Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
Check out the new SourceForge HTML5 internet speed test! No Flash necessary and runs on all devices. ×

Submission + - Electrical Grid Is Called Vulnerable to Power Shutdown (nytimes.com)

mspohr writes: An interesting article in the NY Times: "Two researchers discovered that they could freeze, or crash, the software that monitors a substation, thereby blinding control center operators from the power grid."
These two engineers wrote software to test for vulnerabilities in the control systems of electrical power grids which use a protocol called DNP3 to communicate with sub-stations. They first tested an open source implementation of the protocol and didn't find any problems. They were worried that their software test wasn't adequate so they started testing proprietary systems. The broke every single one of the 16 proprietary systems they tested initially and found a further 9 systems vulnerable in later testing. They were able to install malware and also found firewalls ineffective.
They reported this to the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team, I.C.S.-C.E.R.T. and didn't get much of a response.
Scary that our electrical grid is so vulnerable and there doesn't seem to be much urgency to get it fixed. A few patches have been issued but who knows if the systems have been updated?

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Electrical Grid Is Called Vulnerable to Power Shutdown

Comments Filter:

For every problem there is one solution which is simple, neat, and wrong. -- H. L. Mencken

Working...