funsec mailing list archives

Sources: Staged cyber attack reveals vulnerability in power grid


From: "Richard M. Smith" <rms () computerbytesman com>
Date: Thu, 27 Sep 2007 10:16:25 -0400

http://www.cnn.com/2007/US/09/26/power.at.risk/index.html

WASHINGTON (CNN) -- Researchers who launched an experimental cyber attack
caused a generator to self-destruct, alarming the federal government and
electrical industry about what might happen if such an attack were carried
out on a larger scale, CNN has learned.

 art.dhs1.jpg
<http://i.l.cnn.net/cnn/2007/US/09/26/power.at.risk/art.dhs1.jpg> 

Department of Homeland Security video shows a generator spewing smoke after
a staged experiment.

 
<http://www.cnn.com/.element/img/2.0/mosaic/base_skins/baseplate/corner_wire
_BL.gif> 

Sources familiar with the experiment said the same attack scenario could be
used against huge generators that produce the country's electric power. 

Some experts fear bigger, coordinated attacks could cause widespread damage
to electric infrastructure that could take months to fix.

CNN has honored a request from the
<http://topics.cnn.com/topics/u_s_department_of_homeland_security>
Department of Homeland Security not to divulge certain details about the
experiment, dubbed "Aurora," and conducted in March at the Department of
Energy's Idaho lab

In a previously classified video of the test CNN obtained, the generator
shakes and smokes, and then stops.

DHS acknowledged the experiment involved controlled hacking into a replica
of a power plant's control system. Sources familiar with the test said
researchers changed the operating cycle of the generator, sending it out of
control.  Video
<http://i.l.cnn.net/cnn/.element/img/2.0/mosaic/tabs/video.gif>
<http://www.cnn.com/2007/US/09/26/power.at.risk/index.html#cnnSTCVideo>
Watch the generator shake and start to smoke >

The White House was briefed on the experiment, and DHS officials said they
have since been working with the electric industry to devise a way to thwart
such an attack.

...

 

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Current thread: