Energy Central EnergyPulse Home
Home Subscribe Login Contribute to Energy Pulse Advertise on Energy Pulse About Energy Pulse Feedback to Energy Pulse
Search Articles:   
  You are here: Home > Communications & Security > Article Display


Free Newsletter
Sign up today for your free subscription to the EnergyPulse Weekly Update - delivered directly to your e-mail box.
e-mail:


 

Biofuels: The Promise of the Next Generations

Feb 10 2010 - 1:00 PM Eastern - Your location

The second wave of biofuels such as cellulosic ethanol, algae and others bypass the food vs. fuel controversy and are on the cusp of commercialization. This webinar will review the latest developments in the advanced biofuel space with leading companies more...

Conducting a distributed chorus

Feb 17 2010 - 12:00 Eastern - Your City

Join Intelligent Utility managing editor Kate Rowland, along with a panel from PHI including Rob Stewart, manager of technology evaluation and implementation, and Todd McGregor, AMI director, for an interactive discussion about this company's work to build a more intelligent more...

21st Century T&D: Building the Transmission Piece of Smart Grid

Feb 18 2010 - 12:00 Eastern - Your City

Join industry leaders and Marty Rosenberg, Editor-in-Chief of EnergyBiz magazine, for an interactive discussion about the critical relationship between transmission and distribution (T&D) investment and smart grid success. As the energy enterprise gets smarter toward the consumer end with smart more...

Transforming the Electrical Grid: Addressing Transformation Strategies to Implementing A Smart Grid

Feb 25 2010 - 3:00-4:00pm Eastern - Your City

This webcast should be attended by those individuals that are responsible for identifying, planning and evaluating Smart Grid solutions, including those that empower and engage consumers and are easily assimilated with existing or new technology and business processes. more...

Smart Grid Revolution

Feb 18 2010 - Feb 19 2010 - AUSTIN, TX - USA

ACI's Smart Grid Revolution February 18-19, 2010 A two day strategic event bringing together utility professionals, government & state officials & consultants involved in deployment of the smart grid. To learn strategies which will improve energy efficiency programs & operations, more...

EnergyBiz Leadership Forum 2010: Energy's Emerging Architecture

Feb 28 2010 - Mar 2 2010 - Washington, DC

In 2009, a global economic meltdown collided with an energy crisis to turn the world on its ear. In the United States we've witnessed an unprecedented spending on energy resource development and infrastructure. As a result, a new energy architecture more...

CERAWeek 2010

Mar 8 2010 - Mar 12 2010 - Houston, TX - USA

CERAWeek, IHS CERA's 29th Executive Conference, is recognized as a leading forum offering insight into the energy future. Each year senior policymakers, energy and power executives, and financial and technology leaders from over 55 countries engage with CERA experts in more...

2nd Annual Thin Film Solar Summit Europe

Mar 17 2010 - Mar 18 2010 - Berlin Germany

The conference will provide a comprehensive analysis of the thin film industry and its key challenges in an interactive manner. Leading companies will share their experiences through panel debates and high-level presentations. A great opportunity to network with the whole more...

Gas and Electric Business Understanding Seminar

Feb 24 2010 - Feb 25 2010 - New York, NY - USA

Gas and Electric Business Understanding provides a comprehensive overview of the natural gas and electric industries. Position yourself for career success by gaining a solid understanding of how each business works, including key physical, market and regulatory aspects, as well more...

Gas Business Understanding Seminar

Mar 1 2010 - Mar 2 2010 - Houston, TX - USA

Gas Business Understanding provides a comprehensive overview of the natural gas industry. Position yourself for career advancement by gaining a solid understanding of how the gas business works including key physical, market, and regulatory aspects and how market participants navigate more...

Electric Business Understanding Seminar

Mar 3 2010 - Mar 4 2010 - Houston, TX - USA

Electric Business Understanding provides a comprehensive overview of the electric industry. Position yourself for career advancement by gaining a solid understanding of how the electric business works including key physical, market, and regulatory aspects and how market participants navigate this more...

Gas Market Dynamics Seminar

Mar 3 2010 - Mar 4 2010 - Houston, TX - USA

Gas Market Dynamics offers participants an in-depth understanding of North American natural gas markets and how they function. Enhance your career by furthering your knowledge of market structure, supply and demand, services offered in gas markets, and how various participants more...

Energy Central
Power Network




Communications & Security


We know you have something to say!
There is an immediate need for articles on the hot topics in the Power Industry! EnergyPulse, like no other publication, also provides a means for our readers to immediately interact with experts like you.
 
Contribute Today!
Please view our Author Guidelines and send submissions to the editor.

Click For More Articles on Communications & Security
 
Building the Smart Grid: Proven Methods to Secure the Future
5.19.09   Joshua Pennell, President and Founder, IOActive
Michael Davis, Senior Security Consultant, IOActive

Article Viewed 6100 Times
5 Comments
E-mail Article Printer Friendly
 
  • Comment On Article
  • About The Author
  • More Articles By This Author

    The push for greener, more efficient energy distribution is driving the rapid development and deployment of Advanced Metering Infrastructure (AMI) technology, or smart meters. Smart meters are considered to be just one technology platform within an overall suite of maturing smart grid energy management technologies. These technologies will foster the modernization of the nation's electrical power infrastructure into what will ultimately become the cornerstone for the power grid of tomorrow. In conjunction with the approved $4.5 billion economic stimulus package, the need to create U.S. jobs and a rapidly evolving market space, this long-awaited advancement to the U.S. power infrastructure has become a reality today. But is the technology ready?

    This new generation of energy distribution technology promises to deliver real-time information, and enable the near-instantaneous balance of supply and demand. Utilities and consumers alike will benefit from the smart grid's ability to sense system overloads and reroute power to prevent, or minimize, potential outages. Yet, as with any new innovation promising such benefits, there is both opportunity and associated risk. Without considering the risks, we may never truly see the benefits.

    In April, IOActive researchers were able to identify multiple programming errors on a series of smart meter platforms ranging from the inappropriate use of banned functions to protocol implementation issues. The research team was able to "weaponize" these attack vectors, and create an in-flash rootkit, which allowed them to assume full system control of all exposed smart meter capabilities, including remote power on, power off, usage reporting, and communication configurations. The initial attack vector could also be leveraged to deploy a worm, much like the Blaster worm that wreaked havoc on computer systems in 2003. The consequences of such threats are potentially widespread and devastating.

    And hardware attacks are on the rise, due in large part to the relative ease with which they can be launched. While most software developers build base-level security into their products, hardware level has long been overlooked. Simply acquire a smart meter, and it is easy enough to reverse-engineer the device due to the lack of encryption at the hardware level. Or decode the device's communications by listening to the spectrum of radio patterns emitted by the smart meter. Neither method requires an overspecialized background or significant financial investment. Consider that most utility meters sit outside private residences and businesses, with little or no physical security to prevent access, and you have a recipe for tampering.

    Think this scenario is unlikely? Unfortunately, it's far more likely than people care to imagine. A Department of Energy lab recently published a statistic showing that there were roughly 250 exploits for control systems on any given day in 2006-2007. It was reported to take roughly 131 days to patch and remediate those vulnerabilities -- leaving the window open for exploitation.

    Beyond the ease of threat, the reality is that utility companies are viewed as recession-proof, and thus always earning money. This makes them an attractive target for criminals. Vulnerabilities in the smart grid could cause utilities to lose system control of their metering infrastructure to unauthorized third parties, exposing them to fraud, extortion attempts, lawsuits, widespread system interruption, massive blackouts or worse. The severity of the situation is driving the release of the Critical Electric Infrastructure Protection Act (CEIPA), a new bill solely focused on addressing cybersecurity concerns of the U.S. power grid. And it's only just beginning.

    All of this indicates that the security maturity of the smart meter market warrants immediate inquiry and evaluation. With more than two million smart meters in field use today, and an additional 17 million devices on order by over 73 participating utilities, the threat is not a localized concern. Furthermore, smart meter technology is expected to last 10 to 20 years in the field.

    So can the smart grid be saved? While there are clearly challenges ahead, it's not too late. The utility sector can, and should, protect their investment by demanding that smart meter devices come equipped with the types of security protection afforded to computers on a standard enterprise network.

    The challenge to building a secure smart grid power infrastructure is to quickly enact methods that support both asset owners and smart grid vendors. Typical of most emerging industries and first-to-market initiatives, the smart grid AMI community lacks a formal Secure Development Lifecycle (SDL) to guide and govern the release of sound quality technology and products. Including a requirement to conduct independent third-party security assessments of all smart grid technology will further enable the smart grid AMI industry to deploy their technology in a secure, mindful fashion without causing significant time-to-market delays.

    The SDL is a proven tool for saving money, and decreasing exposure to risk. Studies show that overall project costs are 60 times higher when gaps in information security controls are addressed late in the development cycle, as opposed to projects where security is implemented in the design phase. Championed by Microsoft, the SDL contributed to a massive reduction in the number of security bulletins issued for Windows Server 2003 and SQL Server 2000.

    In light of where we are with the application of smart grid technology, there is still time to stop. Private industry is ready and well positioned to take on this challenge to help pave the way towards a secure smart grid infrastructure that will benefit generations to come. Already at the forefront of the research efforts around AMI security, the industry has been intimately involved in the development and refinement of the SDL.

    And as the old saying goes, "measure twice, cut once." Utilities should embrace their role as the stewards of the energy "ecosystem," and hold smart meter vendors accountable for the security of their products. By demanding that their suppliers adopt secure development practices, and requiring them to undergo third-party security auditing, energy utilities can thrive from the benefit of the smart grid while insuring the future safety of the nation's critical infrastructure.

    For information on purchasing reprints of this article, contact Tim Tobeck ttobeck@energycentral.com.
    Copyright 2010 CyberTech, Inc.
     
    E-mail Article Printer Friendly
     
  • Click Here For More Articles on Grid Security


  • Click Here For More Articles By Joshua Pennell
  • Do you agree or disagree with this article? Send in your own article.

     

    Readers Comments

    Date Comment
    Len Gould
    5.20.09
    "utility companies are viewed as recession-proof, and thus always earning money. This makes them an attractive target for criminals." -- Typical of the (absence of) logic in use in the article. Why not simply throw a sheet over your head and stand in the corner going "Whooo Whoooo"?

    Bob Amorosi
    5.20.09
    Len,

    If the utility industry is reading this article, or have been thinking this way for a long time - which I suspect is the case, is it any wonder why there has been so little support for introducing real-time electricity markets for all consumers as in your IMEUC proposals.

    Besides fighting over who would bear the costs for the in-home technologies, it would require consumers to communicate with THEIR smart meters to get access to the grid. The latter I'm sure conjures up nightmares for utility officials of security breaches, especially given THEIR meters are their only billing mechanism that determines their income.

    In essence my perception has been most utility companies have shuddered at the concept of anyone communicating with THEIR smart meters, and will only allow it if governments or industry regulators force them to.

    Times are a changin’ though. I read on another EP article lately that Texas is passing state legislation that will force all Texas utility companies to provide all customers smart meters equipped with a standardized communication portal into their homes (like Itron’s Open-Way system, or similar Zigbee radio transceivers). I don’t recall exactly by when but it is something like by 2015, presumably at least to enable consumer real-time energy monitoring and also enable utility demand response capabilities through AMI systems.

    Bob Amorosi
    5.20.09
    Len,

    The article is "Advanced Meters in Texas Provide Billing Benefits" by Steve Schugart, just published on EP May14th. The rollout completion date for the whole state is by 2014. Another primary function enabled by the communication portal into residential homes will include customer pre-paid energy billing.

    Len Gould
    5.27.09
    Bob. Agreed, a lot of resistance there. To the point where Google has teamed up with Toronto Hydro to develop a widget to add to the Google toolbar which communicates with the utility central database in order to display meter data. Apparently it can only access the previous days readings..... what nonsense. No doubt utilities will try to use it to show regulators that they are providing the data to customers, though. Day-old meter readings are almost as usless for customers as no meter readings.

    Bob Amorosi
    5.28.09
    Len,

    The previous day's meter data is all that Toronto Hydro is allowed to make available to customers because the mandate given to Ontario's utility companies (by the Ontario government's smart meter initiative) was to collect meter readings only once or twice a day. The data must be ready to access by customers by 8:00am the next morning to view if desired, typically on the utility's website.

    Real-time feedback to all customers is not part of their current plans unless government forces them to provide it through new legislation, or if given the money (by someone) to do so.

    Interestingly some utility people have told me in the past they believed real-time feedback to all customers will be eventually needed in the future, which can be many years out for the traditional pace change in their industry and by our government. Governments take many years to react because they will want to study its benefits to death before committing any tax revenues to implement broad-based new mandates.

    Add your comments:
    Please log in to leave a comment!

    Top

        Home | Register | Subscribe | Contribute | Advertise | About Us | Feedback
       Copyright © 2002-2010, CyberTech, Inc. - All rights reserved. Read our Terms of Service.