‘Crash Override’: The Malware That Took Down a Power Grid

From: Wired

Andy Greenberg

***

Physical Damage?

Another disturbing but less well-understood feature of the program, according to ESET, suggests an extra capability that hackers could potentially use to cause physical damage to power equipment. ESET’s researchers say one aspect of the malware exploits a known vulnerability in a piece of Siemens equipment known as a Siprotec digital relay. The Siprotec device gauges the charge of grid components, sends that information back to its operators, and automatically opens circuit breakers if it detects dangerous power levels. But by sending that Siemens device a carefully crafted chunk of data, the malware could disable it, leaving it offline until it’s manually rebooted. (Siemens didn’t respond to WIRED’s request for comment. Dragos, for its part, couldn’t independently confirm that the Siemens attack was included in the malware sample they analyzed.)

That attack might be intended to merely cut off access to circuit breakers after the malware opens them, preventing the operators from easily turning the power back on, says Mike Assante, a power grid security expert and instructor at the SANS Institute. But Assante, who in 2007 led a team of researchers that showed how a massive diesel generator could be physically and permanently broken with only digital commands, says the Siprotec attack might also have a more destructive function. If attackers used it in combination with overloading the charge on grid components, it could prevent the kill-switch feature that keeps those components from overheating, damaging transformers or other equipment.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *