Department of Energy Invests $50 Million To Improve Critical Energy Infrastructure Security (helpnetsecurity.com) 51
Orome1 shares a report from Help Net Security: Today, the Department of Energy (DOE) is announcing awards of up to $50 million to DOE's National Laboratories to support early stage research and development of next-generation tools and technologies to further improve the resilience of the Nation's critical energy infrastructure, including the electric grid and oil and natural gas infrastructure. The electricity system must continue to evolve to address a variety of challenges and opportunities such as severe weather and the cyber threat, a changing mix of types of electric generation, the ability for consumers to participate in electricity markets, the growth of the Internet of Things, and the aging of the electricity infrastructure. The seven Resilient Distribution Systems projects awarded through DOE's Grid Modernization Laboratory Consortium (GMLC) will develop and validate innovative approaches to enhance the resilience of distribution systems -- including microgrids -- with high penetration of clean distributed energy resources (DER) and emerging grid technologies at regional scale. The project results are expected to deliver credible information on technical and economic viability of the solutions. The projects will also demonstrate viability to key stakeholders who are ultimately responsible for approving and investing in grid modernization activities. In addition, the Department of Energy "is also announcing 20 cybersecurity projects that will enhance the reliability and resilience of the Nation's electric grid and oil and natural gas infrastructure through innovative, scalable, and cost-effective research and development of cybersecurity solutions."
$50 million? (Score:5, Insightful)
They better add a few zeroes to that.
Re: (Score:2)
This is just PR, what is really critical is the Strategic Petroleum Reserve of the United States ;-)
https://en.wikipedia.org/wiki/... [wikipedia.org]
Re: (Score:1, Interesting)
Of course, energy security isn't nearly as important to Americans as.......
Energy security should be among the top items of the list of critical needs. We could certainly afford to invest heavily. A great crux of the problem is that it requires adapting to its realities, after we hit key milestones/plateaus. With optimal handling of energy markets, we could likely diminish corruption and more importantly diminish difficult to measure discrepancies in reporting, without providing a broken vacuum that requires immediate fulfillment. It could even provide an outlet for abandoning fia
Re: (Score:1)
Re: (Score:3)
An F-35 costs a minimum of $165 million, so that $50 mil is less than 1/3.
https://www.bloomberg.com/news... [bloomberg.com]
Re: (Score:2)
Yeah, like China did recently, [nytimes.com] on top of the investments they've been making already for the last decade at least.
Re: (Score:2)
early stage research and development
If "early stage research and development" of something costs $50M plus a few zeroes, then that "something" must be either warp drive research or the cure for death. I don't think this is it.
Re: (Score:2)
The F-35 "fighter" jet program will cost $1.1 trillion, and doesn't include a warp drive or immortality.
Re: (Score:2)
It does not? include a warp drive?
I'm disappointed.
What did the Apollo program cost in 'modern dollars'?
Re: (Score:2)
Re: (Score:2)
They better add a few zeroes to that.
This. $50mil is is like change stuck in the couch of the Federal Government, not enough to do anything but maybe fund a study that will produce a paper in 8 months that nobody will read. And then there's that "up to" part to really let the air leak out of the balloon.
This is a big country, with a huge, interconnected, antiquated power grid that needs complete re-thinking in a world of public and private solar, heat waves, hurricanes, hackers and insecure control equipment, and a population more dependent
Coronal Mass Ejection for Life On Earth, Alex... (Score:5, Funny)
Re: (Score:2)
Don' worry, though, the latest version of Apple's iPhone will have an app to fix that! :-)
Oh no! But I choose healthcare instead. ;)
“Maybe rather than getting that new iPhone” Americans “should invest in their own healthcare” - Rep. Jason Chaffetz [huffingtonpost.com]
Re: (Score:1)
I'll take 10 million (Score:2)
And I'll just take your electrical grids off the fucking internet. There, highly secure (physical attacks only.) Saved you 40 million so you can play with figuring out the oil and gas side of things.
Re:I'll take 10 million (Score:4, Informative)
Re: (Score:2)
I see someone has no idea of what they are talking about in this regard.
Please, stop with the facts. Its more fun to just assume 'its all connected to the internet', so we can all say how stupid and negligent they are. We don't need to have a clue, its /.
Re: (Score:2)
"I see someone has no idea of what they are talking about in this regard."
I see someone fails to remember how IBM researchers hacked and gained remote control of a nuclear fucking reactor.
You think these power companies are actually complying with regulations? You better open your eyes, sonny boy. If the penalty for non-compliance the profits made from non-compliance, they will choose to not comply. This is how you have companies like Oncor in Texas fucking things up royally.
Re: (Score:2)
Fucking inserting HTML when I select plain text. Thanks, Slashdot. If the penalty of non-compliance is less tan the profits gained by non-compliance, they'll choose non-compliance.
Re: (Score:2)
Well (Score:5, Interesting)
I'm all for that. But how expensive is it to block port 23 and changing the BIOS of SCADA systems so that the first thing to be configured is a password?
I have seen power, water, sewer, and traffic systems put into production with an internet gateway that had telnet open, with default admin credentials that are well known.
I have a few "go to" things for the rare occasions I'll take a consulting gig on.
1. nmap the device. Secure the open ports.
2. No default passwords, and it's best if you can change the admin account name to something non-standard.
3. patch patch patch
4. Secure SSH so that only ssh key access is allowed. No username/password.
5. Create a key for each device. Best if you create the key with a password - I usually use the serial number of the device obfuscated. So if the serial number is 123, then the password for that key would be zyx or some simple transposition. I usually use a 10 letter word whose letters don't repeat. INTRODUCES, BLOCKHEADS, CORNFLAKES - and I usually say order them so it doesn't spell a word. EG: BLOCKHEADS to ABCDEHKLOS. And change the key based on the third or second to last number.
6 firewalls, firewalls firewalls. Limit port access to only those IP's you know and control.
7. Trust nothing completely. Defense in depth.
8. Construct "alarm" data and configure deep packet inspection to look for those alarm data and trigger an alert.
9. Ensure you have a panic button to shut down the network.
There are other things, a bit more subtle to go into.
Re: (Score:1)
You forgot some points but I won't pedantically bore everyone pretending I'm the authority on them.
Re: (Score:1)
I'm all for that. But how expensive is it to block port 23 and changing the BIOS of SCADA systems so that the first thing to be configured is a password?
I have seen power, water, sewer, and traffic systems put into production with an internet gateway that had telnet open, with default admin credentials that are well known.
I have a few "go to" things for the rare occasions I'll take a consulting gig on.
1. nmap the device. Secure the open ports.
2. No default passwords, and it's best if you can change the admin account name to something non-standard.
3. patch patch patch
4. Secure SSH so that only ssh key access is allowed. No username/password.
5. Create a key for each device. Best if you create the key with a password - I usually use the serial number of the device obfuscated. So if the serial number is 123, then the password for that key would be zyx or some simple transposition. I usually use a 10 letter word whose letters don't repeat. INTRODUCES, BLOCKHEADS, CORNFLAKES - and I usually say order them so it doesn't spell a word. EG: BLOCKHEADS to ABCDEHKLOS. And change the key based on the third or second to last number.
6 firewalls, firewalls firewalls. Limit port access to only those IP's you know and control.
7. Trust nothing completely. Defense in depth.
8. Construct "alarm" data and configure deep packet inspection to look for those alarm data and trigger an alert.
9. Ensure you have a panic button to shut down the network.
There are other things, a bit more subtle to go into.
If the 'the grid' control networks looked like a corporate network, this might make sense. But 'the grid' is really a huge number of segmented and isolated networks, of varying levels of actual control or risk, most of which have much of the security you describe. Some improperly isolated networks or ones missing some protections probably exist, but they are outliers and can't bring down the greater system.
There is a need for communication between some of the networks across the grid, and that is where ext
Re: (Score:2)
My favourite admin user/password is: :P
User: 'Ruth'
Passwd: 'geh heim'
Really fucking expensive. (Score:1)
Most SCADA systems are commisioned and qualified at great expense and left to run for decades. Upgrades are extremely expensive to perform. Think $millions.
Patching and bios upgrades need to be vendor-qualifed before installation - no-one will take the risk of the lights going out because of an unqualified patch. Vendors are getting better about independent patch releases, but that doesn't help older systems.
Your key protection is retarded. You've reduced the search space to 26!/17! which is searchable i
Re: (Score:2)
Cost of a Mile of Fiber: about $175k (Score:2)
So $50 million buys .285714285714 of a mile, or 1508.57142857 feet or 459.8126 meters.
Thank god we're saved!!
Re: (Score:2)
Here is a rough estimate as of 2015 from Quora: [quora.com]
So $50 million buys .285714285714 of a mile, or 1508.57142857 feet or 459.8126 meters.
Thank god we're saved!!
Incorrect.
Re: (Score:2)
Here is a rough estimate as of 2015 from Quora: [quora.com]
So $50 million buys .285714285714 of a mile, or 1508.57142857 feet or 459.8126 meters.
Thank god we're saved!!
Costs $175k/mile, and $50 million gets a little over a quarter mile? Sign me up for that contract! That's a nice profit margin.
Solution (Score:2)
$50 million advice (Score:2)
Here is my bid: you cannot secure that stuff, just unplug it from the net.
Where do I collect my $50 million?