Showing posts with label facilities. Show all posts
Showing posts with label facilities. Show all posts

Friday, October 9, 2015

Report finds many nuclear power plant systems “insecure by design”

A study of the information security measures at civilian nuclear energy facilities around the world found a wide range of problems at many facilities that could leave them vulnerable to attacks on industrial control systems—potentially causing interruptions in electrical power or even damage to the reactors themselves.

The study, undertaken by Caroline Baylon, David Livingstone, and Roger Brunt of the UK international affairs think tank Chatham House, found that many nuclear power plants’ systems were “insecure by design” and vulnerable to attacks that could have wide-ranging impacts in the physical world—including the disruption of the electrical power grid and the release of “significant quantities of ionizing radiation.” It would not require an attack with the sophistication of Stuxnet to do significant damage, the researchers suggested, based on the poor security present at many plants and the track record of incidents already caused by software.

The researchers found that many nuclear power plant systems were not “air gapped” from the Internet and that they had virtual private network access that operators were “sometimes unaware of.” And in facilities that did have physical partitioning from the Internet, those measures could be circumvented with a flash drive or other portable media introduced into their onsite network—something that would be entirely too simple given the security posture of many civilian nuclear operators. The use of personal devices on plant networks and other gaps in security could easily introduce malware into nuclear plants’ networks, the researchers warned.
The security strategies of many operators examined in the report were “reactive rather than proactive,” the Chatham House researchers noted, meaning that there was little in the way of monitoring of systems for anomalies that might warn of a cyber-attack on a facility. An attack could be well underway before it was detected. And because of poor training around information security, the people responsible for operating the plants would likely not know what to do.

That problem is heightened by what the researchers characterized as a “communication breakdown” between IT security professionals and the plant operations staff, and a simple lack of awareness among plant operations people about the potential dangers of cyber-attacks. Cultural differences between IT and nuclear engineering culture cause friction at some facilities, in fact—making it difficult for IT and security staff to get across the problem with the poor security practices in the plants.

Unfortunately, there’s no way to tell how bad the problem really is, because the nuclear industry doesn’t talk about breaches.

“The infrequency of cyber security incident disclosure at nuclear facilities makes it difficult to assess the true extent of the problem and may lead nuclear industry personnel to believe that there are few incidents,” the researchers wrote in their summary. ”Moreover, limited collaboration with other industries or information-sharing means that the nuclear industry tends not to learn from other industries that are more advanced in this field.”

These issues, combined with a lack of regulation, may lead to an underestimation of risk by nuclear operators and result in a lack of budgeting or planning for reducing the risk of attack. More

 

Monday, September 23, 2013

National Security Archive

Natanz Facility

Underground Facilities: Intelligence and Targeting Issues (New Documents)

U.S. Intelligence: Hiding of Military Assets by "Rogue Nations" and Other States a Major Security Challenge for 21st Century

U.S. Documents Describe Monitoring Effort Going Back to Early Cold War Years

National Security Archive Electronic Briefing Book No. 439

UPDATE -- September 23, 2013

Originally Posted -- March 23, 2012

For more information contact:
Jeffrey T. Richelson - 202/994-7000
nsarchiv@gwu.edu


Washington, D.C., September 23, 2013 -- While the focus on Syria's chemical weapons use, and the possibility of military action against Syrian government targets pushed aside, for a while, the issue of how to deal with Iran's nuclear program, the two situations have one thing in common -- their reported reliance on underground facilities to shield the production and storage of weapons of mass destruction.

Documents posted today by the National Security Archive show that such sites in Syria are only the latest in a long line of alleged and real underground facilities that have posed a high priority challenge for U.S. and allied intelligence collection and analysis efforts, as well as for military planners. There may be more than 10,000 such facilities worldwide, many of them in hostile territory, and many presumably intended to hide or protect lethal military equipment and activities, including weapons of mass destruction, that could threaten U.S. or allied interests.

Today's posting features 21 new documents, in addition to the 41 records from the Archive's initial March 23, 2012, posting on this subject. The new materials include several concerning a key topic of Cold War intelligence collection and analysis -- hardened and underground communications facilities. Also included for the first time are draft charters for the National Reconnaissance Office (NRO) working group on hardened and buried targets. The majority of the new materials consist of reports from the Asian Studies Detachment (ASD) of the 500th Military Group of the Army Intelligence and Security Command. The ASD reports, based on open source intelligence, focus on various aspects of hardened and buried facilities in North Korea and China.

The 21 new items, with one exception, were acquired via Freedom of Information Act requests or research in the National Archives. The original posting described in detail the agencies and programs the U.S. government has brought to the task of identifying and assessing underground structures in foreign countries since World War II.


Check out today's posting at the National Security Archive website -http://www.gwu.edu/~nsarchiv/NSAEBB/NSAEBB439/

Find us on Facebook - http://www.facebook.com/NSArchive

Unredacted, the Archive blog - http://nsarchive.wordpress.com/


________________________________________________________
THE NATIONAL SECURITY ARCHIVE is an independent non-governmental research institute and library located at The George Washington University in Washington, D.C. The Archive collects and publishes declassified documents acquired through the Freedom of Information Act (FOIA). A tax-exempt public charity, the Archive receives no U.S. government funding; its budget is supported by publication royalties and donations from foundations and individuals.