Zibb
Subscribe to Control Engineering
FirstLight
Email
Print
Reprint
Learn RSS

Cyber security: CIA warns about industry hacking, extortion risks

-- Control Engineering, 2/6/2008

The CIA doesn’t normally discuss openly what it sees or what it does. So when a cyber security expert wants to speak publicly and for the record about cyber crime threats in the electric utility industry, people listen. Last month, Tom Donahue, the CIA’s top cyber security analyst, did just that at the SANS Institute 2008 SCADA and Process Control Summit. I caught up with Alan Paller, research director for SANS, and asked him what he carried away from that presentation.

Paller said the CIA asked to make this presentation, but SANS was not allowed to publicize its participation, or even say that Donahue was coming. “The news was that he came prepared and vetted to make the presentation,” Paller notes, “so that means they’ve moved past the stage where this is hypothetical in their minds, and they think it needs to be fixed. I was shocked that they were willing to do that. He said ‘you can quote me,’ and he gave it to me in writing and signed it. Their message is that people need to act on this, and they wanted to give it a credible source.”

The substance of the presentation is that there have been actual cyber break-ins at utilities outside the U.S. where hackers have made extortion demands, and in at least one situation they caused an outage that affected multiple cities. The analysts suspect, but cannot confirm, that the hackers had inside knowledge. “The CIA measures the threat, not the vulnerability,” Paller adds. “They’re looking at who’s doing this and what kind of resources they have. If the CIA thinks it matters, it matters, at least to me. Utilities need to act on the threat.

“People pretend it’s not a problem by putting risks in boxes. Either ‘I’m protected,’ or ‘They’re not going to target me,’ or ‘It’s not a big enough probability.’ The CIA’s job is to measure the extent to which people, either governments, terrorist groups, or organized crime, have gotten to the point where they know how to do it, can do it, and have figured out that they can make a buck or get data they want doing it. That’s got to be what happened.”

Paller says there are three main ways to make money by hacking. The first is spam, obtaining e-mail addresses for advertising or directly soliciting money. The second is getting into an individual’s machine to steal personal financial information. A new variation on that is “pump and dump,” where people’s online stock trading accounts are hijacked and used to pump up a stock price fraudulently. Those two account for many billions of dollars of illegal gain. Extortion, the third method of hacking is rapidly growing.

“Extortion is the biggest silent threat,” warns Paller. “Banks have been hit by it. Lots of e-commerce sites and virtually all online gambling sites are paying extortion. For utilities, it is the big threat. It has been a major crime category since at least 2001, and a friend of mine who runs this area for the FBI says they learn of at least one new cyber-extortion case every day. It’s a huge thing.”

Is there light at the end of the security tunnel? Paller says there is also good news that came out of the January summit. More on that next month.

The SANS Institute provides a wide variety of training and courses for cyber security. There will be a comprehensive seminar in Orlando, April 18-25.

—Peter Welander, process industries editor, peter.welander@reedbusiness.com,
Process & Advanced Control Monthly
Register here and scroll down to select your choice of free eNewsletters.

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Related Content

Related Content

By This Author

There are no other articles written by this author.

Sponsored Links

 

Advertisement
SPONSORED LINKS

More Content

  • Blogs
  • Discussions
  • Webcasts
  • Podcasts
  • Videos

Blogs

  • David Chappell
    Standard profits: Make2Pack and ISA88

    June 30, 2008
    Wisdom shared: Comments on ISA88 Part 5 technical report
    We are devoting the Make2Pack July 2 call to finishing TR88.05, the technical report for ISA88 Part 5. The committee, which includes voting members......
    More
  • Peter Welander
    Pillar to Post: Peter Welander's Blog

    June 24, 2008
    China's new slogan
    China's Communist Party has always had a way with slogans and descriptive language, and it has continued even though Mao's "Red Book&quot......
    More
  • View All BlogsRSS

Webcasts

The Top 5 Things You Need to Know About Process Safety
Join this webcast to gain a complete understanding of the technologies, identify which solutions are most appropriate for specific applications and how to tie them in with your existing plant infrastructure.

Machine vision helps take control
Learn from the experts: What machine vision technology can do for control systems, When machine vision is appropriate, How to incorporate machine vision into control systems, And what results others have obtained.

View All Webcasts

Podcasts

Matt Luallen (SANS Institute, Sph3r3) talks to Renee Robbins and Peter Welander on evolving concepts of cyber security in industrial contexts. Part 1 of 2. (21 minutes)
Matt Luallen on Cyber Security, Part 1
Matt Luallen (SANS Institute, Sph3r3) talks to Renee Robbins and Peter Welander on evolving concepts of cyber security in industrial contexts. Part 1 of 2. (21 minutes) Hear It Now

View All Podcasts Subscribe Now to Podcasts and never miss an episode
Advertisements





NEWSLETTERS

Get engineering industry news, trends, and business-critical information delivered directly to your inbox!

Click on a title below to learn more.

Weekly News (Weekly)
Process Instrumentation & Sensors (Monthly)
System Integration Monthly (Monthly)
Process & Advanced Control (Monthly)
Machine Control Monthly (Monthly)
Information Control (Monthly)
Automation Control (Monthly)
Product Review (Monthly)
Simplified Safety (Monthly)
Fieldbus Facts (Monthly)
PROFInews North American Edition (Monthly)
About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Useful Sites   |   FREE Subscription   |   RSS
© 2008 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites