EFY Times  
Monday, May 20, 2013

 
GO
 
 
PNNL Report Reveals Dramatic Increase In Cyber Threats
 
Home >> Infotech >> Trends
 
PNNL Report Reveals Dramatic Increase In Cyber Threats  
 
   
Rate this news:  (0 Votes)
Wednesday, June 20, 2012 The Pacific Northwest National Laboratory (PNNL), a federal contractor to the U.S. Department of Energy (DOE), in conjunction with McAfee, recently revealed the findings from a report entitled “Technology Security Assessment for Capabilities and Applicability in Energy Sector Industrial Control Systems: McAfee Application Control, Change Control, Integrity Control.”






For the first time, the report fully examines the current challenges facing critical infrastructure and key resources as well as identifying specific risks and vulnerabilities in the evolving cyber threat landscape. It analyzes the value and effectiveness carefully integrated security solutions necessary to support the national security mission to secure industrial control system environments. In addition, the big challenge for critical infrastructure and energy sector owners and operators, as identified by the report, is how to effectively secure their control systems within their governance and technical domains in an active and capable advanced persistent threat environment.

“When early critical infrastructure systems were created, neither security nor misuse of the interconnected network was considered, said Philip A. Craig Jr, Senior Cyber Security Research Scientist, a researcher within the National Security Directorate at the Pacific Northwest National Laboratory. “Today, we are still focused on enhancing the security of control systems. Outdated security methods that use a maze of disparate, multi-vendor, and stacked security tools will only delay a cyber attack, providing numerous opportunities for a more advanced and modern cyber adversary to attack cyber security postures throughout critical infrastructure.”

In the report, PNNL and the DOE have identified the following vulnerabilities to control systems environments:

· Increased Exposure: Communication networks linking smart grid devices and systems will create many more access points to these devices, resulting in an increased exposure to potential attacks.

· Interconnectivity: Communication networks will be more interconnected, further exposing the system to possible failures and attacks.

· Complexity: The electric system will become significantly more complex as more subsystems are linked together.

· Common Computing Technologies: Smart grid systems will increasingly use common, commercially available computing technologies and will be subject to their weaknesses.

· Increased Automation: Communication networks will generate, gather, and use data in new and innovative ways as smart grid technologies will automate many functions. Improper use of this data presents new risks to national security and our economy.

The report also examines how emerging vulnerabilities of control systems continue to accelerate. Today’s cyber attack has evolved into a sophisticated and carefully designed digital-weapon tasked for a specific intent, such as the Stuxnet and Duqu virus.

“Infrastructures that control systems affecting our everyday lives, such as smart grids, are rising in adoption yet still lack the proper security needed to prevent sophisticated cyber attacks, “said Dr. Phyllis Scheck, Vice President and Chief Technology Officer, Global Public Sector, McAfee. “Achieving security by design is essential in securing critical infrastructure. Cybersecurity must be embedded into the systems and networks at the very beginning of the design process so that it becomes an integral part of the systems functioning.”

In addition to control systems, the report also examines the impact of new technologies impacting the Energy sector. As information and communication technology advances and becomes integrated into power system operations and planning functions, smart grids are created, which yield greater visibility into the state of the system and advancements in control to enhance system efficiencies. Despite the significant benefits of the dynamic nature of the power grid, it was not designed with cyber security in mind.

The report cites the following solutions in an effort to prevent vulnerability and mitigate attacks to control systems:

· Dynamic Whitelisting –Provides the ability to deny unauthorized applications and code on servers, corporate desktops, and fixed-function devices.

· Memory Protection – Unauthorized execution is denied and vulnerabilities are blocked and reported.

· File Integrity Monitoring – Any file change, addition, deletion, renaming, attribute changes, ACL modification, and owner modification is reported. This includes network shares.

· Write Protection – Writing to hard disks are only authorized to the operating system, application configuration, and log files. All others are denied.

· Read Protection – Read are only authorized for specified files, directories, volumes and scripts. All others are denied

The Department of Energy’s key objective to secure the critical infrastructure and key resources includes our Nation’s electric generation, transmission, distribution resources, as well as key oil and natural gas assets. The Pacific Northwest National Laboratory seeks to continue to improve the value of security technologies as they are implemented in these critical infrastructure and key resources areas.



Print Email Post Comment 
(Total Views: 512)
 
Share
 
 
Infotech News
   
Now, A Hardware To Check Movie Piracy
Google Hangout Upgrade Slays Voice Calling Support
Opera And Ex-Employee Settle $3.4 Million Lawsuit
Create Apps For Samsung And Win $800,000!
Websites Worth Checking Out!
 
 
 
     
     
     
Press Release
     
Samsung Display Showcasing ...
Nokia Siemens Networks Liquid Broadband ...
STMicroelectronics Reveals Latest Power ...
Panasonic Achieves New Milestone, ...
Infibeam Houses The All New HTC One ...
Compact Can Be Cool Too: F&D’s A511 ...
New Dell Latitude Laptop Delivers ...
Hughes Communications India Named Best ...
KONKA Means Business With ‘TUXEDO 990’
Advaiya Acknowledged As The “Best ...
Telit To Expand Line Of ...
ZALP - An Employee Referral Booster ...
Type A Machines Introduces The Series 1 ...
Rosslare Introduces The goPROX Family
Comguard Unveils A New Range Of ...
Array Networks Wins Frost and ...
Tata Power Lights Up Lives Of Over 1200 ...
ZyXEL Organizes Series Of Knowledge ...
ASUS Appoints Digicomp And Digicare As ...
Robinsons Bank of Philippines Selects ...
F-Secure Enters Indian Corporate ...
Delta India MCIS Bags Award For ...
Businesses In India Can Lose Up To 18% ...
NASSCOM Foundation Volunteers Run To ...
Performance That Stuns ! – iBall ...
 
Uninor Achieves Break-Even In Gujarat, ...
Trend Micro Ramps Up Its Cloud Security ...
Agilent Technologies Introduces ...
Aircel Offers ‘Extra’ On Its Full Talk ...
Video: Avnet And HP Release Video To ...
Micromax Canvas Music A88 Now Available ...
ASRock Promises Improved WiFi With ...
Emkor Solutions Aligns With Citrix To ...
LG Retains Leadership Position In ...
AdaptxtR Keyboard App For Android ...
Unreliable Power Supply Creates Huge ...
Frost & Sullivan: Opportunities For ...
NEC Asia Pacific’s Regional Retail ...
LG Display Introduces Next Generation ...
Mercury Launches 3G Enabled Ultra Slim ...
ESET Launches Managed Service Provider ...
TTI Asia Presents “2012 Supplier ...
TTI Presents “2012 TTI Supplier ...
Food Preparation Appliances Becoming ...
On Purchase Of iPad Mini Get Cash Back ...
Sprint Closes Transaction To Acquire ...
Automotive-grade Factory-Programmable ...
Industry-first Compact White LED With ...
Automotive-grade MLCC Range Expanded ...
CMC Product Line Extended With ...
     
     
     
     
     
Most popular
 
 
 
 
Features
Linux Tips And Tricks That You Can Use
These must-try tips help you experience Linux better than ever. ...
Six Interesting Facebook Tricks That You Might Not Know
Did you know that you can update a blank status, have a status in blue colour via a device that you don't even have. No? Read these 6 interesting tric...
 
  View All
Videos
 
First Look: LG Optimus G
The phone sports a high-end display and comes powered by a powerful processor. ...
Create QR-Codes For Free
TEC-IT releases the freeware QR-Code Studio to provide a quick and convenient way of QR code creation for every application scenario....
DoT Secretary Shares Plans For Growth Of Telecom Sector
M.F. Farooqui has recently taken charge as secretary, Department of Telecom....
Hands-On: Sony Xperia Z
Xperia Z is Sony's first entrant model in the big-screen smartphone category. ...
Hands On: Videocon A30 Smartphone
Videocon, the consumer electronics company which is known for its refrigerators, washing machine and air-conditioner has unveiled its Android-based sm...
   
View All
   
 
Dialogue
 
“Open Source Technology Will Bring In A Services-Based Model With A Reasonable Opex, Zero Capex”
myOpenSourceStore.com is an open source solutions provider catering to businesses worldwide. ...
How OSS Helped A Construction Company Almost Halve Its IT Budget!
SEW Infra has been able to save nearly 40 per cent of its IT budget by deploying open source solutions....
Face To Face With Richard Stallman
The father of the free software movement, Richard M. Stallman talks on topics including why ‘Free Software’ matters so much, the entire confusion crea...
“We See India As Our Top Priority And Believe It To Be A Fascinating Market”
In an exclusive interview with EFY, Yamashita talks about the potential market in India, and Fujitsu’s marketing strategy to explore it....
Indian Market Is A Quality Conscious Market And The Customers Pay The Price For Quality
In an exclusive interview with EFY, Hidekazu Katsuno, president, ROHM Semiconductor Singapore Pte Ltd, talks about the company's strategy to capture t...
   
  View All
CeBIT 2013
 
Major Indian IT Companies Found Missing From CeBIT
Besides European companies, CeBIT 2013 attracted exhibitors and visitors in large numbers from all other continents as well. Poland was the partner co...
CeBIT 2013: Here Comes Brain Painting!
The system is basically a computer program that can help paralysed patients draw artworks simply by using the power of their brains. ...
CeBIT 2013: Fujitsu Unveils Lifebook E Line Notebooks
All three models in the series include flexible and convenient working functions that are normally expected in today’s premium business notebooks. ...
CeBIT 2013: Want To Feel Loved? Get 'Cuddle Jacket' For You
The 'cuddle jacket' can be helpful for kids suffering from autism and other sensory disorders....
CeBIT 2013: Here Comes Solar Powered Water Filtering Technology
The technology works in a unique way as it purifies water with the help of UV rays coming via daylight....
CeBIT 2013: Highlights Of Day 1!
Besides European companies, CeBIT 2013 attracted exhibitors and visitors from all other continents....
   
View All
   
 
Events
 
12 Nov: LASER World Of PHOTONICS INDIA

View All
   
   
 
 

home archives contact us advertise with us
           
Magazines Portals Directories Events News Verticals Educational Institute  
Electronics for You
Open Source for You
Facts for You
Electronics Bazaar
electronicsforu.com
efytimes.com
bpotimes.com
linuxforu.com
Electronics Annual Guide
EFY EXPO
EFY Awards
EduTech Expo
OSIWEEK Expo
Electronics
Infotech
Linux & Open Source
Consumer Electronics
Science & Technology
BPO
EFY Techcenter 
 
 
© Copyright 2013 EFY Enterprises Pvt. Ltd.
All rights reserved. Reproduction in whole or in part in any form or medium without written permission is prohibited.
Usage of the content from the web site is subject to Terms and Conditions