Pacific Northwest National Laboratory Report Reveals Dramatic Increase in Cyber Threats and Sabotage on Critical Infrastructure and Key Resources

The Pacific Northwest National Laboratory in conjunction with McAfee has revealed the findings from a report entitled “Technology Security Assessment for Capabilities and Applicability in Energy Sector Industrial Control Systems: McAfee Application Control, Change Control, Integrity Control.”

For the first time, the report fully examines the current challenges facing critical infrastructure and key resources as well as identifying specific risks and vulnerabilities in the evolving cyber threat landscape. It analyzes the value and effectiveness carefully integrated security solutions necessary to support the national security mission to secure industrial control system environments.  In addition, the big challenge for critical infrastructure and energy sector owners and operators, as identified by the report, is how to effectively secure their control systems within their governance and technical domains in an active and capable advanced persistent threat environment. 

When early critical infrastructure systems were created, neither security nor misuse of the interconnected network was considered stated by Philip A. Craig Jr, Senior Cyber Security Research Scientist, a researcher within the National Security Directorate at the Pacific Northwest National Laboratory.  

In the report, PNNL and the DOE have identified the following vulnerabilities to control systems environments:

  • Increased Exposure: Communication networks linking smart grid devices and systems will create many more access points to these devices, resulting in an increased exposure to potential attacks.
  • Interconnectivity: Communication networks will be more interconnected, further exposing the system to possible failures and attacks. 
  • Complexity: The electric system will become significantly more complex as more subsystems are linked together.
  • Common Computing Technologies: Smart grid systems will increasingly use common, commercially available computing technologies and will be subject to their weaknesses. 
  • Increased Automation: Communication networks will generate, gather, and use data in new and innovative ways as smart grid technologies will automate many functions. Improper use of this data presents new risks to national security and our economy.

The report also examines how emerging vulnerabilities of control systems continue to accelerate. Today’s cyber attack has evolved into a sophisticated and carefully designed digital-weapon tasked for a specific intent, such as the Stuxnet and Duqu virus.

In addition to control systems, the report also examines the impact of new technologies impacting the Energy sector. As information and communication technology advances and becomes integrated into power system operations and planning functions, smart grids are created, which yield greater visibility into the state of the system and advancements in control to enhance system efficiencies. Despite the significant benefits of the dynamic nature of the power grid, it was not designed with cyber security in mind.

The report cites the following solutions in an effort to prevent vulnerability and mitigate attacks to control systems:

  • Dynamic Whitelisting –Provides the ability to deny unauthorized applications and code on servers, corporate desktops, and fixed-function devices.
  • Memory Protection – Unauthorized execution is denied and vulnerabilities are blocked and reported.
  • File Integrity Monitoring – Any file change, addition, deletion, renaming, attribute changes, ACL modification, and owner modification is reported. This includes network shares.
  • Write Protection – Writing to hard disks are only authorized to the operating system, application configuration, and log files. All others are denied.
  • Read Protection – Read are only authorized for specified files, directories, volumes and scripts. All others are denied

The Department of Energy’s key objective to secure the critical infrastructure and key resources includes our Nation’s electric generation, transmission, distribution resources, as well as key oil and natural gas assets. The Pacific Northwest National Laboratory seeks to continue to improve the value of security technologies as they are implemented in these critical infrastructure and key resources areas.

 
Check out more IT News at Itvoir.com


  


Similar Articles
GlacialTech to Showcase Its Latest LED Lights and Drivers at the18th Guangzhou International Lighting Exhibition
GlacialTech, a Taiwanese technology manufacturer, extends an invitation to all business and media partners around the world to attend their display of LED lights and drivers of its subdivisions, Glaci
ZyXEL appoints Regional Head for Western India
ZyXEL Communications, a world-class broadband networking company that provides leading Internet solutions for customers ranging from telecommunication service providers, businesses to home users, anno
IBM Watson At Your Service: New Watson Breakthrough Transforms How Brands Engage Today's Connected Consumers
Ushering in a new era of cognitive computing systems, IBM today unveiled the IBM Watson Engagement Advisor, a technology breakthrough that allows brands to crunch big data in record time to transform
Achieve Cost Savings with SapphireIMS Asset Management Solution
SapphireIMS, one of the leading providers of end-to-end IT Service Management solutions, has added new features in its Asset Management solution. SapphireIMS asset management solution helps organizati
Comguard unveils a new range of security solutions from gateProtect in India
Comguard India, a part of Spectrum Group of Companies, Dubai, and a leading value added distributor of global networking and security products and voice & data distributor, announced the launch of
AsiaPowercom Launches AsiaPower Stabilizer
Asia Powercom, global leader in power protection - a division of Powercom Co. Ltd, today launched AsiaPower AV600 stabilizer for TV. AV600 Safeguards the valuable devices from power fluctuation with i
Foxconn's April Revenues up Sequentially with Pegatron
Foxconn, world's leading manufacturer of computer components and systems, reported that Foxconn saw April consolidated revenues of NT$291.759 billion (US$9.82 billion) increasing on month by 12.05%, w
Nevales Networks Introduces MIPS-Based Energy-Efficient, High-Performance Security Gateway Devices for Carrier-Driven Deployments
Nevales Networks, an innovator in delivering comprehensive and affordable cloud-based managed security services on a 'Pay as You Use' model, is leveraging the popular MIPS architecture in new energy-e
India Post Brings Beam Services across Uttarakhand Post Offices
Beam, India’s revolutionary mobile wallet and mobile/ecommerce marketplace is rolling out its services in 29 major Post Offices across Uttarakhand. Now customers can avail services like mobile,
WatchGuard Expands Network Security Support for Microsoft Hyper-V Customers
WatchGuard Technologies, a global leader in manageable business security solutions, announced it is expanding its network security offerings for customers using Microsoft Hyper-V virtualized environme
Spam in Q1 2013: History repeats itself
According to Kaspersky Lab’s spam report, in Q1 2013, the amount of unsolicited correspondence in email traffic grew slightly (+0.53 percentage points) and averaged 66.55%. The increase in the p
HONEYWELL INTEGRATES AND CERTIFIES FMC SUBSEA AUTOMATION PROTOCOL WITH EXPERION PKS C300 CONTROLLER
Honeywell today announced the integration and certification of the FMC722 subsea automation protocol with its Experion Process Knowledge System (PKS) C300 controller as a native interface. A global pr
ASUS launches its 1st Exclusive Store in Andhra Pradesh
ASUS India, a leading brand driven by the strength of mastering technological innovation and design perfection for the ultimate life-enhancing and computing experience, today, announced the launch of
Transcend Displays Its Advanced Industrial products at ESEC Japan 2013
Transcend Information, Inc. (Transcend ), a leading manufacturer of industrial-grade products, will be displaying its comprehensive industrial solutions at the 16th Embedded Systems Expo (ESEC) 2013.
ESG Labs Achieves Impressive Testing Results for EMC VSPEX Proven Infrastructure Solutions with Brocade Networking
Brocade (NASDAQ: BRCD), the leader in data center networking solutions, today announced impressive testing results performed by ESG Lab for EMC VSPEX Proven Infrastructure solutions enabled with the a
Mega Networks of India Selects Dot Hill AssuredSAN and AssuredSAN Pro Storage Solutions
Dot Hill Systems Corp. (Nasdaq:HILL), a leading provider of SAN storage solutions, entered into an original equipment manufacturer (OEM) agreement with Mega Networks Pvt Ltd., one of India's leading s
Propalms Wins 200+ Customers across Major Verticals
Propalms, leading provider of server based computing technology based on Microsoft Remote Desktop Services, Hypervisor based VDI and Enterprise remote access solutions, today shared its outstanding su
Nimbuzz and Mobilink partner to launch a new communications solution in Pakistan
Nimbuzz, a leading cross-platform global communications solution and Mobilink have announced a partnership to bring the Nimbuzz Messenger app to Mobilink subscribers across Pakistan at an unbeatable p
Leading Analyst firm Gartner recognises Flytxt as a Cool Vendor in Emerging Markets, 2013'
Flytxt, the provider of Big Data analytics powered revenue and customer experience management solutions for Cellular Service Providers (CSPs), today announced that it has been included in the list of
CIPL provides IT Tools and Applications to create your own Website/E-commerce portal
CIPL (Corporate Infocom), an IT entrepreneurship based company focusing on simplifying technology introduces applications and tools to enable customers create their own websites/e-commerce portals.
Follow us on:


 
 



 


 
Mr. Virendra Gupta, Co-Founder & MD, NewsHunt provides inp..

Mr. Virendra Gupta

Co-Founder & MD , NewsHunt

Mr. Virendra Gupta, Co-Founder & MD, NewsHunt provides inputs on the company

 

Mr. Sunil Srivastava

India Sales and Marketing Manager , Shenzhen Rapoo Electron..

Mr. Sunil Srivastava, India Sales and Marketing Manag..

Mr. Ravi Sunderarajan

Vice - President, Sales and Marketing , Gupshup

Mr. Ravi Sunderarajan, Vice - President, Sales and Ma..

 


 
SanDisk Global Product Launch_Hon Wai Cheah Gavin Wu and Manisha Sood unveiling the new product rangeIntel India announced the launch of Intel Future Scientist program in the state of KarnatakaPuneet Chadha, Director GSB, HP-IPG & Siddharth Malhotra, Director Arun&Rajive Pvt. Ltd. - unveiling the HP Wall ArtSeagate Back-up Plus Launch – (L-R) Mr. Futoshi Nizuma, Mr. Benshen Teh, Mr. Nermount Hoh and Mr. Rajesh Khurana unveiling the new product. Toshiba launches AOC TV appoints Ms. Kalki Koechlin as the Brand Ambassador; showcases new range of LCD & LED TVsFujitsu Launches two new Ultrabooks, LIFEBOOK    UH572  and LIFEBOOK    U772 in India. Asus associates with Intel and Microsoft launches mainstream Ultrabooks S Series and Thin and Light notebooks F series. L- R Mr. Unaez Quraishi, Sales, Mr. Alex Huang, MD,  System business Group, Asus India, Mr. Sumeet Gugnani, Director - Multinational Accounts, Microsoft India - Mr. Sandeep Aurora, Director of Marketing, Intel South Asia.
 

 

The most user friendly operating system?

  • Windows
    [81.69%]
  • Mac OS
    [8.45%]
  • Linux
    [9.86%]