The Utility of Attacking Utilities

IEC 60417 - Ref-No 5596Disruptions of US water infrastructure have been in the news recently, which made us think of utilities in general. Utilities in general (water, electricity, natural gas) are often targets of military hacking as opposed to criminal hacking, which made us think of how much we emphasize one (criminal) and minimize the other (military). Let's get into that.

Simpleicons Interface light-bulb-outlineThe model we are used to is cyber crime, almost always in the form of being held for ransom by ransomware. In this scenario your systems are breached, then compromised, then a ransom demand is made.

There is nothing subtle or covert about this process. The goal is immediate attention and payment. You don't have to wonder if you are being attacked. You cannot avoid knowing that you are being attacked.

The military model is very different. Your adversary wants to know what they can do to you, but unless you are actually at war your adversary may not want you to know that they know. There will be no alarm bells. There will be minimal disruption. There will be no demands. At first. When your opponent wants to disrupt people's lives and freak them out and cause some panic and some discomfort, then there will be disruption. If, God forbid, they want to do more than freak people out there will be threats to public safety. The utility of attacking utilities is high and varied.

At first there will be penetration and then probing of your systems with an eye to NOT gaining attention and NOT causing disruption and NOT being detected. In this model there are two very different goals and the same opponent may switch between these goals over time. One goal is to see what there is to see, to learn what there is to learn and possibly to corrupt or erase your data. The other goal is to know that they could disrupt your operations at a moment's notice, should the need arise.

Propane tank with gas flame Pinhead iconThis is kind of a cybersecurity nightmare because if you don't pick up on the abnormal activity and that activity goes on for years then it becomes normal activity. Why do those packets sometimes come from these weird IP addresses? Who knows, but it has been going on as long as I've been here and it doesn't seem to hurt anything, so I guess we just ignore it. Unless and until our president starts a war with the country whose intelligence service has done the penetrating and then suddenly there is a problem. A problem that seems to come out of nowhere. A problem that will not be found by diligently checking recent logs. A problem that might be outside your organization, in your supply chain, where you can't easily find it until it is too late.

If you don't work for a US utility company, especially a small operation without a big staff, big budget, lots of excess capacity and a willingness to start a deep review of all of their threat surfaces, spare a thought for those who aren't so lucky. They have a lot of work to do and not much time in which to do it.

All of us working in cybersecurity share a problem: risk management is about what might be happening. Cybersecurity can't be just about what is happening right now. You have to make sure that there are as few possible failure points as possible. Even if everything seems just fine right now. Even if you have "never had a problem." Just because you are paranoid doesn't mean that they aren't out to get you. PS they are out to get you.

Comments