Tuesday

Industrial Control System Security:                   a reliability Issue?


November 5, 2012 By
 
Cyber Security Expert Joe Weiss has spearheaded the ICS Cyber Security Conference for 12 years, and when he calls in the troops, the best come to serve. Last month’s conference held at Old Dominion University's Virginia Modeling Analysis and Simulation Center -- VMASC in Suffolk, Va. -- was no different. I had a chance to attend the conference and talk with Weiss about Industrial Control System (ICS) security, and this is what he had to say.
 
Karisny: Your conference first and foremost reinforced that industrial control system (ICS) security is different and it is not just IT. Can you briefly explain?

Weiss: ICSs are purpose-built systems for performing specific tasks. They are built with a mix of commercial off-the-shelf systems (such as Windows) and proprietary realtime operating systems, proprietary communication protocols, and have very specific operating requirements. They were built with minimum computing resources and to operate on their own networks to maximize reliability.  They are built to operate for long periods of time (up to 10-20 years) with minimal downtime and will be replaced when they are obsolete or functional operating requirements change. Generally, they will not be replaced because of security reasons. Their primary function is to provide safe, reliable operation with computer operators and system integrators trained for reliable operation not security. From a cyber security perspective, the most important considerations are availability of the process and authentication of the devices; confidentiality is generally not important for the data "in motion." The concern is that inappropriate use of IT technologies, policies, and/or testing such as penetration testing could, and has, impacted the performance of ICSs.
 
Karisny: There were validated disclosures of targeted critical infrastructure cyber incidents in the conference. Without disclosing too much confidentiality can you explain these incidents and their significance?
 
Weiss: There were two ICS cyber incidents that occurred recently that were discussed. These two unintentional incidents are important as they have not been seen before, they represent two different control system suppliers, and there is no guidance in what to do.
In the first case, the utility was in the final stages of a plant distributed control system (DCS) retrofit. During the installation process, the view of the process (the operator displays, etc) were lost. Neither the utility nor the on-site vendor support was able to get the view of the process restored. It took a vendor link from about 2,000 miles away to get the view of the process back. It raises several questions:
1.What caused the loss of view?
2. Why were the on-site staff not trained about this situation?
3. What did the headquarters staff know that allowed them to get the process view restored?
4. What other facilities have suffered this problem?
5. Could this problem be intentionally caused?
The second case was a complete loss of logic in every plant DCS processor with the plant at power. The event occurred more than once and led to complete loss of control and loss of view. (This is well beyond what I thought was the worst case scenario.) What saved the plant were the old hardwired analog safety systems that shut down the processes. The plant has not been able to determine the cause of the loss of logic. They have documented the situation, contacted their vendor, and provided the vendor their recommendations. The utility is still waiting to hear from their vendor. The concern is this could happen to any industrial facility from any control system supplier. It is not clear if this can be done maliciously.
 
Karisny: There is a need of sharing cyber breach information but legal issues seem to be deterring this information from even private disclosure. From government intelligence agencies to private sector confidential disclosure, how can we minimally gather this information in some type of a cyber breach clearing house?
 
Weiss: My view is that end-users will share information if they feel it will help them. That means they need a venue where they feel they can get knowledgeable feedback so that all sides (the discloser as well as the attendees) get something from the disclosure. I also don’t believe private industry trusts the government so a DHS or other government-sponsored vehicle will not work. The ICS Conference works because there are smart people there that can provide intelligent feedback to the presenters and the end-users feel they will not have their information disclosed.
 
Karisny: Will the difference in ICS require a different way of developing ICS security? Were there some promising new technologies capable of addressing these differences discussed in the conference?
 
Weiss: As mentioned before, ICSs are different than IT. Generally, IT security suppliers are taking their existing IT solutions and attempting to “customize” them for ICS.  What should be done is to understand how the ICS works and what could compromise ICS reliability and/or safety. Then, develop solutions that address those specific concerns.  I know of only one technology that seems to have taken this approach. It is still in the R&D stage.
 
Karisny: A hacker can rapidly respond without recognition or requirement of following cyber security rules and regulations. This is not the case for the good guy in cyber security. With an abundance of standards, regulation, compliance and oversight in cyber security, is there a way to offer short cuts to let the good guys get in?
 
Weiss: Unlike the good guys, a hacker doesn’t have an organizational chart to follow. As best as I can tell, the only time the IT and ICS communities worked together flawlessly was the development of Stuxnet. The North American Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) cyber security standards are a good example of a compliance rather than security mindset. The NERC CIPs have made the grid less reliable and less secure as well as becoming a roadmap for hackers to compromise the grid. That is, the NERC CIPs publicly identify the size requirements to make a facility critical which allow one to determine which power plants, substations, and control centers will have cyber security requirements and which will not. With the current set of NERC CIP standards, approximately 70 percent of power plants, 30 percent of transmission substations, and all distributions systems have no cyber security requirements.  Until certain government organizations stop being more afraid of the bad guys learning something rather than educating the good guys, industry will be in trouble because the bad guys want to learn and the good guys will continue to be unaware. This lack of understanding of critical vulnerabilities was demonstrated by the Aurora discussions at the conference. These first public discussions were new to almost all conference attendees.
 
Karisny: What is it going to take to get utility senior management buy-in on understanding the possibility and consequences of a cyber attack incident and the talent required to mitigate and prioritize resources for ICS cyber security?
 
Weiss: Until utility management treats ICS cyber security as a reliability issue rather than a compliance issue, there will be less than robust utility attendance at the ICS Cyber Security Conference. The question is how to reach and educate utility management about the reliability and safety issues of ICS cyber security. The ICS Cyber Security Conference is not a utility conference but a cross-industry ICS cyber security conference. We had a significant number of end-users from water, chemicals, oil/gas, manufacturing, food, pipelines, and DOD. My belief is that the electric industry is not a leader in cyber security of control systems because of the NERC CIPs creating a culture of compliance not security. The leaders in cyber security are the oil/gas and petrochemical industry with DOD starting to take this more seriously. One would hope that after all of the power issues with Hurricane Sandy, utility executives will take ICS cyber security more seriously before it is too late.

For more a full observation summary of the conference by Joe Weiss please click here .
 
Larry Karisny is the director of Project Safety.org, a smart-grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure

Friday

Anomaly Detection: Front-Door Infrastructure Security


 

"Outlier Detection"

September 20, 2012 By
 
The Digital Communities article "Have Hackers Won?" -- with Columbia Computer Science Professor and Federal Trade Commission Chief Technologist Steven Bellovin -- gave a clear explanation of security limitations because of the size and complexity of buggy software code, and limitations in authentication and encryption. "Authentication won’t do it," Bellovin explained in the article. "In most breaches, the bad guys go around the strong authentication, not through it."  He went on to say that as part of a national study, he analyzed every CERT advisory issued up to 1998 and found that 85 percent of them were code problems, configuration errors, etc., that encryption couldn’t fix.

While this may be a difficult problem to address, it is not impossible. It does, however, require a new way of looking at what real security is and how to effectively secure business process information.

Understanding True Security

While technology has delivered benefits, it has also delivered a new set of security risks and business problems, including large volumes of questionable data; vague accountabilities, and ongoing maintenance of business rules, to name a few. As we have digitally automated our business and control processes, we have reached a point of complexity from which it is impossible for a manager to see the-day-to-day actions of these processes or even detect a security breach.  New visualization tools are necessary to assist managers if they are to accurately and effectively direct these business processes.  This is where anomaly detection will help. 

Currently, data collection, buggy code, network encryption and authentication are all viewed and audited at the system output level. Real-time system data and unwanted business events could be detected too late in this type of security system. Security then must be viewed, audited and authorized at the event enterprise input level to achieve higher security levels required for critical infrastructure.

Our current security systems are collecting so many security no's at the output level that intrusion prevention and detection systems are reaching the point of overload. To date there have been over 17.7 million viruses detected.  Add bandwidth eating high-end encryption to the mix and things are eventually going to start slowing down. So how do we handle all these security no's?  The answer to this problem is simply say yes.

It's almost impossible to manually watch, detect, audit and correct all these business activities in the complexity of today’s business processes.  Even when doing this through coordinated government compliance like NERC CIP in securing the power grid, the minute we think we are done and walk away something changes.  These compliance processes cost a lot of money, take a lot of time and can’t guarantee security anyway.

So what if we could create an anomaly algorithm that could audit, detect and approve positive input events in business processes. And if we could do this then wouldn’t risk management and security actually just be a byproduct of allowing these positive business events to occur?

"Anomaly detection," says Wikipedia, is also called "outlier detection" and refers to detecting patterns in a given data set that do not conform to established normal behavior. The patterns thus detected are called anomalies and often translate to critical and actionable information in several application domains. 

In the workplace predetermined activities of employees, information systems and combined human and information system events produce specific desired business process results.  Anomalies are tools that can specifically detect and audit the defined patterns of these combined human and system activities.  A change in the normal pattern of these activities can offer a business manager very specific information that can assist in improving the business process or even detecting a major business or system breach.

Real-World Fix
This may seem like security fantasyland or something that is still on the drawing board but it’s not. The problem is not that it is not available or it doesn’t work. It is available.

Like most paradigm shifts it takes awhile for people to get it and human nature sometimes confuses threats with benefits. We need to start leveraging tools that can view, audit and improve business processes and improve security at the same time.

Tuesday

Grid Security Summit Assembles Top Security Experts


Smart Grids
Photo by James Jhs. Creative Commons License Attribution 2.0 Generic

August 6, 2012 By
I have spent the last few days moderating and recording The  Smart Grid Security Virtual Summit which will be webcast on August 9th. I highly recommend this summit. Speakers include a who’s who list of top industry experts who offer their opinions on how to correct the real issues related to securing the power grid.  From what we have done to what we need to do, summit sessions are real eye openers disclosing problems and providing answers to critically needed smart grid and critical infrastructure security questions.

I moderated the panel discussion “Smart Grid Security, Past, Present and Future” which include industry professionals I have previously interviewed for Digital Communities. Bob Lockhart -- a senior research analyst contributing to Pike Research’s smart-grid practice with a focus on cyber security markets -- co-authored a white paper with Research Director Bob Gohn on the Seven Trends to Watch in Utility Cyber Security.  From market projections for this new multi-billion dollar cyber security business to the current state of near chaos in securing the power grid, the discussion was packed with reality checks of where we are and where we need to be in securing the grid.

The panel discussion continued with outspoken industry leader Patrick Miller who views the need for cyber security from both the public- and private-sector sides. Miller is president and CEO, EnergySec and principal investigator of National Electric Sector Cybersecurity Organization (NESCO), a public-private partnership between the U.S. Department of Energy and EnergySec to enhance cybersecurity in the electric sector. Miller suggested less talk and more action in addressing security breach concerns and discussed a high-level view of power grid security.


Ending the panel discussion was Ted Wood , director at Sterne, Kessler, Goldstein & Fox. Wood's job is the discovery and protection of intellectual property in things like smart-grid security. From international cyber security espionage to plain old American ingenuity, Wood offered a unique view to the realities of cybersecurity. Wood leads the firm's Grid Industry Group, where he focuses on helping innovators involved with ensuring power grid resiliency in an evolving smart-grid infrastructure.  His discussion focused on how small business ingenuity can protect intellectual property while fast tracking creative solutions through the bureaucracies of big business and big government.

I spoke in the second panel discussion,  Is Current Legacy IPS And IDS Security Enough For The Smart Grid And Critical Infrastructure?  My presentation focused on how current security solutions may be too costly, too complex and too inefficient for critical infrastructure requirements.  From securing Intrusion Prevention Systems (IPS) that now must securely encrypt the new end point of nano sensors chip sets to Intrusion Detection Systems (IDS) that must now be able to view real time event anomalies and business processes, this discussion showed the need for security technology change. The subject of why we need to look at smart-grid security differently was first discussed in my recent article, Smart-Grid Security Will Force New Ways of Thinking. This presentation expanded on this article and discussed proof points of why new security solutions are required for smart grid and critical infrastructure security.

The second session speaker was Phil Smith, founder and president of TLC Secure who has had a long and illustrious career with senior technical and managerial roles at HP, Cisco, NASA, Lawrence Livermore National Lab and others. He is the innovator, architect and developer of several implementations of mobile devices as well as the cryptographic libraries and identity management components. Smith has worked with critical infrastructure encryption security used in wireless sensors in atomic power plants and Department of Defense applications.  His time tested applications of Intrusion Prevention System (IPS) security showed how true end-to-end security can be achieved for the smart grid.

The last prerecorded panelist, Rajeev Bhargava, is CEO of Decison-Zone and an expert in the information management field that has architected, developed and built next-generation cyber security, risk, fraud and privacy solutions. In 2010, Rajeev Bhargava received a U.S. Patent for the world’s only technology capable of 100 percent fraud and system security protection. Bhargava discussed a completely new way of addressing Intrusion Detection System (IDS) security through the prediction, detection and correction of event anomalies in realtime business processes.  This discussion revealed why current IDS solutions are not enough for smart grid system security.  
Additional session discussions included:


1. Identifying and Mitigating Cyber and Physical Threats to Smart Grid SCADA Systems , William Lawrence, chief technologist; Energy & Cyber Security Lockheed Martin;
2. A Utility Perspective on Smart Grid Security Status and Challenges, Ward Pyles, senior security analyst, Southern Company;
3. Regulators' Role in Smart Grid Security: What They Want to Know, Alan Rivaldo, cyber security analyst, Public Utility Commission of Texas;
4. Recent TVA Experiences and Insight on Smart Grid Cyber Security,John Stewart, specialist engineer, Power Control Systems, Tennessee Valley Authority and
5. Security Issues Surrounding Cloud Computing and Big Data in the Smart Grid, William Souza, manager - Security Integration, Reliability Services Division, PJM Interconnection. 

Click here for more information on the conference which will be web broadcast Thursday 9 a.m. to 5 p.m. EST.

Thursday

Flame Virus, a Controlled Burn?


Don't Play With Fire

May 31, 2012 By
 
In Florida I have a friend who is a park ranger who does controlled burns in hope of curtailing any large park brush fires.  This may be similar to how the new virus Flame is being used. Like any controlled burn, however, there are risks of the fire getting out of control.

We need to come to a consensus on cyberwar. It has officially started and the weapons are improving. The new computer virus nicknamed Flame, also known as Flamer, sKyWIper and Skywiper and Stuxnet 20, is many times worse than its predecessors. It has the capability of specifically attacking its targets and evading detection.

Based on its predecessors Stuxnet and Duqu, Flame can spread to other systems over a local area network (LAN) or via USB stick. It can record audio, screenshots, keyboard activity and network traffic. The program also records Skype conversations and can turn infected computers into Bluetooth beacons which attempt to download contact information from nearby Bluetooth-enabled devices.

These data, along with locally stored documents, are sent on to one of several command and control servers that are scattered around the world. The program then awaits further instructions from these servers.

Taking away the sociological and political ideologies of whose side we are on in cyberwar, the recent cyber attacks demonstrate the current vulnerability of our legacy security solutions. What Flame is doing in targeted Middle East attacks can be done in other countries, even the ones releasing the attack. There is a first response advantage but the technical nature of computer virus propagation could leak the virus to unintended areas as did Stuxnet. Playing with these vulnerabilities is like playing with fire.  

In a recent conference in Orlando Florida, UTC Telecom 2012, the consensus of those who were somewhat involved in cyber security was that there clearly is no 100 percent capability of securing even our critical infrastructure. This concern was further emphasized when keynote speaker Mark Weatherford, deputy undersecretary for cybersecurity for the National Protection and Programs Directorate (NPPD) at the Department of Homeland Security, asked who felt competent in knowledge of cyber security. One or two hands went up out of 500 in the audience. Weatherford responded by saying we need to prepare our workforce and find talent "to prepare the next generation for cybersecurity. Gaps in talent means gaps in security."

Even the Department of Defense is recognizing the need for forging private-industry partnerships on cybersecurity. This makes sense when the Internet and much of the experience behind it will be found in the private sector. There is a clear issue though, for those who have pursued DOD cyber security jobs or partnerships. That issue is secret and top secret clearance.  There needs to be a better way to address needed background checks than the current clearance procedures.

A person with secret or top secret clearance may have little experience in cyber security or tremendous experience in cyber security but no ability to quickly and economically obtain secret or top secret clearance.

We are faced with some tough decisions as they relate to cyber security with few if any quick decisions. With a limited cyber security workforce and clear cyber security vulnerabilities it seems time to look for new security solutions rather than playing with the appropriately named Flame virus. We can’t continue to patch cyber security while thinking we can manipulate these vulnerabilities in targeted cyber attacks. This could and has already backfired.  We have to minimally overlay new security protection or wipe the slate clean and look for new ways of addressing cyber security or this controlled Flame may get out of control.

Larry Karisny is the director of Project Safety.org, a smart-grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure.

Sunday


Smart Grid Security: An Inside View from Patrick C. Miller



Patrick C. Miller

Security is bolted on, not baked in.

May 14, 2012 By
Patrick C. Miller is president and CEO of EnergySec, a 501(c)(3) nonprofit organization formed to support organizations within the energy sector in securing their critical technology infrastructures. A March survey by EnergySec of 100 energy security professionals revealed that two-thirds think smart-grid projects do not adequately deal with security threats. Larry Karisny, director of Project Safety.org, interviewed Miller about the survey and the subject of smart-grid security.

Karisny: Your survey results from top industry professionals seemed to clearly demonstrate a real concern with the lack of security in today’s power grid. Is this what you expected?

Miller: Yes, it isn’t far from what I’ve heard from them over the past few years as we’ve ramped up the grid modernization efforts. Overall, the grid itself is highly resilient, but we are implementing new technologies and new connections without fully understanding the emergent issues that arise with this degree of innovation and complexity.

You stated that we are moving so fast with smart-grid innovation that rather than baking in security we are bolting it on. Does this mean that we will be adding modules or maybe recall retrofits to insure security to some even recently deployed power-grid equipment and devices?

Yes, I speculate there will need to be some unexpected retrofits or replacements for early technology or components. Without question, more security modules, shims or wrappers will need to be employed. Utilities have an expectation that these digital devices will have a life-span somewhat similar to the older analog elements they replaced. For discussion’s sake, let’s say they think the new digital meter will last 15-20 years. How much will the digital technology surrounding the meter change in that same span? How will the attacker landscape change during this timeframe? To give a general comparison, how many new smartphones will you own between now and when this meter is replaced with the “next generation?”

Are personal security concerns legitimate and are you seeing safeguards to protect personal privacy in the smart grid?

This isn’t a hard problem to solve. For example, opt-in/out programs for any data beyond what is necessary for operations could be one solution. Such an approach would provide those who are sensitive to the matter an option that doesn’t immediately involve going backward and ripping out the smart meters. There are some cryptographic protections for the data, depending on the implementation, but the areas of concern often seem to reside in the ownership of the data and how the data may be used beyond the operational needs of the utility (either by the utility or any third party).

One of the positive responses to the survey was a user acceptance of security for online utility payments.  Is this a false sense of security or could the power companies maybe learn something form banks when it comes to cybersecurity? 

Many of the utilities use already existing financial clearinghouses to process payments. I think those that are familiar enough with securing an electric utility know that payment, or lack thereof, doesn’t directly [immediately] affect the flow of power. Power can still be delivered, even if the payment, billing or end-point metering system isn’t perfect.

Standards are necessary in developing industrywide technologies but they also delay solutions from being deployed.  How can we expedite security standards while keeping pace with smart-grid technology deployments?  

Take a page from Nike and “Just Do It.” We can move as quickly as we want. Moving too fast isn’t the best approach, but neither is moving too slow. My personal belief is that we’re past due for standardization. I think some of the churn has been around governance of the standards and not the standards themselves. Maybe some flexibility in this area might let everyone feel more comfortable, resulting in more substantial movement.

Can you give examples of some of the security innovations that you are currently reviewing and testing?

Our organization does not do this research directly, but we are involved in many security-related conversations on the subject of grid modernization software and hardware. I know many vendors are at least thinking about the problem and how to solve it. A much smaller number of vendors have solid traction and are implementing security at a pace that equals innovation of new features. Even fewer are at the tip of the sword with a holistic model that balances cutting-edge innovation with proven security development approaches such as thorough code review and rigorous supply-chain management.

How can we “architect” a sustainable power grid without having as you said a “spare power grid” to test and deploy fixes?

Infrastructure isn’t inexpensive. Building a full-replica spare is as costly (or more) as building the original. The most cost-effective approach is to use representative platforms, virtualization, simulators, emulators, etc. I think everyone understands that “testing in production” is at the edge of the risk spectrum. It may or may not go wrong for any one specific test, but if it does, the consequences may be severe. For any new system deployed, a portion of the project budget should be allocated to include a satsifactory test (or quality assurance) environment. This is an unpopular position to take in such a tight economic landscape because it can add significant cost to any endeavor.

We talk about security in the power grid because that is our focus. Isn’t there a lot more “smart” that needs to be secured in other industries and the smart grid may be just the start?

This is an area of interest for me. I think we are ultimately seeking a modernized power system that is somewhat self-aware, self-healing and self-managed. This implies an emergent intelligence much like a flock of birds or school of fish. They are all unique individual organisms (devices), but they can operate with a collective, emergent intelligence as a single unit when dealing with threats, obstacles, food (fuel) sources. Securing the entire environment in a utility will be profoundly different when we achieve this state.

It is far too expensive to entirely replace the legacy grid components with the newer “smarter” elements, so there will still be a fairly substantial base of analog, electromechanical and “old” or “dumb” devices in the grid. This aging equipment will be working alongside tomorrow’s amazing new intelligent gadgetry, maybe even in the same rack. Securing this breadth of historic and future technology will be our greatest challenge for the security profession in the electric sector.

Larry Karisny is the director of http://www.projectsafety.org/home.html Project Safety.org, a smart-grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure.

Wednesday

Smart Grid Security, Challenges and Change

Smart Grids 3

April 18, 2012 By

Larry Karisny is the director of Project Safety.org, a smart-grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure.

With former CIA director R. James Woolsey, Jr., wanting to attack smart grid security threats -- the FBI documenting low- and high-tech electrical theft, and Homeland Security reporting 86 attacks on computer systems in the United States that control critical infrastructure, factories and databases -- you would think that the deployment of smart-grid security would be put on the fast track to an immediate solution. Well let's see.

The Smart-Grid Security Circus
If you were to review where we are today in addressing the need for cyber security in our power grid you would find a lot of starts, changes, delays and even do-overs. NERC Critical Infrastructure Protection (CIP) is working on version 5 of its cyber security compliance, and release 2.0 of the NIST Framework that includes updates to many of the 75 standards from Release 1.0 while adding 22 more. To add to the confusion, there is a brand new organization creating new alliances to support the certification and promotion of an interconnect standard for wireless smart-grid devices. The cost and time of trying to become compliant with these guidelines and standards will put smart-grid security years off before it can achieve any agreed-upon security solutions. With immediate security needs evident, there must be a way out of what people in the security business are now calling the "smart grid security circus."

We can’t just throw something on the wall when it comes to critical infrastructure security, but business as usual isn’t going to help either. The bureaucracies and oversight groups are becoming so numerous that large organizations can't get anything done and small entrepreneurs -- that may be holding the solution in hand -- can't afford the time and cost of going through the endless oversight, compliance and standards processes. No one knows this better the EnerNex, a company that offers innovative and professional electric power research, engineering and consulting services to government, utilities, industry and private institutions. In a discussion with Erich Gunther, Chairman and CTO of EnerNex, he stated "simply being compliant with a security standard such as NERC CIP doesn't mean that your grid is secure."

“While I would never characterize the grids as bulletproof," said Pike Research Analyst Bob Lockhart, "I believe that the operations teams have built in safeguards at the physical level that we don’t understand. That still doesn’t excuse the behavior regarding cyber security. Also the lack of standards – other than CIP, which considers distribution grids out of scope – hinders almost everybody from making a decision. You might check out the white paper we just released – my section (trend #4) addresses that.”

Robert Former, head of security research and testing at Itron, said the smart grid security circus is "The sound of [a] paradigm shifting without a clutch,” Former -- quoted in a blog -- continued: “Utilities have to be more enterprise security-aware. With these incidents at organizations of any size or age, the first reaction is to cover it up. The thinking is if we keep this kind of thing secret, nobody will find it or exploit it. But for those of us who are inside the industry, and have been at this long enough, the only way we’re going to fix a security problem is to expose it.” The key words in this quote are "paradigm shift," "cover up," and "exposure." These words require drastic change in what and how things are currently done in addressing smart-grid security.

Change is a Security Requirement not a Luxury
There are those saying that power grid security could best be addressed by not changing and keeping legacy power grid-island security (standalone service centers not interconnected) or that smart meters should be kept dumb. I can assure you these are just not viable options. We need to first consider the tremendous benefits that would be lost and minimally the economic efficiency, stability and security that could not be achieved if we kept legacy systems in place. In security, for instance, both legacy electromechanical and digital smart meters can be breached by rather low-tech methods at the meter location. The only way the breach could be remotely detected is if the breach was realtime and intelligently connected to the smart grid. I referred to these new intrusion prevention systems (IPS) and intrusion detection systems (IDS) security capabilities in my last article, “Smart-Grid Security Will Force New Ways of Thinking.” Electrical theft including legacy meters in India is estimated at 40 percent and is the main reason they are adding intelligence to their power grid. From simple theft to international espionage, there are too many critical security benefits offered by power-grid intelligence to turn back to legacy operations that may seem secure. We must move forward in deploying the required changes to rapidly support current and future requirements in securing needed power-grid intelligence.

We Are Securing System Architecture
System security was the big disconnect that I saw on the smart grid. Coming from a network background, my initial discussions with power companies and meter companies were a little confusing at best. After many discussions and a few explanations, I at last found that today's power grid is just a bunch of sometimes connected operational islands. From the stand-alone power substation to the dumb power meters, in most cases nothing was connected to nothing. With this type of stand-alone system background it was no surprise to me that there was limited knowledge of network and system security and some rather different ways of addressing power grid security though physical operational security.

So we went from nothing to securely connecting sometimes real-time data from every home to a limited and sometimes non-existent power company network infrastructure. This was a bit much for power companies to address all at one time while looking at staged-system approaches in building both network and system security. Even meter companies merging with wireless mesh and modular gateway companies are just now starting work with security software and chip-set companies in addressing these new system architectures. In fact Pike Research has identified the "system architecture" approach as one of the top 10 smart grid trends to watch in 2012.

Can Current Legacy Security Technologies Secure the Smart Grid?
To properly answer this security question I think we need to look at two critical requirements that have changed in the smart grid. If the network demarcation is now the smart-meter optical-communication port, then what are you connecting your smart meter to? This new and previously undetected network edge point of breach is now the new end of true end-to-end smart-grid security. This now changes the end point of intrusion prevention system security and the technologies that can achieve it. Two, internal and external real-time network and business process security requires real-time intrusion detection system security.

This changes current IDS solutions that currently collect historical intrusion data and now requires the capabilities of addressing real-time anomaly detection and even predictive security breach capabilities. Few IPS and IDS security solutions even offer the capability of these true end-to-end and real-time data-security requirements. We are reaching a new need and maybe a new way to address these new security requirements.

As power company and communication companies go through their collaboration culture shock, security companies who historically never talk to each other are going through theirs too. They now must now all collaborate on new security requirements and open the doors on how to achieve them. Even current security solution companies must change their way of looking at security if they are expecting to address the unique security requirements of the smart grid.

Conclusion and Recommendations
I can't emphasize enough the importance of moving forward in addressing these critical smart-grid security requirements. After covering this security issue for a few years I have come to the conclusion that we are still fighting the uncomfortable issue of change rather than keeping our eye on what we are trying to accomplish. Sometimes we are dealing with more people than technology issues and sometimes too much technology and not enough people issues. To this I offer these suggestions in adjusting to change while staying focused on the goal.

1. Don’t surrender to complaints
People are normally suspicious of change especially when it involves big business and big government. From discredited wireless radiation concerns to personal privacy issues, the hype of these complaints many times outweigh the facts. The complainer and naysayer often do not have the whole or big picture. Given the opportunity they should be asked would they be willing to pay 4 times as much for electricity by not having the smart grid? Change is something that is difficult for both energy producers and energy users. With change comes complaints and suggestions, both of which have value in tweaking the proper goal without drastically changing or eliminating it.

2. Remember you are your history
The power generation and distribution companies have a tremendous history of innovation with safety and security always the top priority. This track record should be leveraged with the understanding it started with people complaining that electricity was too dangerous to distribute. These people and technical challenges were no different than the difficulties that power companies had to address in the beginning of electric power production, transmission and distribution in the past. Today’s electric power industry needs to be addressed with the same creative innovation and leadership that was done in the past.

3. Expect the unexpected
When deploying new technologies you should expect and be prepared for the unexpected. For instance when we put IPS and IDS security in the network, these technologies should be able to adapt rapidly (if not real time) to any needed changes that occur in the smart grid. If current security technologies do not offer these capabilities, do not underestimate that you may need a complete paradigm shift to achieve the needed security requirements. Paradigm shifts are not always comfortable or easily understood but are sometimes the only avenue of doing things right.

4. Know elements of victory
Government and communication companies invading the power companies space was at best uncomfortable. We should recognize the differences between government, companies and technology providers but never take a “are you for us or against us” attitude. People must work together, carefully listening with proper leadership in charge following the plan. That is when things get accomplished. That's when victory occurs.

5. Don’t fall short of your goal
I am shocked when I hear comments from the naysayers of the smart grid that think we can just stay at status quo. We need to focus on the goal and the tremendous benefits the smart grid will bring and address the critical security issues it now faces that could flat out just turn it off. Like power companies did in the past, they simply need to step up and try again.

Thursday

Smart-Grid Security Will Force New Ways of Thinking


Ignoring critical infrastructure security problems is no longer acceptable.

January 4, 2012 By

Editor’s Note: Larry Karisny is the director of Project Safety.org, a smart-grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure.

Security attacks are real, validated, and are becoming more costly. According to security expert John McNabb, electric utilities assume they suffer about 10 percent losses to theft each year. The Edison Electric Institute estimates that in 2009, electric power companies earned more than $352.5 billion. That puts electricity theft alone at more than $35 billion, and doesn’t include the cost of peak production premiums and power outages that cost an additional $80 billion annually. All this could be curtailed by making the power grid intelligent and secure.

Adding intelligence to just the demand side of the power grid could produce savings estimated to be as high as 26 percent — a finding announced last month that came from a smart grid contest in Texas. Even with the cost of smart-grid upgrades estimated at $1.5 trillion by 2030, the efficiencies of adding secure intelligence to the power grid seem cost-effective. But none of this will happen without effective security.

Power grid security isn’t just about money. Personal security and national security are at stake. Appearing before the Senate Armed Services Committee in June, then-CIA Director Leon Panetta said, “The next Pearl Harbor could very well be a cyberattack that cripples our government, security and financial systems.” Power companies are beginning to take these threats seriously and are even beginning to disclose these threats in SEC filings. Con Edison isn’t the first utility to disclose cybersecurity as a serious threat in SEC filings, but it’s perhaps the first to describe cyberattacks as a stand-alone risk category. Failure to disclose such breaches or to follow North American Electric Reliability Corp. (NERC) compliance can cost power companies a million dollars a day in mandated penalties.

The threat of endangering personal data from hacked smart meters was recently demonstrated by Tony Flick and Justin Morehouse in a presentation at Defcon 18, which is available in its entirety on YouTube. Flick earlier wrote “Securing the Smart Grid: Next Generation Power Grid Security”, warning of these projected breaches. Threats to personal security and the national power grid are reaching critical mass.

Smart-Grid Security Chaos, Compliance and Collaboration

So how are we doing on securing power infrastructure? The latest Pike Research report on grid security said, ”Utility cybersecurity is in a state of near chaos.” With concerns about the chaos of vendors and regulations, Pike Research also observed a dawning awareness by utilities and vendors during the past 18 months of the importance of securing smart grids with architecturally sound solutions. But correcting these problems might be slowed down by spending billions of dollars on meeting federally mandated security compliance — rather than investing in the development and testing of security solutions.

There are signs, though, of a focused collaboration from the public and private sectors in methodologies to rapidly deploy grid security. A new demonstration project will be conducted jointly by partners Sensus, EnerNex and the Department of Energy’s Oak Ridge National Laboratory addressing this critical need for security. The three partners will collaborate on the project, dubbed the Automated Vulnerability Detection (AVUD) system. The system uses function extraction (FX) — a disruptive new technology platform that can detect and fix software-hardware issues before they become big problems. The system is designed to keep a step ahead of security threats rather than playing catch up as we are now doing.

Intrusion Prevention and Detection Are Key

Complexity within the smart grid boils down to several points. The “smart” part of the grid is a sensor talking to a communication link connected to a database. This is further simplified by the sensor and database information being basically a machine-to-machine application passing consistent data though the network.

In the simplest terms, security breaches occur basically for two reasons. The network wasn’t secure to begin with or someone got in that shouldn’t have. The industry separates these categories into two separate security solutions: One is called Intrusion Prevention Systems (IPS), and the other is called Intrusion Detection Systems (IDS). The two capabilities, combined in a security system, can pretty much keep the bad guys out.

The problem is we can no longer look at IPS and IDS solutions of the past when trying to secure the enormous amount of data now in the grid data. The old way of doing this is just too expensive, too complex, too slow and frankly doesn't get the job done. We must look for ways to simplify and improve security solutions.

New Applications Require New Thinking

Adding security solutions to the smart grid likely will be a massive task. With predictions of 1 trillion intelligent devices connected by 2015, we must learn quickly. These devices are no longer just computers or telephones. There are now billions of microchip devices with small processors offering specific “Internet of things” functionality that often doesn’t require any human intervention. These machine-to-machine devices are the new nerve endings of networks and applications; these devices offer intelligence to a variety of venues, from national critical infrastructure to intelligent home systems. The difference today is that we now have moved the demarcation of network intelligence from typical communication radios or gateways to intelligent microprocessing chips within smart devices. With this type of volume and small processing power, we need to look at new ways of adding security to intelligent networks and applications. Large companies like IBM, Lockheed Martin and Accenture are positioning themselves for a piece of this new $40 billion smart-grid security market. They are spending millions on development and are looking for partners and acquisitions in support of their solution product portfolios.

TLC Secure Inc., a company focusing on intrusion prevention in smart-grid security, looked at the potential complexity of managing Public Key Infrastructure and decided to offer a Layer 2 vendor and protocol-agnostic solution. Phil Smith CEO of TLC Secure Inc. said, "Sensors and their internal communication ports have been defined as the new point of breach in smart meters, as have SCADA operations in the smart grid. By encrypting at Layer 2, we secure everything above it and solve a lot of the vulnerabilities —and the problem of too much diversity and overcomplicated Layer 3 solutions with too little interoperability. This yields stronger blanket security, and greatly simplifies it as well.”

A white paper by John McNabb and companies like InGuardian and IOActive have already verified breaches in smart meters. Layer 3 network security alone is no longer the defining demarcation point of network security. Realizing this, TLC developed a security solution “offering true end-to-end IPS by securing the weakest link of smart networks, from database to the smart meter chipset."

Smart Networks Require Real-Time Detection

With many smart-grid database feeds now being real time, even Intrusion Detection System security needs to be looked at differently. A recent white paper written by Dr. David Chalk presented a new way of looking for real-time data anomalies, in a detection technique called “cyber forensics.” Rather than waiting for an unknown virus to be recognized by a massive global database, Decision Zone's approach historically mirrors what the smart application should be doing and then detects in real time any changes in these defined anomalies. Smart-grid sensor data is relatively simple and consistent, so these application parameters can be securely checked in control systems while flagging any changes in the defined application.

Chalk said, “Just the smart grid alone will collect massive amounts of data. With this much data being collected, typical IDS data-centric approaches for protection of the smart grid won't work. A paradigm shift to ‘process-based audit’ is needed. Decision Zone uses a discovery technology to generate the underlying process then adds a live causal audit application that can then identify any anomalous event to the underlying process prior to failure.“

Conclusion

We are trying to use older security technologies to secure more networks and network applications than we ever have. There is a rule of thumb in security that must be addressed if we are to move forward in protecting these massive intelligent networks: If we make the security solutions too expensive, too difficult to operate or too slow, people won't use them.

We must find simpler and more economical ways of addressing these critical needs in intelligent security. Securing the smart grid will be the defining proving ground for the new security solutions that will safeguard intelligent applications today and in the future. We need to focus on the funding and development of these critical security technologies if we are to enjoy the benefits of the future’s intelligent network applications.

Monday

At Issue: How to Protect the Smart Grid From Cyberattacks



Electricity systems and the smart grid are becoming big targets for hackers. Photo courtesy sylvar / Flickr CC

October 31, 2011 By

Vehicles speed toward a railroad crossing as a train approaches. But the warning lights stay off and the gates remain open. Traffic signals blink out at numerous busy intersections, snarling traffic for miles. Pressure in a residential gas line spikes but sensors fail to warn the utility. A nuclear power plant overheats but the safety systems indicate things are normal.

Such systems — termed Supervisory Control and Data Acquisition (SCADA) — run unnoticed when functioning properly, but a malfunction can mean catastrophe. And now, added to the normal vulnerabilities in any mechanical or electrical system, are some new threats. These systems are now targets of cyberattacks from individual hackers, groups with some social or political agenda — even nations intent on creating havoc.

The threat is not science fiction. In an experiment caught on video and released on the Internet, an electrical power generator is hacked and damaged remotely. According to CNN, the experiment, dubbed “Aurora,” was conducted in 2007 by the U.S. Department of Energy. “DHS acknowledged the experiment involved controlled hacking into a replica of a power plant's control system,” said a CNN article. “Sources familiar with the test said researchers changed the operating cycle of the generator, sending it out of control.”

For more than 10 years hackers have managed to disrupt, damage or stop the operation of critical infrastructure. A report from the Black Hat information security conference outlines some of the better-known incidents. In 2000, hackers gained control of Russia’s Gazprom natural gas pipeline network, and in 2003, a worm attack shut down an Ohio nuclear power plant safety system. And computers seized in Al-Qaeda training camps had data on SCADA systems for dams and other infrastructure.

According to one industry paper, less well-known but more insidious attacks have been occurring for at least five years. Perhaps the most sophisticated attack of all was a Stuxnet worm attack on Iran’s uranium enrichment program, blamed by some on the U.S. and Israel.

In September, the Department of Homeland Security released a bulletin warning of threatened attacks on infrastructure by so-called “hacktivists.”

So what can utilities and local governments do to reduce vulnerability? One common-sense approach is to avoid exposing these systems to the Internet. A tutorial by DPS Telecom says: “For security reasons, SCADA data should be kept on closed LAN/WANs without exposing sensitive data to the open Internet.”

But removing SCADA networks from the Internet might prove expensive. “Using the Internet,” reads another industry report on the subject, “makes it simple to use standard Web browsers for data presentation, thus eliminating the need for proprietary host software. It also eliminates the cost and complexity of long-distance communications.”

As systems become more complex, intelligent and networked, some security problems may be solved while others are created. Larry Karisny, a frequent contributor to Digital Communities on the subject of the smart grid, answered some questions about this arcane but essential subject.

Digital Communities: How does one differentiate between all the different types of industrial control systems?

Karisny: The capabilities between these systems are beginning to blur in functionality as the technical limits that drove the designs of these various systems are no longer as much of an issue. From legacy telephony connections to small embedded controls attached to an industrial computer via a network, we are entering a whole new world in critical infrastructure system design. When you start interconnecting these system design functions you start detecting existing security problems or need to find new ways to secure these needed power-grid upgrades.

Historically weren’t SCADA systems closed and very hard to penetrate? For example, to disrupt the electrical supply in the past, someone would have to attack the physical components?

One of the biggest fears of power grid attacks is physical. When reviewing the components of the power grid, there were potential single-operator catastrophic physical vulnerabilities found in facilities. With a single lock on a door and no way of viewing the operator, video cameras are now put in power grid locations — understanding that even physical components and human intervention can add to security vulnerabilities. Some of the most catastrophic power generation failures were caused by a combination of equipment failure and operator error and/or human error. Adding intelligence to SCADA systems can actually offer instantaneous information that could detect and detour catastrophic energy production errors. Keeping the power grid dumb is really not an option in securing today’s power grid.

Some say, “For security reasons, SCADA data should be kept on closed LAN/WANs without exposing sensitive data to the open Internet.” Is that principle being violated? If so, why?

I recently participated in a webinar Duqu, the Precursor to the Next Stuxnet hosted by Security Week with Kevin Haley, director, of Symantec Security Technology and Response. Interestingly some SCADA system breaches in Europe were stand-alone closed systems. With investigations still in process, even these seemingly closed systems were breached without access from outside networks.

As for open Internet connecting to sensitive data, the answer is not just “Don't put Internet access in” — but also keep it out. I was in an SRI International research extension and showed the research facility director 10 SSID’s capable of campus wireless Internet access, including an unsecured connection from the coffee shop down the street. Add this to your closed LAN/WAN port access with some SCADA OS [operating system] software offering backdoor vulnerabilities, and what you consider a closed system may not be closed at all.

Some regions are rolling out smart-grid projects which provide feedback to households so customers can adjust energy use, get better rates at off-peak hours, and even generate their own power and feed it into the grid to “run the meter backward.” Won't all these additional network access points increase the vulnerability of the grid to hackers?

The main business case for adding intelligence to the power grid (smart grid) was based on collecting electrical demand-side usage information. By knowing peak and off-peak electrical usage (combined with rewarding or penalizing end-user habits) peak power production capital overbuilds and production operational costs could be greatly reduced. Some estimates showed that power production could be reduced by as much as 30 percent, sometimes completely eliminating the need of building a new power plant to the grid.

In addition, if new alternative energy resources were to be added to the power grid there needs to be measured intelligence capabilities to credit the addition of these new energy sources. Without adding intelligence to the electrical demand-side network edge, these demand-side benefits in our current power grids could not be achieved.

As millions of smart grid edge devices (smart meters) were deployed, security concerns became an issue. These security concerns are nothing new to power companies. Legacy electromechanical meters have been run backward for years and are one of the main reasons (preventing electrical theft) China and India are upgrading to smart meters. We need to add network edge intelligence to our power grids while securing the collection of information from the device chip set to the local power-grid data collector. Connecting millions of these smart meters with end-to-end security needs to be done and can be. Smart grid networks should be designed to limit potential network demand-side breaches while isolating internal SCADA systems and networks from demand-side systems and networks.

What can local governments do to lower the vulnerability of critical city and county utilities and other SCADA-managed systems?

Power companies are not the only entities needing to upgrade security for their SCADA systems. SCADA is used in many critical infrastructure systems including manufacturing, production, power generation, fabrication, refining, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines, electrical power transmission and distribution, wind farms, public safety, civil defense, large communication systems, buildings, transportation systems, airports, ships and even space stations. As these systems begin to connect to other control systems they all need one thing in common: a private local wireless and secure IP network.

With tight city and county budgets, building a private IP network for most cities and counties is out of the question. Collaboration with multiple government agencies and private-sector communication entities needs to occur if they are to accomplish the building of this secure network supporting critical infrastructure systems and applications. Building a network for the smart grid offers a big opportunity here. The power company could be the seed anchor tenant because it already owns massive communication fiber-optic and wireless infrastructures and has deep pockets in capital investment for supporting these needed local network upgrades.

Cities and counties have the relationships with the power companies and sometimes even publicly owned assets to support these network build-outs. The smart grid should be viewed as the first step in building the networks we need in securing local SCADA critical infrastructure. Collaboration by the public and private sectors can make this happen. In addition, edge security solutions available today could allow the economical and secure sharing of these needed local wireless IP networks for multiple users and applications. These steps would address the vulnerabilities while reducing the costs of these critically needed security requirements of city and county critical infrastructure.

Wednesday

The Stuxnet 2, Coming to a SCADA System Near You!

Smart Grids 4
Smart Grids

Hackers Target Critical Infrastructure

October 26, 2011 By

With a new Stuxnet 2 (W32.Duqu) now found and the Department of Homeland Security warning of a possible security attack by Anonymous, it probably is a good start to define some security solutions to protect these critical infrastructure targets. Breaching these supervisory control and data acquisition systems (SCADA) could bring our country’s safety and economy to their knees.

One good thing that came out of designing intelligence for the smart grid was we that had to take a look at how to securely integrate some old, transitioning and new-grid technologies into stand-alone, local or regional control centers. A big part of these control centers are SCADA systems that monitor and control industrial, infrastructure and facility-based processes. These control systems in many more areas than the power-grid facilities. They can be found in manufacturing, production, power generation, fabrication, refining, water treatment and distribution, wastewater collection and treatment, oil and gas pipelines, electrical power transmission and distribution, wind farms, civil defense sirens systems, large communication systems, buildings, airports, ships and space stations, just to name a few. Some of the debilitating security warnings that were found in the smart grid unfortunately are not limited just to power-grid SCADA infrastructure.


No matter how new or old the technology, there are tremendous concerns about how to secure these core supervisory control systems and their interconnected intelligent networks. Whether physically pulling down a mechanical switch, pushing a button on an electromechanical device or operating an intelligent smart grid from a centralized network operation center
(NOC) — they all have inherent security vulnerabilities. There are those who say that we should delay any digital intelligent modernizing of our power grid. So while moving forward, we need to do this in stages, watching security at every point.

Richard Clarkes bookCyber War warns of cyber-attacks on the smart grid but also demonstrates an existing ability to breach and take down our legacy power grid infrastructure. Simply doing nothing is not an option in securing the power grid or any critical infrastructure. Countries like India, China and Brazil are moving forward with smart-grid deployments as fast as they can. They recognize the benefits that intelligent networked systems would offer in eliminating power theft while improving their global energy cost competitiveness. They see these benefits far outweighing any catastrophic system security breach and have massive smart-grid deployment in process. So what are the real answers in addressing critical infrastructure security today? Just three things need to be done, and they need to be done simultaneously.

Evaluate Current Security Vulnerabilities

From physical security, to legacy and extended networks, there is a lot of work to be done to address critical infrastructure security. Critical infrastructure facilities can't just hunker down and hope an attack doesn't happen. From simple personal procedures to complete intrusion detection studies, the potential vulnerabilities must be targeted before they are breached. There are automated methodologies that are being developed, though, that may rapidly address these requirements.

To expedite and future-proof security evaluations, Sensus, EnerNex and the Oak Ridge National Laboratory (ORNL) are working on an advanced security demonstration project called the Automated Vulnerability Detection system (AVUD). This project is aimed at developing a cyber-security system for smart energy meters and other advanced grid technologies. The project will use a Function Extraction (FX) technology evaluation platform developed by ORNL to find and fix security issues before they actually cause problems. The initial project is targeting advanced meter infrastructure (AMI) systems. With millions of smart meters ready to deploy, this can't happen soon enough.

Focus on Prevention

If there was ever a security industry award for the best metaphor, the word “virus” perfectly explains what can happen without preventive measures in systems and network security. Just like measures against colds and flu, it seems we are now beginning to focus more on prevention than detection. This is why intrusion prevention systems (IPS) are so critical in SCADA systems. IPS can securely cloak systems with frame-to-frame encryption even to the layer 2 level. This could eliminate port and application vulnerabilities right down to the device chip set. It can eliminate man-in-the-middle (MITM) spoofing/sniffing risks or denial-of-service (DoS) vulnerabilities while enabling strong security on even legacy devices.

Because IPS is inline with the traffic flows on a network, it can shut down attempted network edge attacks, stop attacks by terminating the network connections or user/device session origination. Attack responses can include targeting from the user account, IPS address or other attribute associated with that attacker, or blocking all access to the targeted host, service or application. It seems like an obvious first choice. Don't let the security breaches in.

Detection and Prevention a Natural Mix

Then there is an intrusion detection system (IDS). This system is passive, watching packets of data traverse the network from a monitoring port, comparing the traffic to configured rules, and setting off an alarm if it detects anything suspicious. With Stuxnet 2 (W32.Duqu) now a big concern, we need systems that can detect these now more serious security attack methodologies. These new attacks are now targeting information for SCADA systems used to control machinery and other key critical infrastructure operations.

Although IDS has great value, just seeing the problem is not enough. There must be system security solutions put in place to immediately react to security breaches. This is why bundling both IPS and IDS solutions together seems to be the direction many companies are taking in their security product lines, including recent corporate mergers and acquisitions.

In Conclusion

The AVUD project by Sensus, EnerNex and the Oak Ridge National Laboratory is a good sign of public-private sector cooperation in addressing critical infrastructure security. There has been too much oversight and finger pointing in the past and not enough action. Hopefully the responsible collaboration will be used as a model of how to work together in securing our critical infrastructure. This sure will be different than the “build first, then secure it” methodologies that have been so prevalent in the past. Look at security first and prepare for the future security risks. This is almost too good to believe.

Sunday

Securing the Intellectual Property of Smart Grid Security

Theodore Wood

A unique view to the realities of cybersecurity.

August 25, 2011 By

Theodore Wood's job, at D.C.-based Sterne Kessler Goldstein & Fox, is the discovery and protection of intellectual property in things like smart-grid security. From international cyber security espionage to plain old American ingenuity, Wood offers a unique view to the realities of cybersecurity.

Karisny: Your Grid Industry Group responsibilities for Sterne Kessler Goldstein & Fox include an interesting intellectual property focus, especially in light of the recent cybersecurity attacks. I am beginning to wonder which IP we are protecting, Intellectual Property or Internet Protocol. How serious do you see these attacks and is our critical infrastructure like the power grid a target?

Wood: Our Grid Industry Group focuses on companies that innovate to protect and enhance the resiliency of our power grid. And cybersecurity is one of the primary areas where companies are heavily innovating. Therefore, we follow the cybersecurity challenges, technologies, and guidelines pretty closely. With respect to the cybersecurity attacks, I think you're referring to recent attacks on the IT (information technology) systems of targets such as Sony's online gaming site, various government sites like the senate and the CIA, companies such as Google, a host of credit card companies and several others. We absolutely see these attacks as extremely critical, primarily because they seem to demonstrate a level of success, persistence and an increasing level of organization by the attackers. Fortunately, it doesn't appear that our critical infrastructure has been attacked in the same way as these other sites. But there is little question that critical infrastructure, like the grid, will eventually be targeted. And a successful attack on the grid would be totally devastating, with national security implications.

We all are familiar with former CIA Director Leon Panetta's comments stating that the next Pearl Harbor could be a cyber attack that cripples our electric grid. I'm also reminded of a recent story by Good Morning America, relying on a report from the Department of Homeland Security. This story noted the possibility that sabotage by insiders at a major utility facility could provide Al Qaeda the opportunity for a massive September 11 anniversary attack. And Richard Clarke, in his new book entitled Cyber War, states that the "clearest example of vulnerability brought on by computer controls happens to be the one system that everything else depends upon: the electric power grid." These are just a few examples of recent public comments about vulnerabilities of our critical infrastructure.

Karisny: The words Cyber, Internet, IT and IP sometime get blurred when they are actually very different especially when it comes to security. Can you give some examples that may differ?

Wood: A big part of the reason for the increased risk is due to the Internet Protocol based networks that interconnect our critical infrastructure to global networks. The interconnected systems may be an IT system, or an industrial control system (ICS). Traditional IT systems include components such as routers, network interface controllers and servers. A traditional ICS includes components such as distributed control systems (DCS), supervisory control and data acquisition (SCADA) systems, and programmable logic controllers (PLCs), all of which are used in industries like water, transportation, manufacturing, oil and natural gas, and electricity. These ICS components do things like facilitate data collection from remote locations, control valves, trip breakers, operate relays, monitor alarms etc. Many of these ICS components are integrated with various legacy systems that were not developed with security in mind. The Internet Protocol considerations play a big role because most often the underlying protocol provides the extensive connectivity by which unauthorized and/or malicious persons, machines, or code gain access to these critical systems. But cybersecurity must also consider factors that are unique to each type of system, whether IT or ICS, to ensure that even if unauthorized access is made, damages can be minimized.

Karisny: Knowing networks are different, where should we be focused in protecting critical infrastructure security?

Wood: In my view, the IT/ICS distinction I just mentioned is significant to the discussion of where to focus cybersecurity solutions. Here is the significance: There is a growing recognition that cybersecurity solutions designed for IT systems may not apply to an ICS. Additionally, ICS have different performance and reliability requirements that typical IT support personnel may be unfamiliar with. On the other hand, there are some similarities between ICS and IT systems that create an overlap with some of the cybersecurity solutions. For example, many of the lower-cost IT solutions are now being applied to ICS. But many of these IT solutions fail to provide the security isolation needed by an ICS. As I mentioned earlier, ICSs are employed extensively in our critical infrastructure which creates these sorts of unimaginable consequences if attacked successfully.

A recent Homeland Security Newswire story ... pointed out that the large number of high profile cyber attacks on major corporations and government entities has driven a sharp increase in cybersecurity spending. I would submit, however, that the majority of this spending has been on IT cyber security and not necessarily critical infrastructure ICS cybersecurity. Therefore, we still need something to spur or trigger R&D, innovation, and investment in critical infrastructure ICS cybersecurity. I believe the trigger for this additional R&D, innovation and investment is quality intellectual property (IP). By providing creative incentives, the U.S. Patent and Trademark Office (PTO) can play a pivotal role in the development and protection of IP related to ICS cybersecurity. And if done correctly, this would help ensure that cybersecurity innovations and technologies are more commercially attractive for vendors to develop and for investors to fund.

Karisny: You come from a military background that addressed security on a "need to know" basis and we now live in an age of social networking. Is there some common-sense approach to protecting Intellectual Property in this very open world we live in?

Wood: When I was active duty Air Force, we would simply stamp everything as "secret" and ask questions later. I'm of course exaggerating, but only just a little. For very good reasons, many innovations related to cybersecurity and encryption have been kept by companies as "trade secrets." And there are still a lot of good reasons for protecting IP in this manner. The problem today, however, is two words: "social networking." Twitter, Facebook, LinkedIn discussion groups, and professional blogs provide excellent forums for in-depth technical discussions. I participate in many of these discussions and monitor many others. But when you read the content of these discussions carefully you can't help but wonder how much of the information being discussed, perhaps unknowingly, is some company’s trade secrets. And once publicly disclosed, a trade secret is no longer proprietary and can be used by a company's competitors. Social networking also, unfortunately I might add, provides a convenient way for a disgruntled employee to easily and maliciously disseminate large amounts of proprietary information. Therefore, the tendency to rely only on trade secret protection for all cybersecurity and encryption innovations may be too risky. So wherever possible, companies should protect their key IP by filing for patents early in the development process. Once you file for patent protection of your idea, most of the issues related to trade secret protection, such as those noted above, disappear.

Having said that, the military’s "need to know" based policy was directed at national security concerns. Some of the innovations for cybersecurity, even in the defensive sphere, may be considered as important to national security. The PTO has a procedure to filter such applications and process them separately, striking a balance between protecting national security and protecting inventor rights.

Karisny:. Do you think the stimulus funds directed towards smart meters and not security may be the cart before the horse?

Wood: Don’t want to go that far, but there is certainly an imbalance that must be corrected. Smart meters serve an important consumer function enabling a much more efficient use of electricity, which benefits electricity producers and consumers. As you may be aware from a recent Forbes article, about 75 percent of 2009 stimulus dollars were directed to smart meters. I'm not advocating reducing the amount of spending on smart meters. But I do believe that we need to increase the amount of spending in ICS cybersecurity. As I stated a little earlier, we need to create more incentives for companies and individuals to innovate and invest at the infrastructure end (ICS) rather than, or as well as, at the consumer (IT) end. Grid security used to be exclusively the concern of the power generation companies. But this is no longer true with the expansion of smart grid. A lot of new players are in positions to play a role in securing the grid. So healthy competition can also be used to trigger innovation in this field. Increased spending can certainly help this process.

Karisny:. If we are to address security in areas like the smart grid, how should you protect the Intellectual Property that in turn will protect the network? Power companies are saying who are you, come on in, lock the door, sign this very enforceable non-disclosure and don't expect to get your tested equipment back. What are your suggestions for Intellectual Property protection in this sensitive area of critical infrastructure security?

Wood: I believe the answer to this question is creativity and innovation. Before addressing the IP aspect of your question, I would like to comment on what I mean by creativity and innovation. This past June, I had the privilege of attending the annual conference for a group called the National Electric Sector Cyber Security Organization Resource (NESCOR), managed by the Electric Power Research Institute (EPRI). I think that NESCOR is a pretty creative and innovative concept. NESCOR is the research and analysis arm of National Electric Sector Cyber Security Organization (NESCO) which is a public-private partnership that serves as a focal point to bring together utilities, federal agencies, researchers, vendors and academics. And from what I understand, they're kind of a think tank that helps focus cybersecurity R&D priorities, collect and analyze critical infrastructure vulnerabilities and threats, as well as collaboratively develop solutions in real-time. This group was established by Congress and is funded by the Department of Energy to act as a quick reaction solutions oriented group of super smart people. I believe that groups like this public-private partnership will be crucial to the development of ICS cybersecurity. I also believe that groups like NESCOR make it easier for power companies to discuss potential vulnerabilities in a forum that focuses on solutions instead of penalties.

In my opinion, IP professionals should be involved in these public-private partnerships. By partnering with groups such as NESCOR, at a very early stage of the innovation and technology development process, the IP professionals can help companies develop effective IP strategies that identify and protect the correct IP -- IP they can [use] to facilitate early-stage funding.

Answering the question from a different perspective, the old power company model may have been adequate for earlier times. Then, threats to the grid were low and didn’t originate from all corners of the world. Also, the relevance of our economy and national security on the grid was much less than now. As mentioned earlier, in addition to the relative increase in threats to the grid, with smart grid, the number of stakeholders, or entities in a position to protect the grid, has increased. So while for some innovations, plain and simple secrecy and a non-disclosure agreement will do, I would suggest that a large portion of innovation should be protected not only by U.S. patents, but by international patents as well.

The U.S. is in a position to lead in this sector because we have to innovate now to protect our networks and grid, whereas other countries have nowhere near the same threat at the moment. The rest of the world, however, will eventually face the same problems. With this said, U.S. companies that innovate now may be in a better position to leverage their IP internationally.

Karisny:. There have been some reports of China breaching our power grids. When you have people like this who are not going to play by the rules what good is a legal IP document?

Wood: I'm aware of reports that claim hackers from China, and other nation states, have breached our power grid. You are right in that IP is not the answer to those elements. In fact in many of those cases, the goal of the hackers is the theft of IP. IP rights are designed to incentivize companies and individuals to innovate. A properly calibrated IP system, where companies or individuals can acquire IP rights in a timely manner, and be rewarded for their innovations, is what is needed to jumpstart critical infrastructure cyber security in resiliency-enhancing innovations. This process will ultimately help securitize our nation’s critical infrastructure. So, although IP rights are not a direct answer to hackers and other cyber criminals, as the threats get more frequent and more serious, the companies with IP rights in various solutions can stand to benefit tremendously from monetization of this IP.

Karisny: We are beginning to see the need for interoperable security all the way from DOD to someone's house. Living in Florida I have witnessed hurricane infrastructure destruction that makes it absolutely necessary for all government agencies and the private sector to securely and interoperably communicate. Could the smart grid be the beginning of this locally needed smart secure wireless IP infrastructure?

Wood: I think we have seen again and again that increased interconnectivity and interoperability produces huge benefits in efficiencies. So that is where we should go. The smart grid, as envisioned, will be an extensive part of this interconnectivity -- ultimately increasing the grid’s resilience to natural or other disasters (e.g., multiple built in redundancies). So, it stands to reason that the smart grid is a part of the extensive secure communication medium, such as you mentioned.

Karisny:. We are entering into a massive wireless device market with the majority of these wireless connections being machine to machine. Should machine to machine security and person to machine security be looked at differently?

Wood: There may be differences in the physical security measures. But, other than that, we should not make assumptions about whether the malicious infiltration is by a person or a machine. The massive growth in wireless devices, many of them directly or indirectly connected to the grid, dramatically increases the potential entry points through which malicious elements (rogue machines, malicious code, or persons) access the grid. The threat of massive denial of service attacks will increase. Harmful code can propagate to numerous entry points, making the defense against such harmful code difficult. These entry points will also make difficult the eventual cleanup of the harmful code. Each of these entry points should be monitored and protected against malicious machine as well as human access. In addition, the network perimeters around the critical infrastructure should ideally be protected in a layered manner. The critical systems themselves may be protected by restricting the entry points and implementing stringent access monitoring. These systems may also be protected by taking additional steps that may be necessary to protect the particular control systems.

Karisny: We are beyond media hype with the recent cyber security attacks. What should be our immediate response strategy be to these cyber breaches as it relates to your focus in our nation’s critical infrastructure.

Wood: Clearly we need to use the full force of our laws to track down and punish cyber criminals who attack our critical infrastructure. We also need to close the technical holes through which these attacks happen. In the short term, perhaps steps such as physically separating critical infrastructure networks may be part of the answer. However, in the long term, and from an efficiency standpoint, we want enhanced interconnectivity. In order to maintain this extensive interconnectivity we must have adequate monitoring, along with systems and strategies to protect, detect, and defend with respect to cyber threats.

Karisny:. You are based in the Washington, D.C., Metro area. Is DC listening as it relates to cyber attacks and if you could get your message all the way to the top, what would it be?


Wood: Washington already recognizes the urgent need for effective cybersecurity. But we must more efficiently harness American ingenuity to address the challenges we are facing in defending our critical infrastructure, especially the power grid, from cyber threats. One of the best ways to ensure proper ingenuity is focused on cybersecurity is to facilitate the protection of IP rights so that innovators can be rewarded for their work in this area.

Theodore Wood is a key member of the firm's Grid Industry Group, where he focuses on helping innovators involved with ensuring power grid resiliency in an evolving smart grid infrastructure. Wood's work before the United States Patent and Trademark Office includes patent application preparation and prosecution, reissue, reexamination, and appeals before the Board of Patent Appeals and Interferences. He has served the role of virtual in-house IP counsel for several high technology emerging companies, where he developed programs to identify, protect, manage and commercialize IP assets. Wood has worked on intellectual property matters involving many technologies, including electronics, computer graphics, computer architecture, networks, and network protocols, telecommunications networks, wireless communication systems, e-commerce and Internet applications, GPS location-based services, intelligent vehicle systems, automotive systems, and medical devices.

Larry Karisny is the Director of Project Safety.org , a smart grid security consultant, writer and industry speaker focusing on security solutions for the smart grid and critical infrastructure.