Editor’s Note: Detecting vulnerabilities in critical infrastructure cyber-defenses is an essential step in protecting national security. Any vulnerabailities spotted by federal official could also be found by hostile actors — but with far different consequences.
From: C/Net
The National Security Agency’s Perfect Citizen program hunts for vulnerabilities in “large-scale” utilities, including power grid and gas pipeline controllers, new documents from EPIC show.
Newly released files show a secret National Security Agency program is targeting the computerized systems that control utilities to discover security vulnerabilities, which can be used to defend the United States or disrupt the infrastructure of other nations.
The NSA’s so-called Perfect Citizen program conducts “vulnerability exploration and research” against the computerized controllers that control “large-scale” utilities including power grids and natural gas pipelines, the documents show. The program is scheduled to continue through at least September 2014.
The Perfect Citizen files obtained by the Electronic Privacy Information Center and provided to CNET shed more light on how the agency aims to defend — and attack — embedded controllers. The NSA is reported to have developed Stuxnet, which President Obama secretly ordered to be used against Iran’s nuclear program, with the help of Israel.
U.S. officials have warned for years, privately and publicly, about the vulnerability of the electrical grid to cyberattacks. Gen. Martin Dempsey, the chairman of the Joint Chiefs of Staff, told a congressional committee in February: “I know what we [the U.S.] can do and therefore I am extraordinarily concerned about the cyber capabilities of other nations.” If a nation gave such software to a fringe group, Dempsey said, “the next thing you know could be into our electrical grid.”
Discussions about offensive weapons in the U.S. government’s electronic arsenal have gradually become more public. One NSA employment posting for a Control System Network Vulnerability Analyst says the job involves “building proof-of concept exploits,” and an Air Force announcement in August called for papers discussing “Cyberspace Warfare Attack” capabilities. The Washington Post reported last month that Obama secretly signed a directive in October outlining the rules for offensive “cyber-operations.”
“Sabotage or disruption of these industries can have wide-ranging negative effects including loss of life, economic damage, property destruction, or environmental pollution,” the NSA concluded in a public report (PDF) discussing industrial control systems and their vulnerabilities.
Leave a Reply