Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Potential for a Cyber Atack on American Infrastructure

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » Topic Forums » National Security Donate to DU
 
steven johnson Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-03-09 05:46 PM
Original message
Potential for a Cyber Atack on American Infrastructure
Edited on Fri Apr-03-09 05:49 PM by steven johnson
The April Popular Mechanics has a cover story on the vulnerabilty of US infrastructure to a major cyber attack.

One trick they described was the USB Drive Drop where the hacker drops a USB drive loaded with rootkit software that automatically installs when employee plugs the USB drive into his work computer. It bypasses the firewall and the hackers have control.




Most experts agree that China and Russia routinely probe our industrial networks, looking for information and vulnerabilities to use as leverage in any potential dispute. James Lewis, a cyber-security expert for the policy think tank Center for Strategic and International Studies (CSIS), says that although cyber warfare couldn’t cripple the U.S., it could serve as an effective military tactic. “If I were China, and I were going to invade Taiwan,” he says, “and I needed to complete the conquest in seven days, then it’s an attractive option to turn off all the electricity, screw up the banks and so on.” Could the entire U.S. grid be taken down in such an attack? “The honest answer is that we don’t know,” Lewis says. “And I don’t like that answer.”

In January 2008, senior CIA analyst Tom Donahue dropped a bombshell on a small conference of government officials and power-company engineers from the U.S. and Europe. He told them that extortionists had managed to hack into utilities in multiple regions outside the United States and disrupt power equipment. “In at least one case,” he said, “the disruption caused a power outage affecting multiple cities.” The CIA has been highly secretive about the incident, and Donahue would not discuss where the blackouts occurred or what companies were affected. But he admitted that the CIA had no idea who had perpetrated the attacks. Hackers had shaken down a public utility, it seems, and had gotten away with it.

Could hackers take down key parts of our infrastructure? Experts say yes. They could use the very computer systems that keep America's infrastructure running to bring down key utilities and industries, from railroads to natural gas pipelines. How worried should we be about hacking, the new weapon of mass disruption?


The most Frequently told anecdote in the world of infrastructure cyber security is that of Maroochy Shire. The incident, which occurred in Queensland, Australia, is viewed by many in the industry as an object lesson in the damage that can be done when someone with computer skills and a grudge takes aim at a public system. In 2000, Vitek Boden, a computer expert in his late 40s who had been turned down for a job in municipal government, rigged up his laptop computer to a radio-frequency wireless transceiver to hack into the city’s computerized wastewater management system. Over the course of two months, Boden broke into the system 46 times, instructing it to spill hundreds of thousands of gallons of raw sewage into rivers, parks and public areas. He was finally caught when a police officer pulled him over and found control-systems equipment in his car. The reason the Maroochy Shire incident is recounted so frequently is that it shows how difficult it is to thwart hackers who want to disrupt the infrastructure, since attacks can come from almost anywhere. An insider with detailed knowledge could target a specific company’s system, or a hacker could launch an anonymous Internet assault from a distant country.

http://www.popularmechanics.com/technology/military_law/4307521.html


http://www.popularmechanics.com/technology/military_law/4307528.html





Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
billyoc Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-03-09 05:54 PM
Response to Original message
1. Diabolical genious. NOBODY would resist the urge to plug in a USB drive that they found.
Printer Friendly | Permalink | Reply | Top
 
Deja Q Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-03-09 05:55 PM
Response to Original message
2. Disable Autorun or equivalent; do a full antivirus sweep before opening.
Assuming the malware is known and not 'in the wild', of course.
Printer Friendly | Permalink | Reply | Top
 
Mind_your_head Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Apr-03-09 07:32 PM
Response to Original message
3. I think we rely too much on technology, especially when technology is not your 'core business'
Edited on Fri Apr-03-09 08:17 PM by Mind_your_head
Personally experienced examples in the recent past:

My local pizza parlor shut down for the evening (couldn't/wouldn't accept my order) b/c their computer system went down. I thought this was crazy! Just send someone up to the local 'Office Depot' to get an "old-fashioned" receipt book with a carbon paper in the middle. Write the order - make three copies of every order. Send one copy back to the kitchen to produce the pizza, one for bookkeeping, and give one to the customer. Simple. Nope they CLOSED for the evening and lost one night's revenue b/c they didn't have any non-technology based back-up plan in place. The manager and employees were all young (so they didn't remember/know any way to handle the business prior to computers managing it all).

Another example:

Hair Salon. Their computer 'crashed'. They couldn't accept/make any new appointments b/c they didn't know who was scheduled for what service or at what time. They didn't 'close', however. They just had to wait and see who walked in for a scheduled appointment (even though they lost their appointment schedule).

All this salon would have had to do would be to print out the next day's schedule's every night at the close of business. Then if the computer crashed the next day, they would still have a "hard copy" of who was coming in for which service......and could continue to manually schedule appointments.

Technology only can AID "common sense" by having a faster and more efficient system. It doesn't/NEVER WILL replace 'common sense' itself.
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sun Dec 22nd 2024, 04:07 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Topic Forums » National Security Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC