ukwirednews
Technology
Siemens 'flaw' claim sparks US power plant security probe
Published: 22nd Aug 2012 13:53:56
The US government is investigating claims that a flaw in Siemens' networking equipment could enable hackers to attack power plants and other critical systems.
A security expert said that he had found a backdoor in hardware from a Siemens subsidiary, RuggedCom.
The equipment is widely used by power companies.
The Department of Homeland Security said it was in contact with the firm to assess the claim.
The alleged flaw was made public by security researcher Justin W Clarke at a conference in Los Angeles.
He told delegates that the firm used a single software "key" to decode traffic that it encrypted across its network, and that he had found a way to extract the key.
"If you can get to the inside, there is almost no authentication, there are almost no checks and balances to stop you," Mr Clarke said.
He added that if hackers could spy on the communications of infrastructure operators, they might be able to gain credentials to access systems used to operate power stations and other infrastructure.
In an alert, Homeland Security's Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) said it was aware of his findings.
"According to this report, the vulnerability can be used to decrypt SSL traffic between an end-user and a RuggedCom network device," read the advisory.
It said that it had "notified the affected vendor of the report" and had asked it "to confirm the vulnerability and identify mitigations".
The BBC contacted RuggedCom but the firm declined to give any more information.
Mr Clarke researched the issues in his spare time, purchasing RuggedCom equipment via eBay.
It is the second time that Mr Clarke has reported a bug in products from the firm. In May the company released an update to its software to address his earlier finding.
Although there have been no publicly reported cases of damage caused by cyber-attacks on US critical infrastructure, the issue is a growing problem.
Earlier this year the country's National Security Agency reported that there had been a 17-fold rise in the number of attempted attacks between 2009 and 2011.
ICS-CERT has also reported that 90 vulnerabilities have been identified this year, up from 60 in 2011.
Countries around the world have been alerted to the threat after revelations that the Stuxnet virus had targeted a uranium enrichment facility in Iran.
Earlier this month security firms reported another type of malware - dubbed Shamoon - had struck "at least one organisation" in the energy sector.
Harvard Citation
BBC News, 2012. Siemens 'flaw' claim sparks US power plant security probe. [Online] (Updated 22 Aug 2012)Available at: http://www.ukwirednews.com/news.php/1447640-Siemens-flaw-claim-sparks-US-power-plant-security-probe [Accessed 13th May 2013]
Latest News
-
At 23:24:45 in Headlines
New Orleans Mother's Day parade hit by shooting
Twelve people have been shot during a Mother's Day parade in the US city of New Orleans, police say.... -
At 21:15:41 in Headlines
Two bodies found after New Jersey hostage standoff
US police have ended a 37-hour-long standoff with an armed 38-year-old man who took three people hostage in a house in New Jersey, authoriti... -
At 19:13:57 in Headlines
Afghan protest at Iran 'shooting' of migrants
Afghan Foreign Minister Zalmai Rasoul has summoned Iran's ambassador to protest at the alleged killing of migrants by Iranian border gu... -
At 19:08:20 in Entertainment
Dutch singer Caro Emerald's album tops chart
Jazz and pop singer Caro Emerald's second album, The Shocking Miss Emerald, has shot to the top of the charts, pushing East London dru... -
At 18:23:37 in Wales
Swansea murder: Richard Craddock named Gowerton stab victim
Murder squad detectives have named a 51-year-old man who died after he was discovered stabbed in a Swansea road.... -
At 18:15:23 in World
New Bangladesh panel to raise garment workers' wages
Bangladesh has set up a panel to raise the minimum wage for more than three million garment workers, the minister for textiles has said.... -
At 18:01:48 in England
Boy, 15, charged over acid attack
A 15-year-old boy has been charged over an acid attack on a woman in Romford, east London.... -
'Dramatic decline' warning for plants and animals
More than half of common plant species and a third of animals could see a serious decline in their habitat range because of climate change.... -
At 18:00:03 in Politics
EU graduates 'cannot evade' loan repayments
The government has warned overseas graduates who borrowed money to study in the UK that they cannot evade their obligation to repay by movin... -
At 17:32:45 in England
Blackpool Madame Tussauds removes Ken Barlow waxwork
A waxwork of Coronation Street's Ken Barlow at Madame Tussauds in Blackpool has been removed over fears of it being damaged, a spokesma...
News In Other Categories
-
West Belfast sex attack on teenager investigated
The police are investigating an alleged serious sexual assault on a teenage girl in west Belfast. ... -
North Korea's silent football matches
Foreign visitors to North Korea are allowed to attend sports matches alongside their minders. But football in this secretive republic has li... -
EU graduates 'cannot evade' loan repayments
The government has warned overseas graduates who borrowed money to study in the UK that they cannot evade their obligation to repay by movin... -
New Orleans Mother's Day parade hit by shooting
Twelve people have been shot during a Mother's Day parade in the US city of New Orleans, police say.... -
New Orleans Mother's Day parade hit by shooting
Twelve people have been shot during a Mother's Day parade in the US city of New Orleans, police say.... -
Philip Hammond: Small firms to get army reserve cash 'incentives'
Small firms are to be offered cash incentives to encourage them to allow workers to join the military reserves, says defence secretary Phili...



