From the man who discovered Stuxnet, dire warnings one year later
csmonitor.com
csmonitor.com
Symptoms of problems include the ability to DOS a SCADA network simply by flooding it with packets and the lack of authentication/ encryption embedded in protocols such as IEC 61850 (an increasingly popular SCADA standard).
There are two halves to the problem of hacking a SCADA system.
First, you must be able to exploit the software. E.g., Siemens Step 7. That is standard IT hacking. Not a "problem".
Second, you must be able to exploit the installation. Let me explain a bit more.
In software terms, what you are given to work with is a list of hex values denoting inputs, and then a list of hex values denoting outputs.
So - without knowledge - what you will see is conceptually like this:
READ 0x1
READ 0x2
IF 0x1 + 0x2 > 314159 THEN
WRITE 0xA, 100
ENDIF
What do those numbers mean? There's no context until you know what those read/write registers are plugged into. And those could be different for each installation.The second part isn't always brought out in the Stuxnet discussions. Part of the search for understanding for Stuxnet was decoding how the registers mapped to the installation.
For the interested reader, I refer you to the Symantec white paper. It is of quite high quality and good technical detail. The SCADASEC mailing list contains useful discussion by people involved in the industry, and they really bring out the differences between SCADA security and IT security. And for the really interested reader, I recommend reading up on PLC programming and digging up protocol standards for MODBUS and DNP3.
I'm somewhat worried about these things. The problem I see is that we are becoming even more and more leveraged/dependent on technology. And these technologies are increasingly interdependent. A successful attack on one technology can potentially bring down entire systems down in unanticipated ways.
The recent power outage in San Diego and nearby areas serves as a good reminder. You don't actively think about power, it is something you take for granted. Only when the power is lost, then you realize how dependent everything is on it; traffic lights stopped, ATMs didn't work, credit and debit cards didn't work, freezers and fridges stopped, and so forth. From modern times to the dark ages in an eye-blink, instant paralysis.
I don't think nuclear power plants as targets are that interesting. Just turning off traffic light system would be enough to bring down and entire US urban area down to its knees.
New networks of complex dependencies are being created all the time. The smartphone boom is going to create one, and people will start relying on the existence of it. If iPhone and Android keep dominating the market it will create more homogenous mass of devices, providing a more consistent attack surface and more potential for widespread damage. I don't see how smartphones could avoid the same problems PCs were/are experiencing. Waiting for the first smartphone "UNIX worm".
Wireless features are getting added to cars. Yet another potential complex network. War-driving could soon get completely new meanings.
Control systems should be on separate networks, but even those networks are susceptible to wandering USB keys and contractor laptops.
The idea could be used, sure: find some important place that you want to damage in some way. Find out if it has computers that hook into some kind of specialized hardware. Work out how that hardware can be damaged via those computers. Find out how those computers are vulnerable. Write an overly-complicated virus that hides what it's really doing, and set it loose, and hope it makes it all way to those specific computers, and delivers its payload. ...it kinda sounds like a single-use case, really.
More likely, stuxnet is just encouraging people (governments, whatever) to consider attacks that target non-computer run systems. The motors being damaged in Iran, if I understood it correctly, weren't being run by computers, just programmed by them. (I'd be surprised to learn that no one had thought of that before.)
The gist of this guy's argument seems to be that industrial systems aren't being patched fast enough to plug the holes that stuxnet used. Until these systems are all fully patched, anyone looking at stuxnet can exploit those holes without needing to gain access to the software these systems are running (to find new exploits).
Is this really the case? I'm nothing close to a security specialist, so maybe I'm talking out of my ass. Still, everything I read on the subject said that Stuxnet was especially impressive in that it exploited not one but several previously-unknown OS-level exploits, on top of the embedded systems attacks it used. With these zero-days now discovered and hopefully patched, how much more value does Stuxnet offer?
(Neither of these questions are rhetorical — hopeful that one of our resident experts can fill me in.)
Imagine you have a plastics plant running with ACME SCADA system. Your plastics plant has molten plastic running through the facility 24/7. It's actually a lights-out facility, and you're making 1M per day. You schedule six days a year for maintenance, three days every six months, to do a look-see at the pipes. This takes about one day to spin the plant down, one day to audit the pipes, and one day to spin the plant up. This whole process costs you 3M in lost profit, plus the cost of auditing and the process cost of spinning up/down.
Now, your IT guy comes to you and says, "we gotta patch! ACME SCADA's got a hack out against it". Now remember, your ACME system is running the plant. If you power it down without the proper procedure, the pipes freeze with plastic, and your facility needs to be replaced.
What's the risk of you being hacked? You're a plastics facility, making Widgets for economists and their lectures. No one really cares about Widgets. Anyway, you're in the badlands of Boondockia, USA.
Your expected cost of patches must be below the expected cost of being hacked for you to apply the patches.
---
That's the sort of requirements which SCADA owners have to deal with. It's not simply a question of laziness.
In other words, even if you have an easily-exploited attack vector available to you, you still need to know a lot about your target in order to cause damage. Contrast this to guided missiles, which don't really need to know anything about the building that they are blowing up other than its GPS coordinates.
For this reason, I'm skeptical that "any dumb hacker" will ever be capable of causing something like a nuclear meltdown via virus infection.
Computer-controlled systems that can have disastrous real-world consequences almost always have built-in checks to avoid these failure states.
On the other hand, triggering the reactor to automatically shut down would be pretty easy -- and if you shut down all the nuclear reactors in the US for a few weeks, you'll certainly have made a significant impact.
Knock out several of those in critical locations, and you start to grind the U.S. economy to a halt.
You don't need to go nuclear. And destroying the engine was a fairly simple task of pushing it well outside its performance envelope.
EDIT: Looks like pnathan already cited this event -- see the last link in this comment:
http://news.ycombinator.com/item?id=3035909
It's a bit older than I remembered. The article is dated September, 2007.
I note incidentally that for one "catastrophic" scenario they describe, with an estimated "cost" of $700 billion, the damages figure now pales in comparison to what the U.S. economy has been through in the last few years. A bit of a lesson of its own regarding the rhetoric that surrounds the actual topic.
Of course there are safeguards to prevent catastrophes, but even stopping some part of the automation in an industrial plant could easily cause serious problems such as damaged equipment and downtime for debugging.
The electric power grid security is an area of national concern in the US. I read a report to Congress (publically available) a few years back that suggested the power grid was being hacked in quite a few ways. Googling electric power grid security returns a plethora of results, all of them reporting problems.
Here's a few reports. I haven't evaluated them for reliability and accuracy.
A 2009 report that kicked off a lot of talk http://online.wsj.com/article/SB123914805204099085.html
This one is old http://www.wired.com/science/discoveries/news/1998/06/12746
This one is 'new', as of Jan '11. http://www.gao.gov/new.items/d11117.pdf
Here's a blog on it: http://smartgridsecurity.blogspot.com/
Lockheed sez they are going to work on it. http://www.bloomberg.com/news/2011-06-30/lockheed-promises-e...
In 2010, we got some national guidelines. http://www.nist.gov/public_affairs/releases/nist-finalizes-i...
A video of some congressional testimony: http://www.youtube.com/watch?v=JIPQRKAmCWo
China is frequently cited in this business http://www.uscc.gov/researchpapers/2009/NorthropGrumman_PRC_...
And MacAfee has a report on China going after energy companies. http://www.mcafee.com/us/resources/white-papers/wp-global-en...
Explode a generator! (this can be mitigated) http://articles.cnn.com/2007-09-26/us/power.at.risk_1_genera...