The Water Pump Alarm

This subject goes in and out of vogue in various government circles, yet we still seem to be treading water, waiting for a real attack to make us serious about addressing the threat.
BACKGROUND: FBI, DHS say no evidence of a hack in an Illinois water district pump failure
Many thought the early reports out of Springfield on Nov. 10 were the opening salvo. That day, the Illinois Statewide Terrorism & Intelligence Center (STIC) issued a report titled "Public Water District Cyber Intrusion."
Early coverage of the event said someone in Russia had hacked into a SCADA contractor and purloined credentials that were then used to access controls in Springfield's Curran-Gardner Public Water District. By repeatedly cycling a pump on and off, it was believed the attacker managed to cause that device to fail.
If true, the incident would be the first reported domestic attack on a utility from a foreign land to result in damage, and potentially portend more significant attacks.
The FBI and Department of Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) have since concluded there was no evidence of an attack, but the way the whole incident unfolded is reason enough for concern.
Consider the glacial response. Illinois issued the report on a Thursday. ICS-CERT didn't become aware of it until the following Wednesday. If the incident was real -- and there was no evidence at the time that it was anything but -- shouldn't alarm bells have started to ring upstream somewhere? And while ICS-CERT did jump on some log analysis when it finally became aware of the event, it didn't actually send a team in to investigate until many days after that.

While this whole incident increasingly appears to have been a false alarm, the real alarm is our lackadaisical response. Addressing the process for reacting to events is a lot easier than addressing the inadequacies of infrastructure security, yet evidently we haven't even gotten that right yet.
What's it going to take before the government mandates that national infrastructure security is brought in line with enterprise network security? Unfortunately, I think we all know the answer to that.
Read more about wide area network in Network World's Wide Area Network section.






Add Your Comment