CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

60 Minutes highlights cyber threats to our power grid

If you missed it this weekend, I am including a link to the 60 Minutes special on cyber security this weekend as well as embedding the video below. The episode is a sobering look at the threats to not only to the systems that comprise our power grid, but it also sheds light on just how vulnerable we are as a nation to an online attack.

Watch CBS News Videos Online

The story begins with an interview of Admiral Mike McConnell, former chief of national intelligence, who has this to say:

“If I were an attacker and I wanted to do strategic damage to the United States, I would either take the cold of winter or the heat of summer, I probably would sack electric power on the U.S. East Cost, maybe the West Coast, and attempt to cause a cascading effect. All of those things are in the art of the possible from a sophisticated attacker,” McConnell explained.

“Do you believe our adversaries have the capability of bringing down a power grid?” Kroft asked.

“I do,” McConnell replied.

Asked if the U.S. is prepared for such an attack, McConnell told Kroft, “No. The United States is not prepared for such an attack.”

As someone who has worked in the computer industry for over 20 years, it is often easy to simply look at compliance requirements as a necessary evil that brings very little real value to business. In the case of regulations governing security on the Internet, like the North American Electric Reliability Corporation – Critical Infrastructure Protection (NERC-CIP) guidelines, their goal is nothing short of our National security.

In general, this was a very thorough piece that not only deals with grid security, but also highlights recent Internet based attacks and provides details of how important it is to defend all of our critical systems. If you have some time today this segment is certainly worth watching.

A look at application whitelisting in control systems on Digital Bond

Jason Holcomb, from Digital Bond, recently attended a live implementation of CoreTrace’s award-winning BOUNCER application whitelisting product. He has a great post about his impressions on whitelisting in general, as well as his experience using BOUNCER on a control system server. His reaction?

“My overall impression: this is an elegant and effective solution to some of the security challenges we face with Windows servers and workstations in control systems.”

Jason hits on many of the reasons why application whitelisting has been so popular in the energy industry and why, more than ever, it is being used to protect critical SCADA and DCS systems as well as met NERC CIP requirements. Continue reading this post…

Power Grid Security Critically Important – Reactive Security Won’t Cut It

The U.S. Department of Homeland Security takes the security of our power grid seriously and with good reason. A disruption to our power distribution systems could have devastating effects for our citizens, businesses and our economy. That is the driver behind the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) regulations; keeping our national power grids safe.

Yesterday came the latest report of how fragile our power infrastructure can be. Continue reading this post…

Application Whitelisting Momentum – Meeting NERC CIP-007 Requirements

Last week I blogged about the general momentum around application whitelisting citing our meetings with Neil MacDonald from Gartner and a recent post from George Kurtz of McAfee.

This week, I want to speak more specifically about using application whitelisting to both meet the letter and the spirit of NERC CIP-007 compliance requirements. This is an area where application whitelisting is gaining significant momentum as a supplement or alternative to traditional blacklist antivirus. There are many reasons why the energy industry is ahead of the general curve in adopting whitelisting technologies. Continue reading this post…

Time For an Update of PCI Antivirus Requirements: Take a lesson from NERC CIP

Time For an Update of PCI Anti-Virus Requirements: Take a lesson from NERC CIPPCI requirements have come under scrutiny lately. A number of high profile security incidents resulting in the exposure of hundreds of thousands of credit cards have, fairly or unfairly, brought attention to the companies who suffered these attacks and yet were PCI compliant at the time. The highest profile incident was that of Network Solutions where over a half a million credit cards were compromised.

The culprit? Unauthorized code on their servers resulted in the exposure of the credit card data. Despite the protections employed to protect the card data on servers, they were done in by simple malware on a system in their infrastructure.


Continue reading this post…