mspohr writes “The NY Times has an interesting story about a pair of researchers who ‘discovered that they could freeze, or crash, the software that monitors a [power] substation, thereby blinding control center operators from the power grid.’ These two engineers wrote software to test for vulnerabilities in the control systems of electrical power grids which use a protocol called DNP3 to communicate with sub-stations. They first tested an open source implementation of the protocol and didn’t find any problems. They were worried that their software test wasn’t adequate so they started testing proprietary systems. The broke every single one of the 16 proprietary systems they tested initially and found nine more systems vulnerable in later testing. They were able to install malware and also found firewalls ineffective. The pair reported this to the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team, I.C.S.-C.E.R.T. and didn’t get much of a response. It’s scary that our electrical grid is so vulnerable and there doesn’t seem to be much urgency to get it fixed. A few patches have been issued, but who knows if the systems have been updated?”… mspohr writes “The NY Times has an interesting story about a pair of researchers who ‘discovered that they could freeze, or crash, the software that monitors a [power] substation, thereby blinding control center operators from the power grid.’ These two engineers wrote software to test for vulnerabilities in the control systems of electrical power grids which use a protocol called DNP3 to communicate with sub-stations. They first tested an open source implementation of the protocol and didn’t find any problems. They were worried that their software test wasn’t adequate so they started testing proprietary systems. The broke every single one of the 16 proprietary systems they tested initially and found nine more systems vulnerable in later testing. They were able to install malware and also found firewalls ineffective. The pair reported this to the Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team, I.C.S.-C.E.R.T. and didn’t get much of a response. It’s scary that our electrical grid is so vulnerable and there doesn’t seem to be much urgency to get it fixed. A few patches have been issued, but who knows if the systems have been updated?”

Read more of this story at Slashdot.






Read more http://rss.slashdot.org/~r/Slashdot/slashdot/~3/-V8tYO4TeyQ/story01.htm