the Internet, but don't have security features such as firewalls and antivirus protection.

Nathan Keltner, a consultant on FishNet Security's assessment team, has been analyzing smart-grid technology for clients. He said the smart grid amounts to "old-school SCADA that's been bolted into some sort of a newer technology."

It may be particularly hard to protect the smart grid because would-be attackers will have physical access to components connected to the network. Pollet says that all it takes is for one determined attacker to find a way in--information about how to hack a device is then quickly shared online. "Those who have the intent and motivation can do this stuff," he says.

Shawn Moyer, who is the principal consultant on FishNet Security's assessment team, says he's concerned that utilities don't have expertise in network security. For example, he says, many advertise that they offer encryption in their smart-grid products, but on further inspection, there are problems with how that encryption is implemented.

Moyer and Keltner revealed a proof-of-concept smart-grid attack at Black Hat. They used a customizable piece of radio equipment and some freely available software to find smart meters on a network and circumvent the encryption used to protect them. If an attacker were to do the same, they say, it would be possible to issue commands that could misreport data to the utility or shut off power to some users.

Moyer notes that utilities have battled meddling for a long time, but the smart grid adds another dimension to the problem. "Theft of service isn't new, tampering isn't new--only the scale of what's possible," he says.

Print

Related Articles

White House Promotes a Smarter Grid

But some consumers, concerned about rising prices and privacy, would rather their electricity meters stayed dumb.

How to Hack the Power Grid for Fun and Profit

Attackers could manipulate poorly protected data to make money or cause blackouts.

Hacking the Smart Grid

One researcher shows how your house's power could be shut down remotely, but the threat is only theoretical--for now.

Advertisement

MAGAZINE

People Power 2.0

How civilians helped win the Libyan information war.

Sponsored Content

Technologies from National Instruments

Triggering
Learn how to configure a start trigger on a USB data acquisition device

> Click here for more National Instruments Videos <
Whitepaper

How To Measure Voltage

Voltage is the difference of electrical potential between two points of an electrical or electronic circuit, expressed in volts. It measures the potential energy of an electric field to cause an electric current in an electrical conductor.

Most measurement devices can measure voltage. Two common voltage measurements are direct current (DC) and alternating current (AC).

Learn the fundamentals of creating an AC or DC voltage measurement system. See how to properly connect the signals to your data acquisition system for accurate acquisition.

This document is part of the How-To Guide for Most Common Measurements centralized resource portal.

View full PDF > Listen to story >
Find us on Youtube

Videos

Interview with George Dyson

More

Advertisement
Advertisement
Advertisement